Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,861 - 1,880 of 34,868 CVEs

Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Vendor: npm
Product: tar
Published: Jun 15, 2026
Source: GitHub

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Vendor: npm
Product: launch-editor
Published: Jun 15, 2026
Source: GitHub

vite: `server.fs.deny` bypass on Windows alternate paths

Vendor: npm
Product: vite
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53550 MEDIUM - 5.3

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Vendor: npm
Product: js-yaml
Published: Jun 15, 2026
Source: GitHub

@babel/core: Arbitrary File Read via sourceMappingURL Comment

Vendor: npm
Product: @babel/core
Published: Jun 15, 2026
Source: GitHub

@angular/service-worker: Request Credential & Cache Policy Stripping

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache

Vendor: npm
Product: @angular/common
Published: Jun 15, 2026
Source: GitHub

@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)

Vendor: npm
Product: @angular/core
Published: Jun 15, 2026
Source: GitHub

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Vendor: composer
Product: symfony/html-sanitizer
Published: Jun 15, 2026
Source: GitHub

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Vendor: npm
Product: @angular/service-worker
Published: Jun 15, 2026
Source: GitHub

@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass

Vendor: npm
Product: @angular/platform-server
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48779 HIGH - 7.5

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally sm...

Vendor: npm
Product: ws
Published: Jun 15, 2026
Source: GitHub
CVE-2026-9863 HIGH - 7.5

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Maste...

Published: Jun 15, 2026
Source: NVD
CVE-2026-9862 CRITICAL - 9.8

Fortra'sย  Core Privileged Access Manager (BoKS)ย contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration proc...

Published: Jun 15, 2026
Source: NVD
CVE-2026-9595 MEDIUM - 5.3

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's...

Vendor: webpack.js
Product: webpack-dev-server
Published: Jun 15, 2026
Source: NVD
CVE-2026-8683 MEDIUM - 6.5

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owner to crash the application via including a script to call window.open on a very large URL. Mattermost Advisory ID: MMSA-2026-...

Vendor: mattermost
Product: mattermost_desktop
Published: Jun 15, 2026
Source: NVD