Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,804
Quick preset (or use dates below)
Clear Filters
Showing 1 - 20 of 1,465 CVEs

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Vendor: composer
Product: statamic/cms
Published: Jun 26, 2026
Source: GitHub

Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy

Vendor: composer
Product: aimeos/pagible
Published: Jun 26, 2026
Source: GitHub

Flawfinder output manipulation via untrusted filenames and source text

Vendor: pip
Product: flawfinder
Published: Jun 26, 2026
Source: GitHub

Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub

Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}

Vendor: go
Product: github.com/lxc/incus/v7/cmd/incusd
Published: Jun 26, 2026
Source: GitHub

fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`

Vendor: rubygems
Product: fluent-plugin-s3
Published: Jun 26, 2026
Source: GitHub
CVE-2026-3472 LOW - 3.5

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate data to an attacker-controlled server via injecting markdown image synta...

Published: Jun 26, 2026
Source: NVD

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

Vendor: JetBrains
Product: YouTrack
Published: Jun 26, 2026
Source: NVD

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

Vendor: nodejs
Product: node
Published: Jun 26, 2026
Source: NVD

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Vendor: nodejs
Product: node
Published: Jun 26, 2026
Source: NVD

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the d...

Vendor: Red Hat
Product: Red Hat OpenShift Virtualization 4
Published: Jun 26, 2026
Source: NVD

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template reference...

Vendor: bitwarden
Product: server
Published: Jun 25, 2026
Source: NVD

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

Vendor: getk2.com
Product: K2 extension for Joomla
Published: Jun 25, 2026
Source: NVD

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

Vendor: tenable
Product: Nessus
Published: Jun 25, 2026
Source: NVD

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly enforced on the JRuby implementation. As a result, a schema parsed with def...

Vendor: sparklemotion
Product: nokogiri
Published: Jun 25, 2026
Source: NVD

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 chall...

Vendor: Devolutions
Product: Server
Published: Jun 25, 2026
Source: NVD

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

Vendor: PowerDNS
Product: DNSdist
Published: Jun 25, 2026
Source: NVD