Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,944
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,801 - 1,820 of 34,478 CVEs
CVE-2026-6211 HIGH - 8.7

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.

Published: Jun 12, 2026
Source: NVD
CVE-2026-54133 CRITICAL - 9.8

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an a...

Vendor: jmespath
Product: jmespath.php
Published: Jun 12, 2026
Source: NVD
CVE-2026-53787 CRITICAL - 9.8

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authent...

Vendor: Amasty
Product: Order Attributes for Magento 2
Published: Jun 12, 2026
Source: NVD
CVE-2026-53722 MEDIUM - 5.4

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. When an application binds attac...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD
CVE-2026-53721 HIGH - 8.2

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD

Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Injection via get_blog_list. This issue has been patched in versions 15.106.0 and 16.16.0.

Vendor: frappe
Product: frappe
Published: Jun 12, 2026
Source: NVD
CVE-2026-10557 CRITICAL - 9.8

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carryin...

Vendor: Yarbo
Product: Yarbo Android/IOS mobile application, Yarbo Cloud MQTT infrastructure
Published: Jun 12, 2026
Source: NVD

SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec

Vendor: swift
Product: github.com/apple/swift-nio-http2
Published: Jun 12, 2026
Source: GitHub

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

Vendor: swift
Product: github.com/apple/swift-nio-extras
Published: Jun 12, 2026
Source: GitHub

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

Vendor: swift
Product: github.com/apple/swift-nio
Published: Jun 12, 2026
Source: GitHub
CVE-2026-48121 MEDIUM - 6.7

LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access

Vendor: npm
Product: @langchain/langgraph-checkpoint-mongodb
Published: Jun 12, 2026
Source: GitHub

Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Vendor: go
Product: github.com/jpillora/chisel
Published: Jun 12, 2026
Source: GitHub

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD

Rejected reason: Reserved but no longer needed.

Published: Jun 12, 2026
Source: NVD
CVE-2026-49993 MEDIUM - 5.7

Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspa...

Vendor: nuxt
Product: nuxt
Published: Jun 12, 2026
Source: NVD

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Published: Jun 12, 2026
Source: NVD