| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5552 | PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection | PHPGurukul | Online Shopping Portal Project | Medium | 6.3 | 2026-04-05 08:30:14 | Deep Dive |
| CVE-2026-35535 | Sudo 安全漏洞 | Sudo project | Sudo | High | 7.4 | 2026-04-03 02:21:34 | Deep Dive |
| CVE-2026-34760 | vLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI Models | vllm-project | vllm | Medium | 5.9 | 2026-04-02 18:59:50 | Deep Dive |
| CVE-2026-34743 | XZ Utils: Buffer overflow in lzma_index_append() | tukaani-project | xz | - | - | 2026-04-02 18:36:37 | Deep Dive |
| CVE-2026-34593 | Ash Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash | ash-project | ash | - | - | 2026-04-02 17:42:26 | Deep Dive |
| CVE-2026-5368 | projectworlds Car Rental Project Parameter login.php sql injection | projectworlds | Car Rental Project | High | 7.3 | 2026-04-02 17:15:13 | Deep Dive |
| CVE-2026-21630 | Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint | Joomla! Project | Joomla! CMS | - | - | 2026-04-01 09:03:49 | Deep Dive |
| CVE-2026-23898 | Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate | Joomla! Project | Joomla! CMS | - | - | 2026-04-01 09:03:40 | Deep Dive |
| CVE-2026-21629 | Joomla! Core - [20260301] - ACL hardening in com_ajax | Joomla! Project | Joomla! CMS | - | - | 2026-04-01 09:03:38 | Deep Dive |
| CVE-2026-23899 | Joomla! Core - [20260306] - Improper access check in webservice endpoints | Joomla! Project | Joomla! CMS | - | - | 2026-04-01 09:03:19 | Deep Dive |
| CVE-2026-21631 | Joomla! Core - [20260303] - XSS vector in com_associations comparison view | Joomla! Project | Joomla! CMS | - | - | 2026-04-01 09:03:17 | Deep Dive |
| CVE-2026-21632 | Joomla! Core - [20260304] - XSS vectors in various article title outputs | Joomla! Project | Joomla! CMS | - | - | 2026-04-01 09:03:11 | Deep Dive |
| CVE-2026-27893 | vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out | vllm-project | vllm | High | 8.8 | 2026-03-26 23:56:54 | Deep Dive |
| CVE-2026-34085 | fontconfig 安全漏洞 | fontconfig project | fontconfig | Medium | 5.9 | 2026-03-25 16:54:37 | Deep Dive |
| CVE-2026-33004 | Jenkins LoadNinja Plugin 安全漏洞 | Jenkins Project | Jenkins LoadNinja Plugin | 中危 | - | 2026-03-18 15:15:27 | Deep Dive |
| CVE-2026-33003 | Jenkins LoadNinja Plugin 安全漏洞 | Jenkins Project | Jenkins LoadNinja Plugin | 中危 | - | 2026-03-18 15:15:26 | Deep Dive |
| CVE-2026-33002 | Jenkins 安全漏洞 | Jenkins Project | Jenkins | 高危 | - | 2026-03-18 15:15:25 | Deep Dive |
| CVE-2026-33001 | Jenkins 安全漏洞 | Jenkins Project | Jenkins | 高危 | - | 2026-03-18 15:15:24 | Deep Dive |
| CVE-2026-26001 | GLPI Inventory Plugin has SQL Injection on dropdown_calendar Report | glpi-project | glpi-inventory-plugin | High | 7.1 | 2026-03-17 23:18:01 | Deep Dive |
| CVE-2026-25937 | GLPI has a MFA bypass | glpi-project | glpi | Medium | 6.5 | 2026-03-17 23:16:38 | Deep Dive |