Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 161 - 180 of 36,724 CVEs
CVE-2026-48785 MEDIUM - 4.8

Apptainer has incorrect path matching for 'limit container paths' directive

Vendor: go
Product: github.com/apptainer/apptainer
Published: Jun 26, 2026
Source: GitHub
CVE-2026-54753 MEDIUM - 5.9

Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Origin: * on every response, letting any website a developer visited read the server's responses cross-origin — includ...

Vendor: nrwl
Product: nx
Published: Jun 26, 2026
Source: NVD
CVE-2026-48090 MEDIUM - 5.9

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream that has already been torn down. A late AsyncClie...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-47220 HIGH - 7.5

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host related options is specified, like HOST_FIRST, SNI_FIRST, it's possible to crash Envoy when the specif...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-47205 MEDIUM - 5.9

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentation fault exists in Envoy's ext_authz HTTP filter when processing per-route authorization overri...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-13372 HIGH - 7.2

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name col...

Vendor: Devolutions
Product: Remote Desktop Manager
Published: Jun 26, 2026
Source: NVD
CVE-2026-48769 CRITICAL - 9.9

Incus has an arbitrary file write on its client due to trusted image hash

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48758 MEDIUM - 5.4

@sigstore/core has DSSE payloadType type-binding failure

Vendor: npm
Product: @sigstore/core
Published: Jun 26, 2026
Source: GitHub

Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48755 CRITICAL - 9.9

Incus has an argument injection in backup compression algorithm leading to AFW and ACE

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub

Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48753 CRITICAL - 9.9

Incus has an arbitrary file write via path traversal in S3 multipart upload

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48752 CRITICAL - 9.9

Incus has arbitrary file read+write on host via templates/ symlink in malicious image

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48751 CRITICAL - 9.9

Incus has a restricted project bypass leading to arbitrary command execution

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48750 CRITICAL - 9.9

Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-48749 CRITICAL - 9.9

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub
CVE-2026-56876 HIGH - 8.1

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction dir...

Vendor: max-mapper
Product: extract-zip
Published: Jun 26, 2026
Source: NVD
CVE-2026-54341 HIGH - 7.5

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, crashing the entire server process (SIGSEGV). Because DragonflyDB requires no authentication by de...

Vendor: dragonflydb
Product: dragonfly
Published: Jun 26, 2026
Source: NVD
CVE-2026-48743 HIGH - 7.5

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete at the transport layer (HEADERS with FIN / headers-only close) but still carries a nonzero Content-Len...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD
CVE-2026-48706 MEDIUM - 5.9

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpStatsdSink), where the thread-local flusher buffer can be overflowed by exceptionally long statisti...

Vendor: envoyproxy
Product: envoy
Published: Jun 26, 2026
Source: NVD