Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34313
Total
2675
Critical
10128
High
10348
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-13916 | MEDIUM | 5.9 | IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | Apr 01, 2026 |
| CVE-2026-5311 | MEDIUM | 5.3 | A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, … | Apr 01, 2026 |
| CVE-2026-34872 | CRITICAL | 9.1 | An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due … | Apr 01, 2026 |
| CVE-2026-34750 | MEDIUM | 6.5 | Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3, the client-upload signed-URL endpoints … | Apr 01, 2026 |
| CVE-2026-34749 | MEDIUM | 5.4 | Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication … | Apr 01, 2026 |
| CVE-2026-34748 | HIGH | 8.7 | Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerability existed in … | Apr 01, 2026 |
| CVE-2026-34747 | HIGH | 8.5 | Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker could … | Apr 01, 2026 |
| CVE-2026-34746 | HIGH | 7.7 | Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the … | Apr 01, 2026 |
| CVE-2026-34456 | CRITICAL | 9.1 | Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability … | Apr 01, 2026 |
| CVE-2026-34455 | UNKNOWN | — | Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository classes pass the user-supplied sort_by query … | Apr 01, 2026 |
| CVE-2025-66442 | MEDIUM | 5.1 | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto … | Apr 01, 2026 |
| CVE-2026-35000 | MEDIUM | 6.5 | ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementation that allows attackers to read arbitrary local files by using unblocked … | Apr 01, 2026 |
| CVE-2026-34874 | HIGH | 7.5 | An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows … | Apr 01, 2026 |
| CVE-2026-34871 | MEDIUM | 6.7 | An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random … | Apr 01, 2026 |
| CVE-2026-25835 | HIGH | 7.7 | Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). | Apr 01, 2026 |
| CVE-2026-25833 | HIGH | 7.5 | Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function | Apr 01, 2026 |
| CVE-2026-5199 | UNKNOWN | — | A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation … | Apr 01, 2026 |
| CVE-2026-34875 | CRITICAL | 9.8 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. | Apr 01, 2026 |
| CVE-2026-34751 | CRITICAL | 9.1 | Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery … | Apr 01, 2026 |
| CVE-2026-34447 | MEDIUM | 5.5 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external … | Apr 01, 2026 |
| CVE-2026-34446 | MEDIUM | 4.7 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code … | Apr 01, 2026 |
| CVE-2026-34445 | HIGH | 8.6 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s … | Apr 01, 2026 |
| CVE-2026-34397 | MEDIUM | 6.3 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is … | Apr 01, 2026 |
| CVE-2026-34376 | HIGH | 7.5 | PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-control vulnerability allows … | Apr 01, 2026 |
| CVE-2026-34236 | HIGH | 8.2 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP … | Apr 01, 2026 |