Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,527
Quick preset (or use dates below)
Clear Filters
Showing 7,561 - 7,580 of 13,549 CVEs
CVE-2026-33175 HIGH - 8.8

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email address on an Auth0 tenant to login to JupyterHub. When email is u...

Vendor: jupyterhub
Product: oauthenticator
Published: Apr 03, 2026
Source: NVD
CVE-2026-28797 HIGH - 8.8

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Templ...

Vendor: infiniflow
Product: ragflow
Published: Apr 03, 2026
Source: NVD
CVE-2026-27885 HIGH - 7.2

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including us...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2026-27834 HIGH - 7.2

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing authenticated administra...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2026-27833 HIGH - 7.5

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2016-15058 HIGH - 8.1

Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enable...

Vendor: Belden
Product: Hirschmann HiLCOS Classic Platform
Published: Apr 03, 2026
Source: NVD
CVE-2015-10148 HIGH - 8.2

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-i...

Vendor: Belden
Product: Hirschmann HiLCOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-35043 HIGH - 7.8

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 1648 interpolates system_packages directly into a sh...

Vendor: pip
Product: bentoml
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35042 HIGH - 7.5

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that fast-jwt does not understand, the library accepts the token in...

Vendor: npm
Product: fast-jwt
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35029 HIGH - 8.8

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment...

Vendor: pip
Product: litellm
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35470 HIGH - 8.8

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability. The righe parameter received via $_GET['righe'] is directly concatenate...

Vendor: composer
Product: devcode-it/openstamanager
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34824 HIGH - 7.5

Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of W...

Vendor: pip
Product: mesop
Published: Apr 03, 2026
Source: GitHub
CVE-2026-33752 HIGH - 8.6

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpo...

Vendor: pip
Product: curl_cffi
Published: Apr 03, 2026
Source: GitHub
CVE-2026-5485 HIGH - 7.8

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To re...

Published: Apr 03, 2026
Source: NVD
CVE-2026-35562 HIGH - 7.5

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate thi...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-35561 HIGH - 7.4

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate ...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-35560 HIGH - 7.4

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This o...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-35558 HIGH - 7.8

Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user...

Vendor: Amazon
Product: Amazon Athena ODBC driver
Published: Apr 03, 2026
Source: NVD
CVE-2026-32646 HIGH - 7.5

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

Vendor: Gardyn
Product: Cloud API
Published: Apr 03, 2026
Source: NVD
CVE-2026-22665 HIGH - 8.1

prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-de...

Vendor: f
Product: prompts.chat
Published: Apr 03, 2026
Source: NVD