Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,781 - 1,800 of 3,443 CVEs
CVE-2017-20235 CRITICAL - 9.1

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functions without valid credentials. Attackers can bypass the authentication mechanism ...

Vendor: ProSoft Technology
Product: ICX35-HWC Cellular Gateway
Published: Apr 03, 2026
Source: NVD
CVE-2017-20234 CRITICAL - 9.8

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and ...

Vendor: Belden
Product: GarrettCom Magnum 6K and 10K Managed Switches
Published: Apr 03, 2026
Source: NVD
CVE-2026-27634 CRITICAL - 9.8

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without any escaping or type v...

Vendor: Piwigo
Product: Piwigo
Published: Apr 03, 2026
Source: NVD
CVE-2018-25237 CRITICAL - 9.8

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers ca...

Vendor: Belden
Product: Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One)
Published: Apr 03, 2026
Source: NVD
CVE-2026-35030 CRITICAL - 9.1

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 ...

Vendor: pip
Product: litellm
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35471 CRITICAL - 9.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.

Vendor: go
Product: github.com/patrickhener/goshs
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34208 CRITICAL - 10.0

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject). Because this.construct...

Vendor: npm
Product: @nyariv/sandboxjs
Published: Apr 03, 2026
Source: GitHub
CVE-2026-28766 CRITICAL - 9.3

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

Vendor: Gardyn
Product: Cloud API
Published: Apr 03, 2026
Source: NVD
CVE-2026-25197 CRITICAL - 9.1

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

Vendor: Gardyn
Product: Cloud API
Published: Apr 03, 2026
Source: NVD
CVE-2017-20237 CRITICAL - 9.8

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over th...

Vendor: Belden
Product: Hirschmann Industrial HiVision
Published: Apr 03, 2026
Source: NVD
CVE-2026-28798 CRITICAL - 9.0

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain using a Cloudflare Tunnel) to make requests to internal loc...

Vendor: IceWhaleTech
Product: ZimaOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-0545 CRITICAL - 9.1

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`)...

Vendor: pip
Product: mlflow
Published: Apr 03, 2026
Source: NVD
CVE-2026-28373 CRITICAL - 9.6

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.

Published: Apr 03, 2026
Source: NVD
CVE-2026-35216 CRITICAL - 9.0

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint. No authentication is required to trigger the exploi...

Vendor: Budibase
Product: budibase
Published: Apr 03, 2026
Source: NVD
CVE-2026-31818 CRITICAL - 9.6

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the BLACKLIST_IPS env...

Vendor: Budibase
Product: budibase
Published: Apr 03, 2026
Source: NVD
CVE-2026-35393 CRITICAL - 9.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.

Vendor: go
Product: github.com/patrickhener/goshs
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35392 CRITICAL - 9.8

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.

Vendor: go
Product: github.com/patrickhener/goshs
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35039 CRITICAL - 9.1

fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for different tokens can lead to cache collisions. This could cause tokens to be mis-identified during the verification proces...

Vendor: npm
Product: fast-jwt
Published: Apr 03, 2026
Source: GitHub

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 31.0.0.0, the application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An atta...

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35171 CRITICAL - 9.8

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration schema supports the special () key, which enables arbitrary ca...

Vendor: pip
Product: kedro
Published: Apr 03, 2026
Source: GitHub