Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,853
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 141 - 160 of 12,881 CVEs
CVE-2026-54006 MEDIUM - 4.3

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

Vendor: pip
Product: open-webui
Published: Jun 17, 2026
Source: GitHub

NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint

Vendor: npm
Product: nocodb
Published: Jun 17, 2026
Source: GitHub

NocoDB: Server-Side Request Forgery via Base Migration URL

Vendor: npm
Product: nocodb
Published: Jun 17, 2026
Source: GitHub

NocoDB: Stored Cross-Site Scripting via Secure Attachment

Vendor: npm
Product: nocodb
Published: Jun 17, 2026
Source: GitHub

NocoDB: Refresh Tokens Persist Through Password Recovery

Vendor: npm
Product: nocodb
Published: Jun 17, 2026
Source: GitHub

NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL

Vendor: npm
Product: nocodb
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54233 MEDIUM - 6.5

vLLM: OOM Denial of Service via Audio Decompression Bomb

Vendor: pip
Product: vllm
Published: Jun 17, 2026
Source: GitHub

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

Vendor: pip
Product: vllm
Published: Jun 17, 2026
Source: GitHub

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

Vendor: pip
Product: vllm
Published: Jun 17, 2026
Source: GitHub

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

Vendor: pip
Product: vllm
Published: Jun 17, 2026
Source: GitHub

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Jun 17, 2026
Source: GitHub
CVE-2026-53765 MEDIUM - 6.1

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

Vendor: npm
Product: chrome-devtools-mcp
Published: Jun 17, 2026
Source: GitHub
CVE-2026-54325 MEDIUM - 4.4

Pi Agent: Pi loads project-local extensions without approval

Vendor: npm
Product: @earendil-works/pi-coding-agent
Published: Jun 17, 2026
Source: GitHub
CVE-2026-8607 MEDIUM - 6.4

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program โ€“ myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output es...

Published: Jun 17, 2026
Source: NVD
CVE-2026-8494 MEDIUM - 6.4

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level...

Published: Jun 17, 2026
Source: NVD
CVE-2026-8383 MEDIUM - 5.3

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a...

Published: Jun 17, 2026
Source: NVD
CVE-2026-7850 MEDIUM - 5.9

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks agains...

Published: Jun 17, 2026
Source: NVD
CVE-2026-55706 MEDIUM - 5.8

sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.

Vendor: OpenBSD
Product: OpenBSD
Published: Jun 17, 2026
Source: NVD
CVE-2026-54196 MEDIUM - 6.8

Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.

Vendor: Jetmonsters
Product: JetFormBuilder
Published: Jun 17, 2026
Source: NVD
CVE-2026-49072 MEDIUM - 6.5

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

Vendor: OPMC
Product: WooCommerce Anti-Fraud
Published: Jun 17, 2026
Source: NVD