Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,990
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,581 - 1,600 of 34,601 CVEs
CVE-2026-47777 HIGH - 7.5

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could forge the FeatureAuth...

Vendor: mastodon
Product: mastodon
Published: Jun 15, 2026
Source: NVD
CVE-2026-20262 MEDIUM - 6.5

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Jun 15, 2026
Source: NVD

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` โ†’ Generated URL Collapses Off-Route Under RFC 3986 Normalization

Vendor: composer
Product: symfony/routing
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Vendor: composer
Product: symfony/mailomat-mailer
Published: Jun 15, 2026
Source: GitHub

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Vendor: composer
Product: symfony/http-client
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48712 HIGH - 7.5

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

Vendor: composer
Product: symfony/security-http
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54269 MEDIUM - 5.3

protobufjs : Schema-derived names can shadow runtime-significant properties

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/compiler
Published: Jun 15, 2026
Source: GitHub

Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Vendor: npm
Product: tar
Published: Jun 15, 2026
Source: GitHub

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Vendor: npm
Product: launch-editor
Published: Jun 15, 2026
Source: GitHub

vite: `server.fs.deny` bypass on Windows alternate paths

Vendor: npm
Product: vite
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53550 MEDIUM - 5.3

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Vendor: npm
Product: js-yaml
Published: Jun 15, 2026
Source: GitHub