Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,674
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 141 - 160 of 36,344 CVEs
CVE-2026-56766 HIGH - 8.8

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an ex...

Vendor: vanhauser-thc
Product: thc-hydra
Published: Jun 25, 2026
Source: NVD
CVE-2026-55667 HIGH - 8.2

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope (other tenants' data...

Vendor: filebrowser
Product: filebrowser
Published: Jun 25, 2026
Source: NVD

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives ...

Vendor: seaweedfs
Product: seaweedfs
Published: Jun 25, 2026
Source: NVD
CVE-2026-54250 MEDIUM - 5.8

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can be written to a...

Vendor: k3s-io
Product: k3s
Published: Jun 25, 2026
Source: NVD
CVE-2026-54089 CRITICAL - 9.1

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server direc...

Vendor: filebrowser
Product: filebrowser
Published: Jun 25, 2026
Source: NVD

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied c...

Vendor: filebrowser
Product: filebrowser
Published: Jun 25, 2026
Source: NVD

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and w...

Vendor: cursor
Product: cursor
Published: Jun 25, 2026
Source: NVD

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which co...

Vendor: cursor
Product: cursor
Published: Jun 25, 2026
Source: NVD

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing). DPA Countermeasures on SYMCRYPTO can be weakened (reduced entropy) by forcing certain seed values if an attacker gai...

Published: Jun 25, 2026
Source: NVD

In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

Vendor: AzeoTech
Product: DAQFactory
Published: Jun 25, 2026
Source: NVD

Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.

Vendor: Horner Automation
Product: Cscape
Published: Jun 25, 2026
Source: NVD
CVE-2026-48508 HIGH - 8.8

Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission

Vendor: pip
Product: lemur
Published: Jun 25, 2026
Source: GitHub
CVE-2026-48504 MEDIUM - 5.3

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

Vendor: rust
Product: opentelemetry_sdk
Published: Jun 25, 2026
Source: GitHub

Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RSA padding validation failed versus whether the decrypted content was malformed. An attacker able to s...

Published: Jun 25, 2026
Source: NVD

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.

Published: Jun 25, 2026
Source: NVD

Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could present a chain that ends at an intermediate they control and have it accepted as valid. This affects the OpenSSL compatibili...

Published: Jun 25, 2026
Source: NVD

AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD

wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, so the underlying signed-data verification succeeds without authenticating any content. The compatibility-layer verify path now rejects the object when ...

Vendor: wolfSSL
Product: wolfSSL
Published: Jun 25, 2026
Source: NVD
CVE-2026-55700 HIGH - 7.1

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite another reachable file. The merged fix validates both fields, de...

Vendor: pnpm
Product: pnpm
Published: Jun 25, 2026
Source: NVD
CVE-2026-55699 MEDIUM - 6.5

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows could re-derive those nam...

Vendor: pnpm
Product: pnpm
Published: Jun 25, 2026
Source: NVD