LIVE FEED
1828 events · 4 sources · newest first
Events in view
1828
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-26 18:00
UTC
2026-04-06
NVD CVE
CVE-2026-35178: Workbench is a suite of tools for administrators and developers to interact with
CRITICAL
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the...
2026-04-06
NVD CVE
CVE-2026-35459: pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.
CRITICAL
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to...
2026-04-06
NVD CVE
CVE-2026-34444: Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier,
CRITICAL
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This...
2026-04-03
NVD CVE
CVE-2026-34612: Kestra is an open-source, event-driven orchestration platform. Prior to version
CRITICAL
Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in...
2026-04-03
NVD CVE
CVE-2017-20235: ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an
CRITICAL
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative...
2026-04-03
NVD CVE
CVE-2026-0545: In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not
CRITICAL
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the...
2026-04-03
NVD CVE
CVE-2026-32213: Improper authorization in Azure AI Foundry allows an unauthorized attacker to el
CRITICAL
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-33105: Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori
CRITICAL
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-33107: Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized at
CRITICAL
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-31818: Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-
CRITICAL
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP...
2026-04-03
NVD CVE
CVE-2026-32186: Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized atta
CRITICAL
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-28798: ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 syst
CRITICAL
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an...
2026-04-03
NVD CVE
CVE-2026-27634: Piwigo is an open source photo gallery application for the web. Prior to version
CRITICAL
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in...
2026-04-02
NVD CVE
CVE-2026-32871: FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2
CRITICAL
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is...
2026-04-02
NVD CVE
CVE-2026-35053: OneUptime is an open-source monitoring and observability platform. Prior to vers
CRITICAL
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST...
2026-04-02
NVD CVE
CVE-2026-34932: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.
2026-04-02
NVD CVE
CVE-2026-34931: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim...
2026-04-02
NVD CVE
CVE-2026-35002: Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability
CRITICAL
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed...
2026-03-31
NVD CVE
CVE-2026-32916: OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vuln
CRITICAL
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes....
2026-03-31
NVD CVE
CVE-2026-34532: Parse Server is an open source backend that can be deployed to any infrastructur
CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by...
2026-03-31
NVD CVE
CVE-2026-34156: NocoBase is an AI-powered no-code/low-code platform for building business applic
CRITICAL
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a...
2026-03-31
NVD CVE
CVE-2026-34400: Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API
CRITICAL
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search...
2026-03-31
NVD CVE
CVE-2026-34361: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CRITICAL
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that...
2026-03-31
NVD CVE
CVE-2026-34235: PJSIP is a free and open source multimedia communication library written in C. P
CRITICAL
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted...
2026-03-31
NVD CVE
CVE-2026-34221: MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and
CRITICAL
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used...
2026-03-31
NVD CVE
CVE-2026-34162: FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT
CRITICAL
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP...
2026-03-30
NVD CVE
CVE-2025-15036: A path traversal vulnerability exists in the `extract_archive_to_dir` function w
CRITICAL
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions...
2026-03-30
NVD CVE
CVE-2025-15379: A command injection vulnerability exists in MLflow's model serving container ini
CRITICAL
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`,...
2026-03-27
NVD CVE
CVE-2026-33701: OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a
CRITICAL
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that...
2026-03-26
NVD CVE
CVE-2026-26213: thingino-firmware versions up to the firmware-2026-03-16 release contains an una
CRITICAL
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive portal CGI script that allows remote attackers to execute arbitrary...
2026-03-24
NVD CVE
CVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style
CRITICAL
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is...
2026-03-24
NVD CVE
CVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails application
CRITICAL
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved...
2026-03-24
NVD CVE
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
CRITICAL
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
CRITICAL
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
CRITICAL
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-23
NVD CVE
CVE-2026-31848: Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_p
CRITICAL
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is...