Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 30,217 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-2049 | HIGH | 7.8 | 2026-06-10 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta… | |
| CVE-2026-42326 | MEDIUM | Patched | 5.1 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a … |
| CVE-2026-42462 | HIGH | 7.0 | 2026-06-10 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make… | |
| CVE-2026-42542 | HIGH | Patched | 7.5 | 2026-06-10 | TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash… |
| CVE-2026-44692 | HIGH | Patched | 7.7 | 2026-06-10 | Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to th… |
| CVE-2026-45031 | MEDIUM | Patched | 5.3 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD d… |
| CVE-2026-45358 | MEDIUM | Patched | 5.3 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off by one in the meta encoder c… |
| CVE-2026-45359 | MEDIUM | Patched | 5.7 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:kee… |
| CVE-2026-45380 | LOW | Patched | 3.6 | 2026-06-10 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, a one-byte off-by-one error in SafeOutPathBui… |
| CVE-2026-45384 | MEDIUM | Patched | 6.1 | 2026-06-10 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerab… |
| CVE-2026-45624 | MEDIUM | Patched | 5.1 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distor… |
| CVE-2026-45664 | MEDIUM | Patched | 5.3 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the M… |
| CVE-2026-45783 | HIGH | Patched | 7.5 | 2026-06-10 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storage of any @libp2p/kad-dh… |
| CVE-2026-46520 | HIGH | Patched | 7.5 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with d… |
| CVE-2026-46522 | HIGH | Patched | 7.5 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF … |
| CVE-2026-46523 | MEDIUM | Patched | 6.2 | 2026-06-10 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a h… |
| CVE-2026-46625 | HIGH | Patched | 7.5 | 2026-06-10 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plai… |
| CVE-2026-46654 | NONE | Patched | — | 2026-06-10 | Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that pr… |
| CVE-2026-46668 | NONE | Patched | — | 2026-06-10 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structur… |
| CVE-2026-46669 | HIGH | Patched | 7.5 | 2026-06-10 | OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_c… |
| CVE-2026-46673 | HIGH | Patched | 7.5 | 2026-06-10 | Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking p… |
| CVE-2026-46679 | HIGH | Patched | 7.5 | 2026-06-10 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single… |
| CVE-2026-46689 | NONE | Patched | — | 2026-06-10 | Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a few thousand … |
| CVE-2026-46702 | HIGH | Patched | 7.5 | 2026-06-10 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabled, russh accepted compressed packets whose on-wire … |
| CVE-2026-46705 | MEDIUM | Patched | 5.3 | 2026-06-10 | Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authentication path keeps internal userauth state across … |