🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 1 day ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | MEDIUM | ????? | ????? | SA | 1 day ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 3 days ago |
| CVE-2026-108165 Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read L... | MEDIUM | ????? | ????? | NVD | 52 minutes ago |
| CVE-2026-108164 Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that... | HIGH | ????? | ????? | NVD | 52 minutes ago |
| CVE-2026-108163 Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as... | MEDIUM | ????? | ????? | NVD | 52 minutes ago |
| CVE-2026-108162 Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling becau... | MEDIUM | ????? | ????? | NVD | 52 minutes ago |
| CVE-2026-108161 FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute... | HIGH | ????? | ????? | NVD | 52 minutes ago |
| CVE-2026-107794 ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list.
The OUTPUT typemaps call av_extend( av, len-1 )... | UNKNOWN | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-107373 ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument.
The typem... | UNKNOWN | ????? | ????? | NVD | 1 hour ago |
| CVE-2013-10076 ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list.
The OUTPUT typemaps call av_extend( av, len-1... | UNKNOWN | ????? | ????? | NVD | 1 hour ago |
| CVE-2026-103636 Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp).
var_opt_union::deserialize() read the 32-... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-103635 Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp).
compact_theta_sketch::deserialize... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-103513 Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp).
A crafted serialized CPC sketch p... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-103501 Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp).
When deserializing a sketch in LIST mode,... | UNKNOWN | ????? | ????? | NVD | 3 hours ago |
| CVE-2026-108506 ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the int... | MEDIUM | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-106139 In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the for... | MEDIUM | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-106138 In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatt... | MEDIUM | ????? | ????? | NVD | 4 hours ago |
| CVE-2026-108505 ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain devi... | LOW | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-4791 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's '... | MEDIUM | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-91136 The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' paramete... | HIGH | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-107657 The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &... | HIGH | ????? | ????? | NVD | 5 hours ago |
| CVE-2026-104722 The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic... | MEDIUM | ????? | ????? | NVD | 5 hours ago |