Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 141 - 160 of 34,996 CVEs
CVE-2026-56073 CRITICAL - 9.4

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabli...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-55878 HIGH - 7.8

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

Vendor: composer
Product: symfony/ux-toolkit
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55877 MEDIUM - 6.1

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

Vendor: composer
Product: symfony/ux-icons
Published: Jun 19, 2026
Source: GitHub

SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected

Vendor: go
Product: github.com/authzed/spicedb
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55776 MEDIUM - 6.5

OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao's System Backend allows Unauthorized Management of the containing Namespace

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub

OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} โ€” incomplete fix of CVE-2026-45808

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55770 MEDIUM - 6.8

OpenBao: LDAPi ldaputil (wrong escape func)

Vendor: go
Product: github.com/openbao/openbao
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55692 HIGH - 7.5

StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled

Vendor: composer
Product: starcitizenwiki/embedvideo
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55650 MEDIUM - 4.4

Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Vendor: npm
Product: @outerbase/studio
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55447 CRITICAL - 9.6

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-55446 HIGH - 7.5

Langflow: Unauthenticated DoS through multipart form boundary file upload

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub
CVE-2026-50559 HIGH - 7.5

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, ...

Vendor: quarkusio
Product: quarkus
Published: Jun 19, 2026
Source: NVD
CVE-2026-50519 MEDIUM - 6.5

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-49346 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size ...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49337 MEDIUM - 4.3

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in at...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD
CVE-2026-49295 HIGH - 7.1

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predic...

Vendor: strukturag
Product: libde265
Published: Jun 19, 2026
Source: NVD

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonicalization of domains in very specific edge cases, an access control rule may be...

Vendor: authelia
Product: authelia
Published: Jun 19, 2026
Source: NVD
CVE-2026-48584 CRITICAL - 9.9

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Published: Jun 19, 2026
Source: NVD
CVE-2026-55423 MEDIUM - 6.1

Langflow: Logout button does not clear session

Vendor: pip
Product: langflow
Published: Jun 19, 2026
Source: GitHub