Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,277
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,101 - 7,120 of 12,780 CVEs
CVE-2015-10148 HIGH - 8.2

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-i...

Vendor: Belden
Product: Hirschmann HiLCOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-35043 HIGH - 7.8

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 1648 interpolates system_packages directly into a sh...

Vendor: pip
Product: bentoml
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35042 HIGH - 7.5

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token in...

Vendor: npm
Product: fast-jwt
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35029 HIGH - 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment...

Vendor: pip
Product: litellm
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35470 HIGH - 8.8

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability. The righe parameter received via $_GET['righe'] is directly concatenate...

Vendor: composer
Product: devcode-it/openstamanager
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34824 HIGH - 7.5

Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of W...

Vendor: pip
Product: mesop
Published: Apr 03, 2026
Source: GitHub
CVE-2026-33752 HIGH - 8.6

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpo...

Vendor: pip
Product: curl_cffi
Published: Apr 03, 2026
Source: GitHub
CVE-2026-5485 HIGH - 7.8

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To re...

Published: Apr 03, 2026
Source: NVD
CVE-2026-35562 HIGH - 7.5

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate thi...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-35561 HIGH - 7.4

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate ...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-35560 HIGH - 7.4

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This o...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-35558 HIGH - 7.8

Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-32646 HIGH - 7.5

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

Vendor: Gardyn
Product: Cloud API
Published: Apr 03, 2026
Source: NVD
CVE-2026-22665 HIGH - 8.1

prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-de...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2026-22664 HIGH - 7.7

prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validati...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2026-22663 HIGH - 7.5

prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associated with private prompts. Attackers can exploit these missing au...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2026-22661 HIGH - 8.1

prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized filenames containing path traversal sequences. Attackers can exploit missing ser...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD
CVE-2025-10681 HIGH - 8.6

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers.

Vendor: Gardyn
Product: Mobile Application, Cloud API
Published: Apr 03, 2026
Source: NVD
CVE-2022-4987 HIGH - 7.3

Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker to execute arbitrary binaries. Due to insufficient path sanitization, an attacker can place a malicious binary i...

Published: Apr 03, 2026
Source: NVD
CVE-2020-37216 HIGH - 7.5

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a l...

Vendor: Belden
Product: Hirschmann HiOS
Published: Apr 03, 2026
Source: NVD