| CVE-2025-15619 |
HCL Connections is vulnerable to broken access control |
23.06.2026 |
3.5 |
| CVE-2025-55639 |
|
23.06.2026 |
|
| CVE-2025-62180 |
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs. |
23.06.2026 |
|
| CVE-2026-52673 |
|
23.06.2026 |
|
| CVE-2026-54303 |
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints |
23.06.2026 |
|
| CVE-2026-54309 |
n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions |
23.06.2026 |
|
| CVE-2026-54310 |
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes |
23.06.2026 |
|
| CVE-2026-54311 |
n8n: Merge Node SQL Mode Prototype Pollution |
23.06.2026 |
|
| CVE-2026-54312 |
n8n: Microsoft SQL Node Prototype Pollution |
23.06.2026 |
|
| CVE-2026-54313 |
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation |
23.06.2026 |
|
| CVE-2026-54314 |
n8n: Denial of Service via ZIP decompression in webhook workflow |
23.06.2026 |
|
| CVE-2026-55568 |
Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
23.06.2026 |
5.9 |
| CVE-2026-55766 |
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization |
23.06.2026 |
4.8 |
| CVE-2026-55767 |
Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle |
23.06.2026 |
5.8 |
| CVE-2026-56402 |
NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler |
23.06.2026 |
|
| CVE-2026-56692 |
NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttachedFiles |
23.06.2026 |
|
| CVE-2026-56693 |
NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action |
23.06.2026 |
|
| CVE-2026-56694 |
NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback |
23.06.2026 |
|
| CVE-2026-56695 |
OpenHarness - Cross-Session Disclosure via /resume and /summary Commands |
23.06.2026 |
|
| CVE-2026-56696 |
OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands |
23.06.2026 |
|
| CVE-2026-27604 |
FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions |
23.06.2026 |
|
| CVE-2026-28496 |
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE |
23.06.2026 |
|
| CVE-2026-35018 |
NetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection |
23.06.2026 |
|
| CVE-2026-35019 |
NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass |
23.06.2026 |
|
| CVE-2026-56815 |
|
23.06.2026 |
7.4 |
| CVE-2026-10609 |
Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization |
23.06.2026 |
|
| CVE-2026-11772 |
Reflected XSS in DRIMO CMS |
23.06.2026 |
|
| CVE-2026-12969 |
Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation |
23.06.2026 |
|
| CVE-2023-54365 |
Traefik - Denial of Service via HTTP/2 Request Handling |
23.06.2026 |
|
| CVE-2025-71337 |
Flowise - Unverified Email Change via Account Profile Endpoint |
23.06.2026 |
|
| CVE-2025-71341 |
picklescan - Remote Code Execution via Undetected profile.Profile.runctx |
23.06.2026 |
|
| CVE-2025-71365 |
picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Detection Bypass |
23.06.2026 |
|
| CVE-2025-71370 |
picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execWrapper |
23.06.2026 |
|
| CVE-2025-71376 |
picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.AutoComplete.fetch_completions |
23.06.2026 |
|
| CVE-2026-10711 |
RCE in Akınsoft's CafePlus |
23.06.2026 |
8.8 |
| CVE-2026-10857 |
Reflected XSS in Akinsoft's e-Commerce |
23.06.2026 |
6.1 |
| CVE-2026-44089 |
Buffer Overflow in Totolink EX1200L router |
23.06.2026 |
|
| CVE-2026-4610 |
ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content |
23.06.2026 |
6.4 |
| CVE-2026-54892 |
Plug: quadratic-time decoding of nested query/body parameters enables denial of service |
23.06.2026 |
|
| CVE-2026-56222 |
Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings |
23.06.2026 |
|
| CVE-2026-56225 |
Capgo - Authorization Bypass in API Key Management via App-Limited Keys |
23.06.2026 |
|
| CVE-2026-56234 |
Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint |
23.06.2026 |
|
| CVE-2026-56243 |
Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane |
23.06.2026 |
|
| CVE-2026-56248 |
Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy |
23.06.2026 |
|
| CVE-2026-56258 |
Crawl4AI - Arbitrary File Write via output_path Symlink and TOCTOU |
23.06.2026 |
|
| CVE-2026-56263 |
Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard |
23.06.2026 |
|
| CVE-2026-56274 |
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess |
23.06.2026 |
|
| CVE-2026-56275 |
Flowise - Server-Side Request Forgery via Execute Flow Base URL |
23.06.2026 |
|
| CVE-2026-56301 |
Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux |
23.06.2026 |
|
| CVE-2026-56315 |
picklescan - Remote Code Execution via Unblocked Standard Library Modules |
23.06.2026 |
|
| CVE-2026-56322 |
Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter |
23.06.2026 |
|
| CVE-2026-56371 |
ImageMagick - Memory Leak in TXT File Processing via Texture Attribute |
23.06.2026 |
|
| CVE-2026-56376 |
ImageMagick - Heap Use-After-Free in Meta Coder |
23.06.2026 |
|
| CVE-2026-56379 |
ImageMagick - Command Injection via SVG Decoder |
23.06.2026 |
|
| CVE-2026-56701 |
Grav - XML External Entity Injection via SVG Upload |
23.06.2026 |
|
| CVE-2026-56762 |
Hono - Missing Cookie Name Validation in setCookie() |
23.06.2026 |
|
| CVE-2026-56784 |
OpenRemote Manager - Cross-Tenant IDOR in Bulk Alarm Deletion |
23.06.2026 |
|
| CVE-2026-4983 |
|
23.06.2026 |
4.1 |
| CVE-2026-11374 |
Account Takeover via Predictable SSO Ticket Generation |
23.06.2026 |
9 |
| CVE-2026-10521 |
Authenticated unintended access to critical program parameters |
23.06.2026 |
|
| CVE-2026-9733 |
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter |
23.06.2026 |
|
| CVE-2026-7842 |
Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter |
23.06.2026 |
|
| CVE-2026-8163 |
Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter |
23.06.2026 |
|
| CVE-2026-8172 |
Simple Basic Contact Form <= 20250114 - Reflected XSS |
23.06.2026 |
|
| CVE-2026-8378 |
Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scripting via File Rename |
23.06.2026 |
|
| CVE-2026-8379 |
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download |
23.06.2026 |
|
| CVE-2026-12866 |
|
23.06.2026 |
9.8 |
| CVE-2026-55653 |
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service |
23.06.2026 |
|
| CVE-2026-55654 |
Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination |
23.06.2026 |
|
| CVE-2026-55655 |
Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions |
23.06.2026 |
|
| CVE-2026-11833 |
|
23.06.2026 |
|
| CVE-2026-10645 |
fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal |
23.06.2026 |
4.9 |
| CVE-2026-10651 |
Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read |
23.06.2026 |
7.1 |
| CVE-2026-10658 |
Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS |
23.06.2026 |
7.1 |
| CVE-2026-41523 |
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution |
23.06.2026 |
7.5 |
| CVE-2026-47155 |
vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors |
23.06.2026 |
6.5 |
| CVE-2026-48746 |
vLLM: OpenAI auth bypass |
23.06.2026 |
9.1 |
| CVE-2026-53923 |
vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow |
23.06.2026 |
|
| CVE-2026-54232 |
vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile |
23.06.2026 |
8.8 |
| CVE-2026-54233 |
vLLM: OOM Denial of Service via Audio Decompression Bomb |
23.06.2026 |
6.5 |
| CVE-2026-54235 |
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels |
23.06.2026 |
|
| CVE-2026-54236 |
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router |
23.06.2026 |
5.3 |
| CVE-2025-71339 |
Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_length Gadget |
23.06.2026 |
|
| CVE-2025-71344 |
picklescan - Arbitrary Code Execution via Undetected ensurepip._run_pip Function |
22.06.2026 |
|
| CVE-2025-71358 |
picklescan - Remote Code Execution via idlelib.autocomplete.AutoComplete.get_entity |
23.06.2026 |
|
| CVE-2026-44311 |
Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization |
22.06.2026 |
5.4 |
| CVE-2026-44889 |
WebOb: Location header normalization during redirect leads to open redirect |
23.06.2026 |
6.1 |
| CVE-2026-48067 |
Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields |
23.06.2026 |
6.5 |
| CVE-2026-48109 |
MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input |
23.06.2026 |
8.2 |
| CVE-2026-48166 |
Filament: Timing-based user enumeration on login page |
23.06.2026 |
5.3 |
| CVE-2026-48167 |
Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS |
23.06.2026 |
6.4 |
| CVE-2026-48500 |
Filament: Unauthenticated temporary file upload on auth pages |
23.06.2026 |
6.5 |
| CVE-2026-48502 |
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows |
23.06.2026 |
|
| CVE-2026-48505 |
Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission |
23.06.2026 |
7.4 |
| CVE-2026-48506 |
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth |
23.06.2026 |
7.5 |
| CVE-2026-48509 |
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies |
23.06.2026 |
|
| CVE-2026-48510 |
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths |
23.06.2026 |
|
| CVE-2026-48511 |
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps |
23.06.2026 |
|
| CVE-2026-48512 |
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement |
23.06.2026 |
|
| CVE-2026-48513 |
MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement |
23.06.2026 |
|
| CVE-2026-48514 |
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length |
23.06.2026 |
|
| CVE-2026-48515 |
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions |
23.06.2026 |
|
| CVE-2026-48516 |
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings |
23.06.2026 |
|
| CVE-2026-48517 |
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments |
23.06.2026 |
|
| CVE-2026-54281 |
Nest: Middleware Bypass on Fastify via Trailing Slash |
23.06.2026 |
|
| CVE-2026-54911 |
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps() |
23.06.2026 |
6.5 |
| CVE-2026-55409 |
Filament: Disabled RichEditor field state can be used for XSS |
23.06.2026 |
7.6 |
| CVE-2026-56221 |
Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts |
23.06.2026 |
|
| CVE-2026-56255 |
Capgo - Denial of Service via Unlimited Demo App Creation |
23.06.2026 |
|
| CVE-2026-56266 |
Crawl4AI - Server-Side Request Forgery via Direct Crawl Endpoints |
23.06.2026 |
|
| CVE-2026-56268 |
Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint |
23.06.2026 |
|
| CVE-2026-56280 |
Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect |
22.06.2026 |
|
| CVE-2026-56306 |
Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing |
23.06.2026 |
|
| CVE-2026-56311 |
Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
23.06.2026 |
|
| CVE-2026-56314 |
Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint |
23.06.2026 |
|
| CVE-2026-56321 |
Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint |
23.06.2026 |
|
| CVE-2026-56323 |
Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self |
23.06.2026 |
|
| CVE-2026-56324 |
Capgo - Rate Limit Bypass via User-Controlled device_id Parameter |
22.06.2026 |
|
| CVE-2026-56326 |
Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo |
23.06.2026 |
|
| CVE-2026-56348 |
n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint |
23.06.2026 |
|
| CVE-2026-56357 |
n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger |
23.06.2026 |
|
| CVE-2026-56697 |
Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp |
23.06.2026 |
|
| CVE-2026-56698 |
Nuxt - Cross-Site Scripting via navigateTo open Option |
23.06.2026 |
|
| CVE-2026-39904 |
Gophish 0.12.1 Denial of Service via Office Document Upload |
23.06.2026 |
|
| CVE-2026-41479 |
Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type |
23.06.2026 |
5.4 |
| CVE-2026-44727 |
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP |
23.06.2026 |
|
| CVE-2026-45034 |
PhpSpreadsheet: File::prohibitWrappers bypass |
23.06.2026 |
|
| CVE-2026-47240 |
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument |
23.06.2026 |
|
| CVE-2026-47241 |
Net::IMAP: Denial of Service via incomplete raw argument validation |
23.06.2026 |
|
| CVE-2026-47242 |
Net::IMAP: Command Injection via ID command argument |
23.06.2026 |
|
| CVE-2026-49460 |
pypdf: Inefficient decoding of FlateDecode PNG predictor streams |
23.06.2026 |
|
| CVE-2026-49461 |
pypdf: Possible large memory usage for form XObjects during text extraction |
23.06.2026 |
|
| CVE-2026-49468 |
LiteLLM: Authentication Bypass via Host Header Injection |
23.06.2026 |
|
| CVE-2026-54530 |
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction |
23.06.2026 |
|
| CVE-2026-54531 |
pypdf: Possible infinite loop when processing outlines/bookmarks in writer |
23.06.2026 |
|
| CVE-2026-54651 |
pypdf: Possible infinite loop when processing threads/articles in writer |
23.06.2026 |
|
| CVE-2026-55599 |
phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access |
23.06.2026 |
5.8 |
| CVE-2026-55603 |
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` |
23.06.2026 |
7.5 |
| CVE-2026-10852 |
IBM i is Affected By a Denial of Service in IBM WebSphere Application Server Liberty |
23.06.2026 |
5.9 |
| CVE-2026-44271 |
|
23.06.2026 |
8.1 |
| CVE-2026-44272 |
|
23.06.2026 |
8.8 |
| CVE-2026-44273 |
|
22.06.2026 |
6 |
| CVE-2026-44274 |
|
23.06.2026 |
7.8 |
| CVE-2026-48931 |
|
23.06.2026 |
|
| CVE-2026-11834 |
Unauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link Routers |
23.06.2026 |
|
| CVE-2026-50146 |
Astro: Reflected XSS via unescaped slot name |
23.06.2026 |
7.1 |
| CVE-2026-53663 |
React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass |
22.06.2026 |
3.1 |
| CVE-2026-53778 |
|
22.06.2026 |
|
| CVE-2026-53779 |
WebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on Windows |
23.06.2026 |
|
| CVE-2026-54288 |
Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` |
23.06.2026 |
6.5 |
| CVE-2026-54293 |
NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read |
22.06.2026 |
7.5 |
| CVE-2026-54298 |
Astro: XSS via Unescaped Attribute Names in Spread Props |
22.06.2026 |
4.2 |
| CVE-2026-54299 |
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL) |
23.06.2026 |
7.5 |
| CVE-2026-54300 |
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config |
23.06.2026 |
5.3 |
| CVE-2026-55443 |
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders |
22.06.2026 |
5.1 |
| CVE-2026-10789 |
MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop |
23.06.2026 |
9.6 |
| CVE-2026-54286 |
Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) |
23.06.2026 |
5.9 |
| CVE-2026-54287 |
Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice |
22.06.2026 |
5.3 |
| CVE-2026-54289 |
Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest |
22.06.2026 |
4.8 |
| CVE-2026-54290 |
Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard |
22.06.2026 |
7.1 |