Total CVEs

124,116

Critical Severity

2,092

High Severity

7,265

Last 7 Days

1,051
Quick preset (or use dates below)
Clear Filters
๐Ÿ“† Custom Date Range: Apr 3, 2026 - Apr 3, 2026 Clear Custom Dates โ†’
Showing 1 - 20 of 251 CVEs
CVE-2026-35181 MEDIUM - 4.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based security check via ignoreTableSecurityCheck(), remo...

Vendor: composer
Product: wwbn/avideo
Published: Apr 03, 2026
Source: GitHub

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159...

Vendor: go
Product: github.com/gohugoio/hugo
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35179 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access token,...

Vendor: composer
Product: wwbn/avideo
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35468 MEDIUM - 5.3

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers assume that the history index is always available and call blockchain.history_store.history_index().unw...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 03, 2026
Source: NVD
CVE-2026-34933 MEDIUM - 5.5

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-r...

Vendor: avahi
Product: avahi
Published: Apr 03, 2026
Source: NVD
CVE-2026-34788 MEDIUM - 6.5

Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string without using parameterized queries or proper escapin...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34787 MEDIUM - 6.5

Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. The $plugin parameter from the GET request is directly used in a require_once path without proper sanitization. If the CSRF token check can ...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34612 CRITICAL - 9.9

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authe...

Vendor: kestra-io
Product: kestra
Published: Apr 03, 2026
Source: NVD
CVE-2026-34607 HIGH - 7.2

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls $zip->extractTo($path) without san...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34229 MEDIUM - 6.1

Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via URI scheme validation bypass. This issue has been patched in version 2.6.8.

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD

Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parameters. The server first downloads and executes the SQL file, then downloads the ZIP file and extracts it directly into the web root directory. This proc...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34061 MEDIUM - 4.9

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an elected validator proposer can send an election macro block whose header.interlink does not match the canonical next interlink. Honest validato...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 03, 2026
Source: NVD
CVE-2026-33184 HIGH - 7.5

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, the discovery handler accepts a peer-controlled limit during handshake and stores it unchanged. The immediate HandshakeAck path then honors limit ...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 03, 2026
Source: NVD
CVE-2021-4477 CRITICAL - 9.1

Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by establishing IPv6 IPsec connections (IKEv1 or IKEv2) while simulta...

Published: Apr 03, 2026
Source: NVD
CVE-2018-25236 CRITICAL - 9.8

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attac...

Vendor: Belden
Product: Hirschmann HiOS, Hirschmann HiSecOS EAGLE
Published: Apr 03, 2026
Source: NVD
CVE-2017-20238 HIGH - 7.1

Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as t...

Vendor: Belden
Product: Hirschmann Industrial HiVision
Published: Apr 03, 2026
Source: NVD
CVE-2017-20236 CRITICAL - 9.8

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerabil...

Vendor: ProSoft Technology
Product: ICX35-HWC Cellular Gateway
Published: Apr 03, 2026
Source: NVD
CVE-2017-20235 CRITICAL - 9.1

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism ...

Vendor: ProSoft Technology
Product: ICX35-HWC Cellular Gateway
Published: Apr 03, 2026
Source: NVD
CVE-2017-20234 CRITICAL - 9.8

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and ...

Vendor: Belden
Product: GarrettCom Magnum 6K and 10K Managed Switches
Published: Apr 03, 2026
Source: NVD
CVE-2017-20233 MEDIUM - 5.4

Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can...

Vendor: Belden
Product: Hirschmann HiLCOS OpenBAT, BAT450, WLC, Hirschmann HiLCOS BAT867
Published: Apr 03, 2026
Source: NVD