Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,746
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 161 - 180 of 35,119 CVEs
CVE-2026-56408 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in copyString.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56407 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56406 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56405 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in getAttributeId.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56404 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in addBinding.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56403 MEDIUM - 6.9

libexpat before 2.8.2 has an integer overflow in storeAtts.

Vendor: libexpat project
Product: libexpat
Published: Jun 21, 2026
Source: NVD
CVE-2026-56397 CRITICAL - 9.6

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayNa...

Vendor: SiYuan
Product: SiYuan
Published: Jun 21, 2026
Source: NVD
CVE-2026-56396 HIGH - 8.8

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to Super...

Vendor: phpMyFAQ
Product: phpMyFAQ
Published: Jun 21, 2026
Source: NVD
CVE-2026-56395 CRITICAL - 9.6

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayNa...

Vendor: SiYuan
Product: SiYuan
Published: Jun 21, 2026
Source: NVD
CVE-2026-56394 MEDIUM - 6.5

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowi...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56393 MEDIUM - 4.8

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw ...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56385 MEDIUM - 4.3

Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56384 MEDIUM - 4.3

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback transform preview link...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56383 MEDIUM - 4.8

Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with allowAdminC...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56382 HIGH - 7.2

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cle...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD
CVE-2026-56381 MEDIUM - 4.8

Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the user group name field that executes when other user...

Vendor: craftcms
Product: cms
Published: Jun 21, 2026
Source: NVD

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byt...

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 21, 2026
Source: NVD

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB file can lead to information disclosure or a crash.

Vendor: ImageMagick
Product: ImageMagick
Published: Jun 21, 2026
Source: NVD
CVE-2026-56316 MEDIUM - 5.3

Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response discrepancies. Attackers can probe the endpoint without authentication to distin...

Vendor: Cap-go
Product: capgo
Published: Jun 21, 2026
Source: NVD
CVE-2026-56299 MEDIUM - 5.3

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers can send OPTIONS requests to bypass authentication middleware and invoke tusProxy logic with invalid c...

Vendor: Capgo
Product: Capgo
Published: Jun 21, 2026
Source: NVD