Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

34125
Total
2661
Critical
10081
High
10307
Medium
CVE ID Severity Score Description Published
CVE-2018-25237 CRITICAL 9.8 Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote … Apr 03, 2026
CVE-2016-15058 HIGH 8.1 Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability … Apr 03, 2026
CVE-2015-10148 HIGH 8.2 Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that … Apr 03, 2026
CVE-2026-5485 HIGH 7.8 OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary … Apr 03, 2026
CVE-2026-35562 HIGH 7.5 Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial … Apr 03, 2026
CVE-2026-35561 HIGH 7.4 Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack … Apr 03, 2026
CVE-2026-35560 HIGH 7.4 Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication … Apr 03, 2026
CVE-2026-35559 MEDIUM 6.5 Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using … Apr 03, 2026
CVE-2026-35558 HIGH 7.8 Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code … Apr 03, 2026
CVE-2026-34511 MEDIUM 5.3 OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who … Apr 03, 2026
CVE-2026-32662 MEDIUM 5.3 Development and test API endpoints are present that mirror production functionality. Apr 03, 2026
CVE-2026-32646 HIGH 7.5 A specific administrative endpoint is accessible without proper authentication, exposing device management functions. Apr 03, 2026
CVE-2026-28767 MEDIUM 5.3 A specific administrative endpoint notifications is accessible without proper authentication. Apr 03, 2026
CVE-2026-28766 CRITICAL 9.3 A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. Apr 03, 2026
CVE-2026-26058 MEDIUM 6.1 Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path … Apr 03, 2026
CVE-2026-25742 MEDIUM 5.3 Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, … Apr 03, 2026
CVE-2026-25197 CRITICAL 9.1 A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. Apr 03, 2026
CVE-2026-22665 HIGH 8.1 prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing … Apr 03, 2026
CVE-2026-22664 HIGH 7.7 prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests … Apr 03, 2026
CVE-2026-22663 HIGH 7.5 prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized … Apr 03, 2026
CVE-2026-22662 MEDIUM 4.3 prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches … Apr 03, 2026
CVE-2026-22661 HIGH 8.1 prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system … Apr 03, 2026
CVE-2025-10681 HIGH 8.6 Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within … Apr 03, 2026
CVE-2022-4987 HIGH 7.3 Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of user-configured external applications that allows a local attacker … Apr 03, 2026
CVE-2020-37216 HIGH 7.5 Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length … Apr 03, 2026