CVEDatabase.com Logo

SearchCVE Vulnerabilities withAI-Powered Remediation Guidance

Powerful Analysis Tools

Everything you need to secure your infrastructure

CVE Trends & Highlights

Timeframe:
#1
CVE-2026-4688
CRITICAL

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderb...

Mar 24
10.0CVSS
#2
CVE-2026-34162
CRITICAL

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is expo...

Mar 31
10.0CVSS
#3
CVE-2026-4725
CRITICAL

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Mar 24
10.0CVSS
#4
CVE-2026-32169
CRITICAL

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mar 19
10.0CVSS
#5
CVE-2026-32760
CRITICAL

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2...

Mar 20
10.0CVSS
#6
CVE-2026-33054
CRITICAL

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that...

Mar 20
10.0CVSS
#7
CVE-2026-4689
CRITICAL

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR...

Mar 24
10.0CVSS
#8
CVE-2026-32213
CRITICAL

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Apr 3
10.0CVSS
#9
CVE-2026-33105
CRITICAL

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Apr 3
10.0CVSS
#10
CVE-2026-34208
CRITICAL

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), b...

Apr 6
10.0CVSS
#11
CVE-2026-32871
CRITICAL

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP client...

Apr 2
10.0CVSS
#12
CVE-2026-33107
CRITICAL

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Apr 3
10.0CVSS
#13
CVE-2026-32186
CRITICAL

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

Apr 3
10.0CVSS
#14
CVE-2026-4692
CRITICAL

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbir...

Mar 24
10.0CVSS
#15
CVE-2026-34612
CRITICAL

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injec...

Apr 3
9.9CVSS
#16
CVE-2026-34156
CRITICAL

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's W...

Mar 31
9.9CVSS
#17
CVE-2026-34569
CRITICAL

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

Apr 1
9.9CVSS
#18
CVE-2026-27681
CRITICAL

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute craf...

2 days ago
9.9CVSS
#19
CVE-2026-33945
CRITICAL

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers...

Mar 27
9.9CVSS
#20
CVE-2026-34571
CRITICAL

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to...

Apr 1
9.9CVSS

Latest from the Blog

View All
NIST NVD • CISA KEV • EPSS