Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,269
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,141 - 7,160 of 12,780 CVEs

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea clusters configured for dual-stack networking with IPsec encryption enabled (trafficEncryptionMode: ipsec), Antrea fails...

Vendor: go
Product: antrea.io/antrea
Published: Apr 03, 2026
Source: GitHub

Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.

Vendor: pip
Product: ajenti-panel
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35167 HIGH - 7.1

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path components, traversal sequence...

Vendor: pip
Product: kedro
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35037 HIGH - 7.2

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arbitrary URL via the website_url query parameter and makes a server-side HTTP request to it without any validation of the target host or IP address. The ...

Vendor: go
Product: github.com/lin-snow/ech0
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35036 HIGH - 7.5

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a page title) through GET /api/website/title. That is legitimate product behavior, but the implementation is unsafe: the route is unauthenticated, accepts a...

Vendor: go
Product: github.com/lin-snow/ech0
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34986 HIGH - 7.5

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic...

Vendor: go
Product: github.com/go-jose/go-jose/v4
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35535 HIGH - 7.4

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

Vendor: Sudo project
Product: Sudo
Published: Apr 03, 2026
Source: NVD
CVE-2026-28815 HIGH - 7.5

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.

Vendor: Apple
Product: macOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-34780 HIGH - 8.4

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the co...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34774 HIGH - 8.1

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34771 HIGH - 7.5

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34770 HIGH - 7.0

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected,...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34769 HIGH - 7.8

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps ...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-32173 HIGH - 8.6

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_sre_agent
Published: Apr 03, 2026
Source: NVD
CVE-2022-4986 HIGH - 7.5

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service avai...

Published: Apr 02, 2026
Source: NVD
CVE-2026-35467 HIGH - 7.5

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Vendor: CERT/CC
Product: cveClient/encrypt-storage.js
Published: Apr 02, 2026
Source: NVD
CVE-2025-15620 HIGH - 8.6

HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot c...

Vendor: Belden
Product: Hirschmann HiOS Switch Platform
Published: Apr 02, 2026
Source: NVD
CVE-2024-14033 HIGH - 7.5

Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to...

Vendor: Belden
Product: Hirschmann EagleSDV
Published: Apr 02, 2026
Source: NVD
CVE-2026-34840 HIGH - 8.1

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSignatureValid() verifies the first <Signature> element i...

Vendor: OneUptime
Product: oneuptime
Published: Apr 02, 2026
Source: NVD
CVE-2026-34834 HIGH - 7.5

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via...

Vendor: bulwarkmail
Product: webmail
Published: Apr 02, 2026
Source: NVD