🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92880 A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85078 Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the tr... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-26950 Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-54471 Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privil... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-71538 @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmR... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-63472 Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-63461 Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-79752 CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract,... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-63460 Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastr... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-61793 Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when t... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-81447 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attack... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-80356 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-81446 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated atta... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-81445 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-77614 Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the defaul... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92987 roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers ca... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92986 SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles t... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92985 SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft mal... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92984 HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated att... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92983 InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facin... | HIGH | ????? | ????? | NVD | 5 days ago |