Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,287
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,081 - 7,100 of 12,780 CVEs
CVE-2026-35209 HIGH - 7.5

defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype ...

Vendor: npm
Product: defu
Published: Apr 04, 2026
Source: GitHub
CVE-2026-30762 HIGH - 7.5

LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass

Vendor: pip
Product: lightrag-hku
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35442 HIGH - 8.1

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated us...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35412 HIGH - 7.1

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs onl...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35409 HIGH - 7.7

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address validation mechanism used to block requests to local and private networks could be circu...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35408 HIGH - 8.7

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35394 HIGH - 8.3

Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone c...

Vendor: npm
Product: @mobilenext/mobile-mcp
Published: Apr 04, 2026
Source: GitHub

@hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via crafted HTTP header values. Three regular expressions used to parse Content-Type and Content-Disposition headers contain patterns susc...

Vendor: npm
Product: @hapi/content
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35187 HIGH - 7.7

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authent...

Vendor: pip
Product: pyload-ng
Published: Apr 04, 2026
Source: GitHub
CVE-2026-34607 HIGH - 7.2

Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in the emUnZip() function (include/lib/common.php:793). When extracting ZIP archives (plugin/template uploads, backup imports), the function calls $zip->extractTo($path) without san...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-33184 HIGH - 7.5

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, the discovery handler accepts a peer-controlled limit during handshake and stores it unchanged. The immediate HandshakeAck path then honors limit ...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 03, 2026
Source: NVD
CVE-2017-20238 HIGH - 7.1

Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access to managed devices by bypassing access control mechanisms. Attackers can exploit alternative interfaces such as t...

Vendor: Belden
Product: Hirschmann Industrial HiVision
Published: Apr 03, 2026
Source: NVD
CVE-2026-35044 HIGH - 8.8

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extensi...

Vendor: pip
Product: bentoml
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34990 HIGH - 7.8

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token...

Vendor: OpenPrinting
Product: cups
Published: Apr 03, 2026
Source: NVD
CVE-2026-33175 HIGH - 8.8

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is u...

Vendor: jupyterhub
Product: oauthenticator
Published: Apr 03, 2026
Source: NVD
CVE-2026-28797 HIGH - 8.8

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Templ...

Vendor: infiniflow
Product: ragflow
Published: Apr 03, 2026
Source: NVD
CVE-2026-27885 HIGH - 7.2

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including us...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2026-27834 HIGH - 7.2

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing authenticated administra...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2026-27833 HIGH - 7.5

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2016-15058 HIGH - 8.1

Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enable...

Vendor: Belden
Product: Hirschmann HiLCOS Classic Platform
Published: Apr 03, 2026
Source: NVD