Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26379
Total
1954
Critical
7969
High
8218
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-25119 | UNKNOWN | — | Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Gogs accepts the configured authentication header (default: X-WEBAUTH-USER) directly from … | Jun 24, 2026 |
| CVE-2026-1840 | HIGH | 7.5 | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes … | Jun 24, 2026 |
| CVE-2026-13208 | MEDIUM | 6.5 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the … | Jun 24, 2026 |
| CVE-2026-13201 | MEDIUM | 5.2 | A flaw was found in KubeVirt's safepath package. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream helpers … | Jun 24, 2026 |
| CVE-2026-11998 | HIGH | 7.6 | A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within … | Jun 24, 2026 |
| CVE-2025-64719 | MEDIUM | 4.9 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or … | Jun 24, 2026 |
| CVE-2026-55583 | HIGH | 7.6 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the … | Jun 24, 2026 |
| CVE-2026-48028 | MEDIUM | 6.5 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data … | Jun 24, 2026 |
| CVE-2026-47389 | HIGH | 8.6 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address? … | Jun 24, 2026 |
| CVE-2026-46349 | MEDIUM | 5.3 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked-Data … | Jun 24, 2026 |
| CVE-2026-46348 | UNKNOWN | — | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ranges was … | Jun 24, 2026 |
| CVE-2026-27708 | UNKNOWN | — | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter … | Jun 24, 2026 |
| CVE-2026-23879 | HIGH | 8.0 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file … | Jun 24, 2026 |
| CVE-2026-53950 | HIGH | 7.5 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously … | Jun 24, 2026 |
| CVE-2026-53949 | MEDIUM | 5.3 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, … | Jun 24, 2026 |
| CVE-2026-53948 | MEDIUM | 5.4 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed … | Jun 24, 2026 |
| CVE-2026-53947 | MEDIUM | 5.3 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an … | Jun 24, 2026 |
| CVE-2026-53946 | MEDIUM | 5.4 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP … | Jun 24, 2026 |
| CVE-2026-53945 | MEDIUM | 4.0 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing … | Jun 24, 2026 |
| CVE-2026-53944 | MEDIUM | 5.8 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that … | Jun 24, 2026 |
| CVE-2026-53943 | CRITICAL | 9.6 | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared … | Jun 24, 2026 |
| CVE-2026-49980 | CRITICAL | 9.8 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts … | Jun 24, 2026 |
| CVE-2026-49247 | HIGH | 8.8 | Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields … | Jun 24, 2026 |
| CVE-2026-49246 | UNKNOWN | — | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to … | Jun 24, 2026 |
| CVE-2026-49220 | MEDIUM | 5.7 | Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user … | Jun 24, 2026 |