Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-39894 | LOW | Patched | 2.9 | 2026-06-24 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can c… |
| CVE-2026-39897 | MEDIUM | Patched | 6.1 | 2026-06-24 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has … |
| CVE-2026-47093 | NONE | — | 2026-06-24 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-47110 | MEDIUM | 6.5 | 2026-06-24 | Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON wi… | |
| CVE-2026-49979 | LOW | Patched | 2.7 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smt… |
| CVE-2026-50189 | HIGH | Patched | 7.2 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reacha… |
| CVE-2026-50551 | CRITICAL | Patched | 9.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (data… |
| CVE-2026-52794 | HIGH | Patched | 7.5 | 2026-06-24 | Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event… |
| CVE-2026-53765 | MEDIUM | Patched | 6.1 | 2026-06-24 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon w… |
| CVE-2026-53766 | MEDIUM | Patched | 6.1 | 2026-06-24 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforc… |
| CVE-2026-54066 | HIGH | Patched | 7.5 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export… |
| CVE-2026-54067 | CRITICAL | Patched | 9.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSni… |
| CVE-2026-54068 | MEDIUM | Patched | 5.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's … |
| CVE-2026-54069 | NONE | Patched | — | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, gran… |
| CVE-2026-54070 | HIGH | Patched | 7.1 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown … |
| CVE-2026-54158 | CRITICAL | Patched | 9.9 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in f… |
| CVE-2026-54759 | NONE | Patched | — | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with the SiYuan Electron cl… |
| CVE-2026-55454 | CRITICAL | Patched | 9.9 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by def… |
| CVE-2026-55455 | CRITICAL | Patched | 9.1 | 2026-06-24 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API an… |
| CVE-2026-55570 | CRITICAL | Patched | 9.0 | 2026-06-24 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are se… |
| CVE-2026-55666 | NONE | Patched | — | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/… |
| CVE-2026-55759 | HIGH | Patched | 7.4 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-… |
| CVE-2026-55762 | HIGH | Patched | 8.1 | 2026-06-24 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerpr… |
| CVE-2026-9772 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
| CVE-2026-9773 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal… |