Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
Showing 1,801 - 1,820 of 3,569 CVEs
CVE-2026-33107 CRITICAL - 10.0

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_databricks
Published: Apr 03, 2026
Source: NVD
CVE-2026-33105 CRITICAL - 10.0

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_kubernetes_service
Published: Apr 03, 2026
Source: NVD
CVE-2026-32213 CRITICAL - 10.0

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_ai_foundry
Published: Apr 03, 2026
Source: NVD
CVE-2026-32211 CRITICAL - 9.1

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: azure_web_apps
Published: Apr 03, 2026
Source: NVD
CVE-2026-26135 CRITICAL - 9.6

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_custom_locations_resource_provider
Published: Apr 03, 2026
Source: NVD
CVE-2026-34976 CRITICAL - 10.0

Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which requires Guardian-of-Galaxy authentication, restore...

Vendor: go
Product: github.com/dgraph-io/dgraph/v25
Published: Apr 02, 2026
Source: GitHub
CVE-2026-34950 CRITICAL - 9.1

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT algorithm confusion attack that CVE-2023-48223 patche...

Vendor: npm
Product: fast-jwt
Published: Apr 02, 2026
Source: GitHub
CVE-2026-34838 CRITICAL - 9.9

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object...

Vendor: Intermesh
Product: groupoffice
Published: Apr 02, 2026
Source: NVD
CVE-2024-14034 CRITICAL - 9.8

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication h...

Vendor: Belden
Product: Hirschmann HiEOS LRS11
Published: Apr 02, 2026
Source: NVD
CVE-2026-34758 CRITICAL - 9.1

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.

Vendor: OneUptime
Product: oneuptime
Published: Apr 02, 2026
Source: NVD
CVE-2026-34745 CRITICAL - 9.1

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not applied to the unauthenticated /api/uploadChunked/public endpoint in the same file (app/server/fireshare/api.py). An u...

Vendor: ShaneIsrael
Product: fireshare
Published: Apr 02, 2026
Source: NVD
CVE-2026-34841 CRITICAL - 9.8

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran ...

Vendor: npm
Product: @usebruno/cli
Published: Apr 02, 2026
Source: GitHub
CVE-2026-34717 CRITICAL - 9.9

OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE clauses without parameterization. This issue has been patched in version 17.2.3.

Vendor: opf
Product: openproject
Published: Apr 02, 2026
Source: NVD
CVE-2026-34877 CRITICAL - 9.8

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused b...

Vendor: arm
Product: mbed_tls
Published: Apr 02, 2026
Source: NVD
CVE-2026-33950 CRITICAL - 9.4

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated attacker can gain full Administrator access to the SignalK server at any time, a...

Vendor: SignalK
Product: signalk-server
Published: Apr 02, 2026
Source: NVD
CVE-2026-25212 CRITICAL - 9.9

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-33746 CRITICAL - 9.8

Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmetric HMAC-SHA256 signer via lcobucci/jwt, it only validated ti...

Vendor: ConvoyPanel
Product: panel
Published: Apr 02, 2026
Source: NVD
CVE-2026-2701 CRITICAL - 9.1

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Published: Apr 02, 2026
Source: NVD
CVE-2026-2699 CRITICAL - 9.8

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

Published: Apr 02, 2026
Source: NVD
CVE-2026-33615 CRITICAL - 9.1

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.

Vendor: MB connect line
Product: mbCONNECT24, mymbCONNECT24
Published: Apr 02, 2026
Source: NVD