Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33951
Total
2635
Critical
10034
High
10234
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-4498 | HIGH | 7.7 | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege … | Apr 08, 2026 |
| CVE-2026-33461 | HIGH | 7.7 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API … | Apr 08, 2026 |
| CVE-2026-33460 | MEDIUM | 4.3 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana … | Apr 08, 2026 |
| CVE-2026-31017 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized … | Apr 08, 2026 |
| CVE-2026-30080 | UNKNOWN | — | OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request … | Apr 08, 2026 |
| CVE-2026-30075 | UNKNOWN | — | OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). … | Apr 08, 2026 |
| CVE-2026-2377 | MEDIUM | 6.5 | A flaw was found in mirror-registry. Authenticated users can exploit the log export feature by providing a specially crafted web address (URL). This allows the … | Apr 08, 2026 |
| CVE-2025-57175 | MEDIUM | 6.4 | Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password. | Apr 08, 2026 |
| CVE-2025-14243 | MEDIUM | 5.3 | A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different … | Apr 08, 2026 |
| CVE-2023-46945 | UNKNOWN | — | QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request | Apr 08, 2026 |
| CVE-2026-33753 | MEDIUM | 6.2 | rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification … | Apr 08, 2026 |
| CVE-2026-33229 | UNKNOWN | — | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected … | Apr 08, 2026 |
| CVE-2026-31040 | UNKNOWN | — | A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution. | Apr 08, 2026 |
| CVE-2026-39865 | MEDIUM | 5.9 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug … | Apr 08, 2026 |
| CVE-2026-39410 | MEDIUM | 4.8 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling … | Apr 08, 2026 |
| CVE-2026-39409 | UNKNOWN | — | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. … | Apr 08, 2026 |
| CVE-2026-39408 | UNKNOWN | — | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to … | Apr 08, 2026 |
| CVE-2026-39407 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static … | Apr 08, 2026 |
| CVE-2026-39406 | MEDIUM | 5.3 | @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by … | Apr 08, 2026 |
| CVE-2026-39394 | HIGH | 8.1 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller … | Apr 08, 2026 |
| CVE-2026-39393 | HIGH | 8.1 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the install route … | Apr 08, 2026 |
| CVE-2026-39392 | MEDIUM | 5.5 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Pages module … | Apr 08, 2026 |
| CVE-2026-39391 | MEDIUM | 4.8 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the blacklist (ban) … | Apr 08, 2026 |
| CVE-2026-39390 | MEDIUM | 5.5 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps … | Apr 08, 2026 |
| CVE-2026-39389 | MEDIUM | 6.7 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is … | Apr 08, 2026 |