CVE Find is a real-time vulnerability database indexing 341 872 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1242 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-0545 |
2026-04-03 18h16 +00:00 |
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authen... Authorization problems |
9.1 |
Critical |
|
CVE-2026-28373 |
2026-04-03 17h16 +00:00 |
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerabili... Directory Traversal |
9.6 |
Critical |
|
CVE-2026-35218 |
2026-04-03 16h16 +00:00 |
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Pa... Cross-site Scripting |
8.7 |
High |
|
CVE-2026-35216 |
2026-04-03 16h16 +00:00 |
Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker c... OS Command Injection |
9 |
Critical |
|
CVE-2026-31818 |
2026-04-03 16h16 +00:00 |
Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery... Server-Side Request Forgery - SSRF |
9.6 |
Critical |
|
CVE-2026-35214 |
2026-04-03 15h43 +00:00 |
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoi... Directory Traversal |
8.7 |
High |
|
CVE-2025-59711 |
2026-04-03 15h16 +00:00 |
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in ... Directory Traversal |
8.3 |
High |
|
CVE-2026-5463 |
2026-04-03 04h32 +00:00 |
Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version... Command Injection |
9.3 |
Critical |
|
CVE-2026-33105 |
2026-04-03 00h16 +00:00 |
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elev... |
10 |
Critical |
|
CVE-2026-32213 |
2026-04-03 00h16 +00:00 |
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges ove... |
10 |
Critical |