š CVEs & KEV
-
CVE-2026-65321 ā PyAthena 3.35.4 ā CVSS 9.8 ā SQL Injection via DefaultParameterFormatter DELETE/CTASPyAthena CVE-2026-65321 allows SQL injection through the DefaultParameterFormatter in PyAthena version 3.35.4, affecting DELETE and CTAS operations.
- Impact: Critical, CVSS 9.8
- Affected: PyAthena 3.35.4
- Vector: SQL injection in query formatting š Coverage: cve.threatint.com
-
CVE-2026-9856 ā huggingface/transformers ā CVSS 7.1 ā Path Traversal A path traversal vulnerability in huggingface/transformers could allow attackers to access unauthorized files. š Coverage: cve.threatint.com
-
CVE-2026-10848 ā Zephyr OCPP 1.6 ā CVSS 7.0 ā Out-of-bounds read in RPC message parser The Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) contains an out-of-bounds read vulnerability. š Coverage: cve.threatint.com