Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26387
Total
1955
Critical
7970
High
8222
Medium
CVE ID Severity Score Description Published
CVE-2026-56081 CRITICAL 9.1 Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that … Jun 19, 2026
CVE-2026-56080 MEDIUM 4.9 Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to … Jun 19, 2026
CVE-2026-56079 MEDIUM 6.5 Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and … Jun 19, 2026
CVE-2026-56073 CRITICAL 9.4 Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept … Jun 19, 2026
CVE-2026-50559 HIGH 7.5 Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies … Jun 19, 2026
CVE-2026-50519 MEDIUM 6.5 Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. Jun 19, 2026
CVE-2026-49346 HIGH 7.1 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit … Jun 19, 2026
CVE-2026-49337 MEDIUM 4.3 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) … Jun 19, 2026
CVE-2026-49295 HIGH 7.1 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write … Jun 19, 2026
CVE-2026-48794 UNKNOWN Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through … Jun 19, 2026
CVE-2026-48584 CRITICAL 9.9 Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. Jun 19, 2026
CVE-2026-48582 CRITICAL 9.6 Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Jun 19, 2026
CVE-2026-48129 MEDIUM 6.5 Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly under the … Jun 19, 2026
CVE-2026-47645 HIGH 8.8 Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. Jun 19, 2026
CVE-2026-47203 UNKNOWN Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through … Jun 19, 2026
CVE-2026-45480 CRITICAL 10.0 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Jun 19, 2026
CVE-2026-42895 MEDIUM 6.5 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. Jun 19, 2026
CVE-2026-32208 HIGH 8.8 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. Jun 19, 2026
CVE-2026-49345 UNKNOWN Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery (SSRF) vulnerability exists … Jun 19, 2026
CVE-2026-49344 UNKNOWN Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts a JSON … Jun 19, 2026
CVE-2026-49342 MEDIUM 5.3 YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the … Jun 19, 2026
CVE-2026-48787 UNKNOWN gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit … Jun 19, 2026
CVE-2026-48774 HIGH 7.5 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its documented … Jun 19, 2026
CVE-2026-48773 CRITICAL 9.8 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in … Jun 19, 2026
CVE-2026-48772 CRITICAL 10.0 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY … Jun 19, 2026