Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,339
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 3,310 CVEs
CVE-2026-55518 CRITICAL - 9.6

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Vendor: rubygems
Product: avo
Published: Jun 17, 2026
Source: GitHub

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.utilities
Published: Jun 17, 2026
Source: GitHub
CVE-2026-55450 CRITICAL - 9.3

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Vendor: pip
Product: langflow
Published: Jun 17, 2026
Source: GitHub
CVE-2026-49980 CRITICAL - 9.8

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Vendor: go
Product: github.com/rclone/rclone
Published: Jun 16, 2026
Source: GitHub

LiteLLM: Authentication Bypass via Host Header Injection

Vendor: pip
Product: litellm
Published: Jun 16, 2026
Source: GitHub
CVE-2026-22313 CRITICAL - 9.1

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operati...

Vendor: Radiflow
Product: iSAP Smart Collector
Published: Jun 16, 2026
Source: NVD
CVE-2026-54157 CRITICAL - 9.0

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

Vendor: npm
Product: @lobehub/lobehub
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53753 CRITICAL - 9.8

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-48746 CRITICAL - 9.1

vLLM: OpenAI auth bypass

Vendor: pip
Product: vllm
Published: Jun 16, 2026
Source: GitHub
CVE-2026-48519 CRITICAL - 9.6

Langflow: Unauthenticated RCE in Shareable Playgrounds

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53776 CRITICAL - 9.1

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued be...

Vendor: PerryTS
Product: perry
Published: Jun 16, 2026
Source: NVD
CVE-2026-12316 CRITICAL - 9.1

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12315 CRITICAL - 9.1

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-12304 CRITICAL - 9.1

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Vendor: Mozilla
Product: Firefox
Published: Jun 16, 2026
Source: NVD
CVE-2026-40750 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

Vendor: themagnifico52
Product: Kids Online Store
Published: Jun 16, 2026
Source: NVD
CVE-2026-52715 CRITICAL - 9.3

Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

Vendor: Eyal Fitoussi
Product: GEO my WordPress
Published: Jun 16, 2026
Source: NVD
CVE-2026-49774 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.

Vendor: Filipe Nasc
Product: RD Station
Published: Jun 16, 2026
Source: NVD
CVE-2026-49772 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

Vendor: Liquid Web / StellarWP
Product: The Events Calendar
Published: Jun 16, 2026
Source: NVD
CVE-2026-39574 CRITICAL - 9.3

Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

Vendor: RealMag777
Product: InPost Gallery
Published: Jun 16, 2026
Source: NVD
CVE-2026-12205 CRITICAL - 9.1

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same obj...

Vendor: TIMLEGGE
Product: Crypt::DSA
Published: Jun 15, 2026
Source: NVD