LIVE FEED
1777 events · 4 sources · newest first
Events in view
1777
all sources
Critical
1499
severity
Active sources
4
collectors
Last sync
2026-08-27 00:00
UTC
2026-03-31
NVD CVE
CVE-2026-34532: Parse Server is an open source backend that can be deployed to any infrastructur
CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by...
2026-03-31
NVD CVE
CVE-2026-34221: MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and
CRITICAL
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used...
2026-03-31
NVD CVE
CVE-2026-34235: PJSIP is a free and open source multimedia communication library written in C. P
CRITICAL
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted...
2026-03-31
NVD CVE
Impact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both...
2026-03-31
NVD CVE
CVE-2026-34162: FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT
CRITICAL
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP...
2026-03-30
NVD CVE
CVE-2025-15379: A command injection vulnerability exists in MLflow's model serving container ini
CRITICAL
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`,...
2026-03-30
NVD CVE
CVE-2025-15036: A path traversal vulnerability exists in the `extract_archive_to_dir` function w
CRITICAL
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions...
2026-03-27
NVD CVE
CVE-2026-33701: OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a
CRITICAL
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that...
2026-03-27
NVD CVE
CVE-2026-33896: Forge (also called `node-forge`) is a native implementation of Transport Layer S
HIGH
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements...
2026-03-27
NVD CVE
CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the f
HIGH
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior,...
2026-03-27
NVD CVE
CVE-2026-33943: Happy DOM is a JavaScript implementation of a web browser without its graphical
HIGH
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to...
2026-03-26
NVD CVE
CVE-2026-26213: thingino-firmware versions up to the firmware-2026-03-16 release contains an una
CRITICAL
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive portal CGI script that allows remote attackers to execute arbitrary...
2026-03-24
NVD CVE
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
CRITICAL
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
CRITICAL
Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
CRITICAL
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
CRITICAL
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style
CRITICAL
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is...
2026-03-24
NVD CVE
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
CRITICAL
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
2026-03-24
NVD CVE
CVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails application
CRITICAL
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved...
2026-03-23
NVD CVE
CVE-2026-31848: Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_p
CRITICAL
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the encoding is...
2026-03-23
NVD CVE
CVE-2026-4601: Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Crypto
HIGH
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private...
2026-03-23
NVD CVE
CVE-2026-4600: Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verif
HIGH
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509...
2026-03-20
NVD CVE
CVE-2026-33228: flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function
CRITICAL
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are...
2026-03-20
NVD CVE
CVE-2025-15608: This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient i
CRITICAL
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that...
2026-03-20
NVD CVE
CVE-2026-33210: Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versi
CRITICAL
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information...
2026-03-19
NVD CVE
CVE-2006-10003: XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflo
CRITICAL
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at...
2026-03-19
NVD CVE
CVE-2025-71257: BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentica
HIGH
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated...
2026-03-18
NVD CVE
CVE-2026-28500: Open Neural Network Exchange (ONNX) is an open standard for machine learning int
HIGH
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the...
2026-03-18
NVD CVE
CVE-2025-15031: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file
CRITICAL
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables...
2026-03-18
NVD CVE
CVE-2026-27459: pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22
CRITICAL
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256...
2026-03-16
NVD CVE
CVE-2026-32640: SimpleEval is a library for adding evaluatable expressions into python projects.
CRITICAL
SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects...
2026-03-13
NVD CVE
CVE-2026-23941: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab
CRITICAL
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.
This vulnerability is associated with program files...
2026-03-13
NVD CVE
CVE-2026-31806: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0
CRITICAL
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using...
2026-03-11
NVD CVE
CVE-2026-29515: MiCode FileExplorer contains an authentication bypass vulnerability in the embed
CRITICAL
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username...
2026-03-09
NVD CVE
CVE-2026-3823: EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Ov
CRITICAL
EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
2026-03-09
NVD CVE
CVE-2026-25960: vLLM is an inference and serving engine for large language models (LLMs). The SS
HIGH
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing...
2026-03-07
NVD CVE
CVE-2026-29186: Backstage is an open framework for building developer portals. Prior to version
HIGH
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package...
2026-03-06
NVD CVE
CVE-2026-28802: Authlib is a Python library which builds OAuth and OpenID Connect servers. From
CRITICAL
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was...