LIVE FEED
3595 events · 4 sources · newest first
Events in view
3595
all sources
Critical
1828
severity
Active sources
4
collectors
Last sync
2026-08-27 06:00
UTC
2026-04-03
NVD CVE
CVE-2026-25726: Cloudreve is a self-hosted file management and sharing system. Prior to version
HIGH
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical...
2026-04-03
NVD CVE
CVE-2026-5463: Command injection vulnerability in console.run_module_with_output() in pymetaspl
HIGH
Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline characters into module options such as RHOSTS. This breaks the intended...
2026-04-03
NVD CVE
CVE-2026-32213: Improper authorization in Azure AI Foundry allows an unauthorized attacker to el
CRITICAL
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-33105: Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori
CRITICAL
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-33107: Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized at
CRITICAL
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
CVE-2026-31818: Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-
CRITICAL
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP...
2026-04-03
NVD CVE
CVE-2026-32186: Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized atta
CRITICAL
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
2026-04-02
NVD CVE
CVE-2026-32871: FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2
CRITICAL
FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clients by parsing OpenAPI specifications. The RequestDirector class is...
2026-04-02
NVD CVE
CVE-2026-35002: Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability
CRITICAL
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed...
2026-04-02
CISA KEV
TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or...
2026-04-02
NVD CVE
CVE-2026-5368: A vulnerability was determined in projectworlds Car Rental Project 1.0. The affe
HIGH
A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname...
2026-04-02
NVD CVE
CVE-2026-34931: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim...
2026-04-02
NVD CVE
CVE-2026-34932: hoppscotch is an open source API development ecosystem. Prior to version 2026.3.
CRITICAL
hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.
2026-04-02
NVD CVE
CVE-2026-35053: OneUptime is an open-source monitoring and observability platform. Prior to vers
CRITICAL
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST...
2026-04-01
NVD CVE
CVE-2026-34430: ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vul
HIGH
ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based...
2026-04-01
CISA KEV
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect...
2026-03-31
NVD CVE
Impact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both...
2026-03-31
NVD CVE
CVE-2026-34361: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
CRITICAL
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that...
2026-03-31
NVD CVE
CVE-2026-34359: HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i
HIGH
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs...
2026-03-31
NVD CVE
CVE-2026-24164: NVIDIA BioNeMo contains a vulnerability where a user could cause a deserializati
HIGH
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information...
2026-03-31
NVD CVE
CVE-2026-34156: NocoBase is an AI-powered no-code/low-code platform for building business applic
CRITICAL
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a...
2026-03-31
NVD CVE
CVE-2026-34162: FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT
CRITICAL
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP...
2026-03-31
NVD CVE
CVE-2026-34221: MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and
CRITICAL
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used...
2026-03-31
NVD CVE
CVE-2026-34532: Parse Server is an open source backend that can be deployed to any infrastructur
CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by...
2026-03-31
NVD CVE
CVE-2026-34235: PJSIP is a free and open source multimedia communication library written in C. P
CRITICAL
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted...
2026-03-31
NVD CVE
CVE-2026-34400: Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API
CRITICAL
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search...
2026-03-31
NVD CVE
CVE-2026-24148: NVIDIA Jetson for JetPack contains a vulnerability in the system initialization
HIGH
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of...
2026-03-31
NVD CVE
CVE-2026-32916: OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vuln
CRITICAL
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes....
2026-03-30
NVD CVE
CVE-2025-15036: A path traversal vulnerability exists in the `extract_archive_to_dir` function w
CRITICAL
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions...
2026-03-30
NVD CVE
CVE-2025-15379: A command injection vulnerability exists in MLflow's model serving container ini
CRITICAL
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`,...
2026-03-30
CISA KEV
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
2026-03-27
NVD CVE
CVE-2026-33943: Happy DOM is a JavaScript implementation of a web browser without its graphical
HIGH
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to...
2026-03-27
NVD CVE
CVE-2026-33701: OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a
CRITICAL
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that...
2026-03-27
NVD CVE
CVE-2026-33896: Forge (also called `node-forge`) is a native implementation of Transport Layer S
HIGH
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements...
2026-03-27
CISA KEV
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
2026-03-27
NVD CVE
CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the f
HIGH
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior,...
2026-03-26
NVD CVE
CVE-2026-26213: thingino-firmware versions up to the firmware-2026-03-16 release contains an una
CRITICAL
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive portal CGI script that allows remote attackers to execute arbitrary...
2026-03-26
CISA KEV
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database...
2026-03-25
CISA KEV
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
2026-03-24
NVD CVE
CVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style
CRITICAL
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is...