Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,831 CVEs

CVEs (9,831, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 9,831 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-39894 LOW Patched 2.9 2026-06-24 Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can c…
CVE-2026-39897 MEDIUM Patched 6.1 2026-06-24 Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has …
CVE-2026-47093 NONE — 2026-06-24 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47110 MEDIUM 6.5 2026-06-24 Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON wi…
CVE-2026-49979 LOW Patched 2.7 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smt…
CVE-2026-50189 HIGH Patched 7.2 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reacha…
CVE-2026-50551 CRITICAL Patched 9.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (data…
CVE-2026-52794 HIGH Patched 7.5 2026-06-24 Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event…
CVE-2026-53765 MEDIUM Patched 6.1 2026-06-24 Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon w…
CVE-2026-53766 MEDIUM Patched 6.1 2026-06-24 Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforc…
CVE-2026-54066 HIGH Patched 7.5 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export…
CVE-2026-54067 CRITICAL Patched 9.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSni&hellip;
CVE-2026-54068 MEDIUM Patched 5.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's &hellip;
CVE-2026-54069 NONE Patched &mdash; 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, gran&hellip;
CVE-2026-54070 HIGH Patched 7.1 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown &hellip;
CVE-2026-54158 CRITICAL Patched 9.9 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in f&hellip;
CVE-2026-54759 NONE Patched &mdash; 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with the SiYuan Electron cl&hellip;
CVE-2026-55454 CRITICAL Patched 9.9 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by def&hellip;
CVE-2026-55455 CRITICAL Patched 9.1 2026-06-24 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API an&hellip;
CVE-2026-55570 CRITICAL Patched 9.0 2026-06-24 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are se&hellip;
CVE-2026-55666 NONE Patched &mdash; 2026-06-24 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/&hellip;
CVE-2026-55759 HIGH Patched 7.4 2026-06-24 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-&hellip;
CVE-2026-55762 HIGH Patched 8.1 2026-06-24 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerpr&hellip;
CVE-2026-9772 HIGH Patched 8.8 2026-06-24 Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install&hellip;
CVE-2026-9773 HIGH Patched 8.8 2026-06-24 Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal&hellip;