Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-55583 | HIGH | Patched | 7.6 | 2026-06-24 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR)… |
| CVE-2025-64719 | MEDIUM | Patched | 4.9 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial of serv… |
| CVE-2026-11998 | HIGH | 7.6 | 2026-06-24 | A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within th… | |
| CVE-2026-13201 | HIGH | Patched | 7.3 | 2026-06-24 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but dow… |
| CVE-2026-13208 | MEDIUM | Patched | 6.5 | 2026-06-24 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely… |
| CVE-2026-1840 | HIGH | 7.5 | 2026-06-24 | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness expo… | |
| CVE-2026-25119 | NONE | Patched | — | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (def… |
| CVE-2026-31978 | MEDIUM | Patched | 6.5 | 2026-06-24 | motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path tr… |
| CVE-2026-32315 | MEDIUM | Patched | 5.5 | 2026-06-24 | motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc… |
| CVE-2026-33235 | HIGH | Patched | 7.7 | 2026-06-24 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Templa… |
| CVE-2026-33543 | NONE | Patched | — | 2026-06-24 | FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/create, intended for initial… |
| CVE-2026-45677 | NONE | Patched | — | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAM… |
| CVE-2026-45687 | HIGH | Patched | 8.5 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sen… |
| CVE-2026-45688 | CRITICAL | Patched | 9.1 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS… |
| CVE-2026-45689 | CRITICAL | Patched | 9.1 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticate… |
| CVE-2026-45757 | NONE | Patched | — | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allow… |
| CVE-2026-46423 | NONE | Patched | — | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAM… |
| CVE-2026-47267 | HIGH | Patched | 8.3 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolv… |
| CVE-2026-47733 | MEDIUM | Patched | 4.4 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled … |
| CVE-2026-49277 | NONE | Patched | — | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does … |
| CVE-2026-49278 | MEDIUM | Patched | 6.7 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.i… |
| CVE-2026-50128 | MEDIUM | Patched | 5.3 | 2026-06-24 | Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of the… |
| CVE-2026-50129 | HIGH | Patched | 7.5 | 2026-06-24 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught Exception vulerability)… |
| CVE-2026-52795 | MEDIUM | 4.3 | 2026-06-24 | Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository they have no access to, because the access chec… | |
| CVE-2026-52796 | LOW | Patched | 3.5 | 2026-06-24 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic when rendering, resulting in denial of service. In … |