VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 866 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-27834

Piwigo Piwigo, piwigo

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing authenticated administrators to execute arbitrary SQL commands. This issue has been patched in version 16.3.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27833

Piwigo Piwigo, piwigo

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-27634

Piwigo Piwigo, piwigo

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without any escaping or type validation. This could result in an unauthenticated attacker reading the full database, including user password hashes. This issue has been patched in version 16.3.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2018-25237

Belden Hirschmann HiSecOS Classic Firewall (EAGLE, EAGLE One)

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-15058

Belden Hirschmann HiLCOS Classic Platform

Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when the feature is enabled. Attackers with local network access can sniff SNMP traffic or extract configuration data to recover plaintext credentials and gain unauthorized administrative access to the switches.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2015-10148

Belden Hirschmann HiLCOS

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-in-the-middle attacks, impersonate devices, and expose sensitive information by leveraging the shared default cryptographic keys across multiple devices.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5485

Amazon Amazon Athena ODBC driver, athena odbc, linux kernel

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To remediate this issue, users should upgrade to version 2.0.5.1 or later.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35562

Amazon Amazon Athena ODBC driver, athena odbc, macos

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should upgrade to version 2.1.0.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-35561

Amazon Amazon Athena ODBC driver, athena odbc, macos

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users should upgrade to version 2.1.0.0.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-35560

Amazon Amazon Athena ODBC driver, athena odbc, macos

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35559

Amazon Amazon Athena ODBC driver, athena odbc, macos

Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-35558

Amazon Amazon Athena ODBC driver, athena odbc, macos

Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated authentication. To remediate this issue, users should upgrade to version 2.1.0.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-32646

Gardyn Cloud API, cloud api

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-28766

Gardyn Cloud API, cloud api

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-25197

Gardyn Cloud API, cloud api

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

The CVSS severity warrants an early asset and exposure review.