| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-24147 | NVIDIA Triton Inference Server 路径遍历漏洞 | NVIDIA | Triton Inference Server | Medium | 4.8 | 2026-04-07 17:12:12 | Deep Dive |
| CVE-2026-24146 | NVIDIA Triton Inference Server 安全漏洞 | NVIDIA | Triton Inference Server | High | 7.5 | 2026-04-07 17:11:55 | Deep Dive |
| CVE-2026-22675 | OCS Inventory NG Server Stored XSS via User-Agent | OCS Inventory | OCS Inventory NG Server | Medium | 5.4 | 2026-04-06 21:19:59 | Deep Dive |
| CVE-2026-35200 | Parse Server has a file upload Content-Type override via extension mismatch | parse-community | parse-server | - | - | 2026-04-06 19:47:28 | Deep Dive |
| CVE-2025-7024 | Local privilege escalation in Windows Server OS through installed Tetra Connectivity Server (TCS) | AIRBUS | TETRA Connectivity Server (TCS) | High | 7.3 | 2026-04-03 07:30:11 | Deep Dive |
| CVE-2026-35038 | signalk-server: Arbitrary Prototype Read via `from` Field Bypass | SignalK | signalk-server | - | - | 2026-04-02 16:20:18 | Deep Dive |
| CVE-2026-34083 | signalk-server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow | SignalK | signalk-server | Medium | 6.1 | 2026-04-02 16:14:39 | Deep Dive |
| CVE-2026-33951 | signalk-server: Unauthenticated Source Priorities Manipulation | SignalK | signalk-server | - | - | 2026-04-02 16:11:59 | Deep Dive |
| CVE-2026-33950 | signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity | SignalK | signalk-server | Critical | 9.4 | 2026-04-02 16:08:59 | Deep Dive |
| CVE-2025-65114 | Apache Traffic Server: Malformed chunked message body allows request smuggling | Apache Software Foundation | Apache Traffic Server | - | - | 2026-04-02 15:55:27 | Deep Dive |
| CVE-2025-58136 | Apache Traffic Server: A simple legitimate POST request causes a crash | Apache Software Foundation | Apache Traffic Server | - | - | 2026-04-02 15:54:47 | Deep Dive |
| CVE-2026-4989 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 15:07:29 | Deep Dive |
| CVE-2026-5175 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 15:04:22 | Deep Dive |
| CVE-2026-4925 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 15:02:07 | Deep Dive |
| CVE-2026-4927 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 14:54:46 | Deep Dive |
| CVE-2026-4924 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 14:50:52 | Deep Dive |
| CVE-2026-4828 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 14:48:54 | Deep Dive |
| CVE-2026-4829 | Devolutions Server 安全漏洞 | Devolutions | Server | - | - | 2026-04-01 14:44:05 | Deep Dive |
| CVE-2026-0932 | M-Files Server 安全漏洞 | M-Files Corporation | M-Files Server | - | - | 2026-04-01 10:03:28 | Deep Dive |
| CVE-2025-13855 | IBM Storage Protect Server is affected by a vulnerability that could allow authenticated users to access administrative metadata through the JSON-RPC endpoint . | IBM | Storage Protect Server | High | 7.6 | 2026-04-01 00:23:29 | Deep Dive |