Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,941 - 1,960 of 34,990 CVEs
CVE-2025-55643 MEDIUM - 5.5

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55642 MEDIUM - 6.5

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2025-55641 MEDIUM - 5.5

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Vendor: gpac
Product: gpac
Published: Jun 15, 2026
Source: NVD
CVE-2026-48817 MEDIUM - 5.3

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoin...

Vendor: pip
Product: starlette
Published: Jun 15, 2026
Source: GitHub
CVE-2026-48125 MEDIUM - 5.3

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

Vendor: npm
Product: ua-parser-js
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54271 HIGH - 8.2

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

Vendor: npm
Product: protobufjs-cli
Published: Jun 15, 2026
Source: GitHub
CVE-2026-54270 MEDIUM - 5.3

protobufjs: Memory amplification from preserved unknown fields in binary decode

Vendor: npm
Product: protobufjs
Published: Jun 15, 2026
Source: GitHub

aiohttp: Incomplete websocket frame payloads bypass memory limits

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

aiohttp: CRLF injection in multipart headers

Vendor: pip
Product: aiohttp
Published: Jun 15, 2026
Source: GitHub

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

Vendor: npm
Product: react-router
Published: Jun 15, 2026
Source: GitHub
CVE-2026-53633 CRITICAL - 9.8

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

Vendor: npm
Product: @vitest/browser
Published: Jun 15, 2026
Source: GitHub

DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content

Vendor: npm
Product: dompurify
Published: Jun 15, 2026
Source: GitHub
CVE-2026-49458 MEDIUM - 6.1

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

Vendor: npm
Product: dompurify
Published: Jun 15, 2026
Source: GitHub