Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,604
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,521 - 1,540 of 36,815 CVEs
CVE-2026-55441 HIGH - 8.6

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are loaded on a path that never reaches it. When a directory has a task-include dir (mise-tasks/, .m...

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

Vendor: GnuPG
Product: GnuPG
Published: Jun 23, 2026
Source: NVD
CVE-2026-57053 MEDIUM - 4.0

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

Vendor: GNU
Product: libidn
Published: Jun 23, 2026
Source: NVD
CVE-2026-54323 MEDIUM - 5.9

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization h...

Vendor: daytonaio
Product: daytona
Published: Jun 23, 2026
Source: NVD
CVE-2026-54318 HIGH - 7.1

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResul...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-54317 HIGH - 7.6

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = F...

Vendor: home-assistant
Product: core
Published: Jun 23, 2026
Source: NVD
CVE-2026-53662 CRITICAL - 9.6

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single link click. The co...

Vendor: immich-app
Product: immich
Published: Jun 23, 2026
Source: NVD

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redire...

Vendor: OpenStack
Product: Swift
Published: Jun 23, 2026
Source: NVD

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Published: Jun 23, 2026
Source: NVD
CVE-2025-71382 MEDIUM - 6.5

MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable...

Vendor: ArtifexSoftware
Product: mupdf
Published: Jun 23, 2026
Source: NVD
CVE-2025-61029 HIGH - 7.5

An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2025-61024 HIGH - 7.5

An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

Published: Jun 23, 2026
Source: NVD
CVE-2020-9713 MEDIUM - 5.5

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose se...

Vendor: adobe
Product: acrobat_dc
Published: Jun 23, 2026
Source: NVD
CVE-2020-9711 MEDIUM - 5.5

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of t...

Vendor: adobe
Product: acrobat_dc
Published: Jun 23, 2026
Source: NVD
CVE-2020-9695 HIGH - 7.8

Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic...

Vendor: adobe
Product: acrobat_dc
Published: Jun 23, 2026
Source: NVD
CVE-2026-54557 MEDIUM - 5.5

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's syml...

Vendor: rust
Product: mise
Published: Jun 23, 2026
Source: GitHub

OctoPrint has possible file exfiltration via query parameters on upload endpoints

Vendor: pip
Product: OctoPrint
Published: Jun 23, 2026
Source: GitHub
CVE-2026-53925 HIGH - 7.8

Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation o...

Vendor: pip
Product: glances
Published: Jun 23, 2026
Source: GitHub
CVE-2026-54350 CRITICAL - 10.0

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published a PUBLIC write query...

Vendor: npm
Product: @budibase/server
Published: Jun 23, 2026
Source: GitHub
CVE-2026-55173 HIGH - 8.1

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Vendor: composer
Product: wwbn/avideo
Published: Jun 23, 2026
Source: GitHub