🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 11 hours ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 2 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | Unknown | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 3 days ago |
| CVE-2026-82560 Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output... | UNKNOWN | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-94001 A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user creden... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94000 A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership e... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-93999 A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the ... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-93987 rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/dock... | LOW | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-93986 rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences i... | LOW | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-93985 OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block ... | CRITICAL | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-93984 OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing rev... | MEDIUM | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-93983 OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. A... | MEDIUM | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-93982 OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without ... | LOW | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-93981 hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alon... | MEDIUM | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-78030 DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.
DBD::DBM passes the dbm_type... | UNKNOWN | ????? | ????? | NVD | 6 hours ago |
| CVE-2026-93742 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This... | CRITICAL | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-9858 The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_ord... | MEDIUM | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-9613 The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.... | MEDIUM | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-76579 The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and ... | MEDIUM | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-1256 The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions ... | MEDIUM | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-9766 The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the p... | MEDIUM | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-9289 The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ... | MEDIUM | ????? | ????? | NVD | 8 hours ago |
| CVE-2026-1255 The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'yslea... | HIGH | ????? | ????? | NVD | 8 hours ago |