🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92591 Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92590 Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig au... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92589 Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticate... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92588 n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92587 n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the confi... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92586 AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowi... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92585 AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing lo... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92584 AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objec... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92583 AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing atta... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92582 AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92581 In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to de... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92580 In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the st... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92579 The AVideo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 29.0. This is due to missing or inco... | MEDIUM | ????? | ????? | Wordfence | 6 days ago |
| CVE-2026-92578 WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential throug... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92577 In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-grou... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92576 HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-89034 TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-64684 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/tr... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20282 A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected de... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20235 A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an a... | MEDIUM | ????? | ????? | NVD | 6 days ago |