Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34125
Total
2661
Critical
10081
High
10307
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34061 | MEDIUM | 4.9 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an elected validator proposer can … | Apr 03, 2026 |
| CVE-2026-34052 | MEDIUM | 5.9 | LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-level dictionary that … | Apr 03, 2026 |
| CVE-2026-33184 | HIGH | 7.5 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, the discovery handler accepts a … | Apr 03, 2026 |
| CVE-2021-4477 | CRITICAL | 9.1 | Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall … | Apr 03, 2026 |
| CVE-2018-25236 | CRITICAL | 9.8 | Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management … | Apr 03, 2026 |
| CVE-2017-20238 | HIGH | 7.1 | Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorization vulnerability that allows read-only users to gain write access … | Apr 03, 2026 |
| CVE-2017-20236 | CRITICAL | 9.8 | ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject … | Apr 03, 2026 |
| CVE-2017-20235 | CRITICAL | 9.1 | ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain … | Apr 03, 2026 |
| CVE-2017-20234 | CRITICAL | 9.8 | GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string … | Apr 03, 2026 |
| CVE-2017-20233 | MEDIUM | 5.4 | Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP … | Apr 03, 2026 |
| CVE-2026-34990 | UNKNOWN | — | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can … | Apr 03, 2026 |
| CVE-2026-34980 | UNKNOWN | — | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with … | Apr 03, 2026 |
| CVE-2026-34979 | MEDIUM | 5.3 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer … | Apr 03, 2026 |
| CVE-2026-34978 | MEDIUM | 6.5 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. … | Apr 03, 2026 |
| CVE-2026-34947 | UNKNOWN | — | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, staged user custom fields … | Apr 03, 2026 |
| CVE-2026-33709 | UNKNOWN | — | JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows … | Apr 03, 2026 |
| CVE-2026-33175 | HIGH | 8.8 | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in … | Apr 03, 2026 |
| CVE-2026-28797 | UNKNOWN | — | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text … | Apr 03, 2026 |
| CVE-2026-27885 | HIGH | 7.2 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the … | Apr 03, 2026 |
| CVE-2026-27834 | HIGH | 7.2 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service … | Apr 03, 2026 |
| CVE-2026-27833 | HIGH | 7.5 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the … | Apr 03, 2026 |
| CVE-2026-27634 | UNKNOWN | — | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in … | Apr 03, 2026 |
| CVE-2026-27481 | UNKNOWN | — | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass vulnerability … | Apr 03, 2026 |
| CVE-2026-27456 | MEDIUM | 4.7 | util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from … | Apr 03, 2026 |
| CVE-2026-27447 | MEDIUM | 4.8 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an … | Apr 03, 2026 |