Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,970
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,901 - 1,920 of 34,447 CVEs
CVE-2025-27511 HIGH - 7.2

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

Vendor: maven
Product: org.geoserver.extension:gs-db2
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48099 HIGH - 7.1

WsgiDAV encoded dot segments can escape filesystem share roots

Vendor: pip
Product: wsgidav
Published: Jun 11, 2026
Source: GitHub

DevGuard has improper authorization on public assets

Vendor: go
Product: github.com/l3montree-dev/devguard
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48067 MEDIUM - 6.5

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

Vendor: composer
Product: filament/tables
Published: Jun 11, 2026
Source: GitHub
CVE-2026-48059 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested ...

Vendor: maven
Product: io.netty:netty-codec-haproxy
Published: Jun 11, 2026
Source: GitHub
CVE-2026-53782 HIGH - 7.4

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicio...

Vendor: steipete
Product: summarize
Published: Jun 11, 2026
Source: NVD
CVE-2026-53781 MEDIUM - 4.3

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attacke...

Vendor: steipete
Product: summarize
Published: Jun 11, 2026
Source: NVD
CVE-2026-49973 CRITICAL - 9.4

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable networ...

Vendor: nesquena
Product: hermes-webui
Published: Jun 11, 2026
Source: NVD
CVE-2026-49949 MEDIUM - 5.3

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carryi...

Vendor: steipete
Product: CodexBar
Published: Jun 11, 2026
Source: NVD
CVE-2026-46622 HIGH - 8.1

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database โ€” through SQL injection, a leaked backup, a misconf...

Vendor: SolidInvoice
Product: SolidInvoice
Published: Jun 11, 2026
Source: NVD
CVE-2026-46489 HIGH - 8.1

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every ...

Vendor: SolidInvoice
Product: SolidInvoice
Published: Jun 11, 2026
Source: NVD

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to ...

Vendor: CyberArk Software, a Palo Alto Networks Company
Product: Idira Endpoint Privilege Manager
Published: Jun 11, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: Jun 11, 2026
Source: NVD
CVE-2026-53702 MEDIUM - 6.5

A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses an incorrect loop bound derived from cpb_cnt_minus1[i] (the loop index) instead of the sub-layer 0 CPB count cpb_cnt_minus1[0] from the r...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 11, 2026
Source: NVD
CVE-2026-53701 MEDIUM - 6.5

An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates without checking that the slice index stays within bou...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 11, 2026
Source: NVD
CVE-2026-52860 HIGH - 7.8

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python evaluates function default values, parameter...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-52859 HIGH - 8.2

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stoppi...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-52858 HIGH - 7.8

Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found...

Vendor: vim
Product: vim
Published: Jun 11, 2026
Source: NVD
CVE-2026-48547 HIGH - 7.3

KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() cal...

Vendor: lingdojo
Product: kana-dojo
Published: Jun 11, 2026
Source: NVD

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the AutoMod remove flow looks up and deletes rules by global database ID without verifying that the rule belongs to the guild where the command is executed. A user can learn a victim gu...

Vendor: duck-organization
Product: quest-bot
Published: Jun 11, 2026
Source: NVD