Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
30387
Total
2427
Critical
9093
High
9467
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34046 | UNKNOWN | — | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` … | Mar 27, 2026 |
| CVE-2026-33938 | HIGH | 8.1 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template … | Mar 27, 2026 |
| CVE-2026-33937 | CRITICAL | 9.8 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to … | Mar 27, 2026 |
| CVE-2026-33916 | MEDIUM | 4.7 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via … | Mar 27, 2026 |
| CVE-2026-33907 | MEDIUM | 6.5 | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing … | Mar 27, 2026 |
| CVE-2026-33906 | HIGH | 7.2 | Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore … | Mar 27, 2026 |
| CVE-2026-33904 | MEDIUM | 6.5 | Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire … | Mar 27, 2026 |
| CVE-2026-33903 | MEDIUM | 6.5 | Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker … | Mar 27, 2026 |
| CVE-2026-33896 | HIGH | 7.4 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints … | Mar 27, 2026 |
| CVE-2026-33895 | HIGH | 7.5 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures … | Mar 27, 2026 |
| CVE-2026-33894 | HIGH | 7.5 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged … | Mar 27, 2026 |
| CVE-2026-33891 | HIGH | 7.5 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists … | Mar 27, 2026 |
| CVE-2026-33887 | MEDIUM | 5.4 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions … | Mar 27, 2026 |
| CVE-2026-33886 | MEDIUM | 6.5 | Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel … | Mar 27, 2026 |
| CVE-2026-33885 | MEDIUM | 6.1 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation … | Mar 27, 2026 |
| CVE-2026-33884 | MEDIUM | 4.3 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to … | Mar 27, 2026 |
| CVE-2026-33883 | MEDIUM | 6.1 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into … | Mar 27, 2026 |
| CVE-2026-33882 | MEDIUM | 6.5 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to … | Mar 27, 2026 |
| CVE-2026-33881 | UNKNOWN | — | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals … | Mar 27, 2026 |
| CVE-2026-33879 | UNKNOWN | — | Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP … | Mar 27, 2026 |
| CVE-2026-33875 | CRITICAL | 9.3 | Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to … | Mar 27, 2026 |
| CVE-2026-33874 | HIGH | 7.8 | Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of … | Mar 27, 2026 |
| CVE-2026-33873 | UNKNOWN | — | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python … | Mar 27, 2026 |
| CVE-2026-32187 | MEDIUM | 4.2 | Microsoft Edge (Chromium-based) Defense in Depth Vulnerability | Mar 27, 2026 |
| CVE-2026-4975 | HIGH | 8.8 | A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The … | Mar 27, 2026 |