Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

34125
Total
2661
Critical
10081
High
10307
Medium
CVE ID Severity Score Description Published
CVE-2026-34061 MEDIUM 4.9 nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an elected validator proposer can … Apr 03, 2026
CVE-2026-34052 MEDIUM 5.9 LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that … Apr 03, 2026
CVE-2026-33184 HIGH 7.5 nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, the discovery handler accepts a … Apr 03, 2026
CVE-2021-4477 CRITICAL 9.1 Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall … Apr 03, 2026
CVE-2018-25236 CRITICAL 9.8 Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management … Apr 03, 2026
CVE-2017-20238 HIGH 7.1 Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access … Apr 03, 2026
CVE-2017-20236 CRITICAL 9.8 ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject … Apr 03, 2026
CVE-2017-20235 CRITICAL 9.1 ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain … Apr 03, 2026
CVE-2017-20234 CRITICAL 9.8 GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string … Apr 03, 2026
CVE-2017-20233 MEDIUM 5.4 Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP … Apr 03, 2026
CVE-2026-34990 UNKNOWN OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can … Apr 03, 2026
CVE-2026-34980 UNKNOWN OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with … Apr 03, 2026
CVE-2026-34979 MEDIUM 5.3 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer … Apr 03, 2026
CVE-2026-34978 MEDIUM 6.5 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. … Apr 03, 2026
CVE-2026-34947 UNKNOWN Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, staged user custom fields … Apr 03, 2026
CVE-2026-33709 UNKNOWN JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows … Apr 03, 2026
CVE-2026-33175 HIGH 8.8 OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in … Apr 03, 2026
CVE-2026-28797 UNKNOWN RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text … Apr 03, 2026
CVE-2026-27885 HIGH 7.2 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the … Apr 03, 2026
CVE-2026-27834 HIGH 7.2 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service … Apr 03, 2026
CVE-2026-27833 HIGH 7.5 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the … Apr 03, 2026
CVE-2026-27634 UNKNOWN Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in … Apr 03, 2026
CVE-2026-27481 UNKNOWN Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass vulnerability … Apr 03, 2026
CVE-2026-27456 MEDIUM 4.7 util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from … Apr 03, 2026
CVE-2026-27447 MEDIUM 4.8 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an … Apr 03, 2026