| Apr 30 | Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS JupyterHighApr 30 | Jupyter | High | 4.5.7+1 more |
| Apr 30 | `container system dns create` unvalidated domain name allows pf rule injection AppleLowApr 30 | Apple | Low | 0.12.3 |
| Apr 30 | Insecure Hostname Validation Allows HTTP Downgrade Attack AppleMedium6.9Apr 30 | Apple | Medium6.9 | 0.12.3 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials AWSHigh7.2Apr 30 | AWS | High7.2 | 1.103.0 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials AWSUnratedApr 30 | AWS | Unrated | No fix yet |
| Apr 29 | n8n has XML Node Prototype Pollution that to RCE n8nCritical9.9Apr 29 | n8n | Critical9.9 | 1.123.32+2 more |
| Apr 29 | n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE n8nCritical10.0Apr 29 | n8n | Critical10.0 | 1.123.32+2 more |
| Apr 29 | n8n Vulnerable to XSS via MCP OAuth client n8nHigh8.2Apr 29 | n8n | High8.2 | 1.123.32+2 more |
| Apr 29 | n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay n8nHigh8.5Apr 29 | n8n | High8.5 | 1.123.33+1 more |
| Apr 29 | n8n has a Python Task Runner Sandbox Escape Vulnerability n8nHigh7.5Apr 29 | n8n | High7.5 | 1.123.32+2 more |
| Apr 29 | n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure n8nMedium7.7Apr 29 | n8n | Medium7.7 | 1.123.32+2 more |
| Apr 29 | n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration n8nHigh7.5Apr 29 | n8n | High7.5 | 1.123.32+2 more |
| Apr 29 | n8n Vulnerable to Hijacking of Unauthenticated Chat Execution n8nMedium5.4Apr 29 | n8n | Medium5.4 | 1.123.32+2 more |
| Apr 29 | n8n has SQL Injection in SeaTable Node n8nMedium6.8Apr 29 | n8n | Medium6.8 | 1.123.32+2 more |
| Apr 29 | n8n has Open Redirect in MCP OAuth Consent Flow n8nMedium4.7Apr 29 | n8n | Medium4.7 | 1.123.32+2 more |
| Apr 29 | n8n has SQL Injection in Oracle Database Node via Limit Field n8nMedium9.8Apr 29 | n8n | Medium9.8 | 1.123.32+2 more |
| Apr 29 | n8n has SQL Injection in Snowflake and MySQL Nodes n8nMedium8.2Apr 29 | n8n | Medium8.2 | 1.123.32+2 more |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer... AWSUnratedApr 29 | AWS | Unrated | No fix yet |
| Apr 29 | Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP AWSUnratedApr 29 | AWS | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues AWSUnratedApr 29 | AWS | Unrated | No fix yet |
| Apr 27 | vLLM makes Use of Uninitialized Resource vLLMLow5.6Apr 27 | vLLM | Low5.6 | 0.19.1 |
| Apr 27 | Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS AWSUnratedApr 27 | AWS | Unrated | No fix yet |
| Apr 26 | Ollama is Vulnerable to Path Traversal OllamaLow5.6Apr 26 | Ollama | Low5.6 | No fix yet |
| Apr 25 | LiteLLM: Authenticated command execution via MCP stdio test endpoints LiteLLMHigh8.8Apr 25 | LiteLLM | High8.8 | 1.83.7 |
| Apr 24 | Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses gemini-cliCritical10.0Apr 24 | gemini-cli | Critical10.0 | 0.39.1+1 more |
| Apr 24 | LiteLLM has SQL Injection in Proxy API key verification LiteLLMCritical9.8Apr 24 | LiteLLM | Critical9.8 | 1.83.7 |
| Apr 24 | Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars DgraphCritical9.8Apr 24 | Dgraph | Critical9.8 | No fix yet |
| Apr 24 | Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization RayHighApr 24 | Ray | High | 2.55.0 |
| Apr 24 | LiteLLM: Server-Side Template Injection in /prompts/test endpoint LiteLLMHighApr 24 | LiteLLM | High | 1.83.7 |
| Apr 24 | Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field DgraphCritical9.1Apr 24 | Dgraph | Critical9.1 | No fix yet |
| Apr 24 | Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field DgraphCritical9.1Apr 24 | Dgraph | Critical9.1 | No fix yet |
| Apr 24 | Apache Airflow: improper access control Apache AirflowMedium4.3Apr 24 | Apache Airflow | Medium4.3 | 3.2.1rc1 |
| Apr 24 | Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions Apache AirflowMedium4.3Apr 24 | Apache Airflow | Medium4.3 | 3.2.1rc1 |
| Apr 24 | Apache DolphinScheduler has an Incorrect Authorization Vulnerability dolphinschedulerHigh8.1Apr 24 | dolphinscheduler | High8.1 | 3.4.1 |
| Apr 24 | Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability dolphinschedulerMedium6.3Apr 24 | dolphinscheduler | Medium6.3 | 3.3.1 |
| Apr 24 | Grafana Tempo has an Uncontrolled Resource Consumption issue TempoHigh7.5Apr 24 | Tempo | High7.5 | 2.8.4+2 more |
| Apr 24 | Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool AnthropicMedium4.8Apr 24 | Anthropic | Medium4.8 | 0.91.1 |
| Apr 24 | Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution AnthropicHigh7.7Apr 24 | Anthropic | High7.7 | 2.1.84 |
| Apr 24 | Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912 AWSUnratedApr 24 | AWS | Unrated | No fix yet |
| Apr 23 | H2O-3: remote code execution H2O-3Critical9.8Apr 23 | H2O-3 | Critical9.8 | 3.46.0.10 |
| Apr 22 | Malicious code in xinference (PyPI) XinferenceUnratedApr 22 | Xinference | Unrated | No fix yet |
| Apr 22 | Title: Sandbox escape via JavaScript prototype chain traversal in cohere-terrarium CohereCritical9.3Apr 22 | Cohere | Critical9.3 | 1.01 |
| Apr 21 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability FlowiseCritical9.8Apr 21 | Flowise | Critical9.8 | 3.1.0 |
| Apr 21 | OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation OpenBaoLowApr 21 | OpenBao | Low | 0.0.0-20260420162526-f58111d2ca54 |
| Apr 21 | OpenBao's SQL Injection in PostgreSQL database secrets engine OpenBaoMedium4.9Apr 21 | OpenBao | Medium4.9 | 0.0.0-20260420155735-b596b0882620 |
| Apr 21 | OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) OpenBaoLow3.1Apr 21 | OpenBao | Low3.1 | 0.0.0-20260420180337-2b2a901aa9f7 |
| Apr 21 | OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate OpenBaoLow3.1Apr 21 | OpenBao | Low3.1 | 0.0.0-20260420160924-abe84e1af4c3 |
| Apr 21 | nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding JupyterMedium6.5Apr 21 | Jupyter | Medium6.5 | 7.17.1 |
| Apr 21 | nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames JupyterMedium6.5Apr 21 | Jupyter | Medium6.5 | 7.17.1 |
| Apr 21 | LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading LMDeployHigh7.5Apr 21 | LMDeploy | High7.5 | No fix yet |
| Apr 20 | Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation Apache KafkaCritical9.1Apr 20 | Apache Kafka | Critical9.1 | 4.1.2 |
| Apr 20 | Apache Kafka exposes sensitive information in its DEBUG logs Apache KafkaMedium5.3Apr 20 | Apache Kafka | Medium5.3 | 3.9.2+1 more |
| Apr 20 | FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426) FastChatMedium5.3Apr 20 | FastChat | Medium5.3 | No fix yet |
| Apr 20 | AgentScope vulnerable to Server-Side Request Forgery agentscopeMedium7.3Apr 20 | agentscope | Medium7.3 | No fix yet |
| Apr 20 | FastChat has a Content Moderation Bypass via Arena Side-by-Side Views FastChatMedium5.3Apr 20 | FastChat | Medium5.3 | No fix yet |
| Apr 20 | AgentScope vulnerable to Server-Side Request Forgery agentscopeMedium7.3Apr 20 | agentscope | Medium7.3 | No fix yet |
| Apr 20 | AgentScope vulnerable to Server-Side Request Forgery agentscopeMedium7.3Apr 20 | agentscope | Medium7.3 | No fix yet |
| Apr 20 | Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint LangflowLow4.3Apr 20 | Langflow | Low4.3 | 1.9.1 |
| Apr 20 | AgentScope Vulnerable to Remote Code Injection agentscopeMedium7.3Apr 20 | agentscope | Medium7.3 | No fix yet |
| Apr 20 | Langflow vulnerable to injection LangflowLow6.3Apr 20 | Langflow | Low6.3 | No fix yet |