LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2026-04-05
NVD CVE
CVE-2019-25692: Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with...
2026-04-05
NVD CVE
CVE-2019-25688: Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthent
HIGH
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted...
2026-04-05
NVD CVE
CVE-2019-25680: Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that
HIGH
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers...
2026-04-05
NVD CVE
CVE-2019-25676: Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerab
HIGH
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags...
2026-04-05
NVD CVE
CVE-2019-25674: CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated
HIGH
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php...
2026-04-05
NVD CVE
CVE-2026-5584: A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the func
HIGH
A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code...
2026-04-05
NVD CVE
CVE-2026-5574: A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0
MEDIUM
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to...
2026-04-05
NVD CVE
A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The...
2026-04-05
NVD CVE
CVE-2026-5562: A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts t
HIGH
A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code...
2026-04-04
NVD CVE
CVE-2026-5526: A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/
HIGH
A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper...
2026-04-04
NVD CVE
CVE-2026-34955: PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSand
HIGH
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-pattern matching...
2026-04-04
NVD CVE
CVE-2026-34775: Electron is a framework for writing cross-platform desktop applications using Ja
MEDIUM
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not...
2026-04-03
NVD CVE
CVE-2026-35561: Insufficient authentication security controls in the browser-based authenticatio
HIGH
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due...
2026-04-03
NVD CVE
CVE-2026-28798: ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 syst
CRITICAL
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an...
2026-04-03
NVD CVE
CVE-2017-20235: ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an
CRITICAL
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative...
2026-04-03
NVD CVE
CVE-2026-0545: In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not
CRITICAL
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the...
2026-04-03
NVD CVE
CVE-2026-34937: PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() i
HIGH
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c "<code>" and passing it to...
2026-04-03
NVD CVE
CVE-2026-34612: Kestra is an open-source, event-driven orchestration platform. Prior to version
CRITICAL
Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in...
2026-04-03
NVD CVE
CVE-2026-27634: Piwigo is an open source photo gallery application for the web. Prior to version
CRITICAL
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in...
2026-04-03
NVD CVE
CVE-2026-25726: Cloudreve is a self-hosted file management and sharing system. Prior to version
HIGH
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical...
2026-04-03
NVD CVE
CVE-2026-32186: Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized atta
CRITICAL
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-31818: Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-
CRITICAL
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP...
2026-04-03
NVD CVE
CVE-2026-5463: Command injection vulnerability in console.run_module_with_output() in pymetaspl
HIGH
Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended...
2026-04-03
NVD CVE
CVE-2026-33107: Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized at
CRITICAL
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-33105: Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori
CRITICAL
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-32213: Improper authorization in Azure AI Foundry allows an unauthorized attacker to el
CRITICAL
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
2026-04-02
NVD CVE
CVE-2026-35053: OneUptime is an open-source monitoring and observability platform. Prior to vers
CRITICAL
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST...
2026-04-02
NVD CVE
CVE-2026-34931: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim...
2026-04-02
NVD CVE
CVE-2026-35002: Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability
CRITICAL
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed...
2026-04-02
NVD CVE
CVE-2026-34932: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.
2026-04-02
NVD CVE
CVE-2026-5368: A vulnerability was determined in projectworlds Car Rental Project 1.0. The affe
HIGH
A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname...
2026-04-02
NVD CVE
CVE-2026-32871: FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2
CRITICAL
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is...
2026-04-01
NVD CVE
CVE-2026-34430: ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vul
HIGH
ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based...
2026-03-31
NVD CVE
CVE-2026-24148: NVIDIA Jetson for JetPack contains a vulnerability in the system initialization
HIGH
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of...
2026-03-31
NVD CVE
CVE-2026-24164: NVIDIA BioNeMo contains a vulnerability where a user could cause a deserializati
HIGH
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information...
2026-03-31
NVD CVE
CVE-2026-34359: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
HIGH
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs...
2026-03-31
NVD CVE
CVE-2026-34361: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CRITICAL
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that...
2026-03-31
NVD CVE
CVE-2026-34400: Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API
CRITICAL
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search...
2026-03-31
NVD CVE
CVE-2026-34156: NocoBase is an AI-powered no-code/low-code platform for building business applic
CRITICAL
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a...
2026-03-31
NVD CVE
CVE-2026-32916: OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vuln
CRITICAL
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes....