🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2025-56566 MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with phys... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2025-56565 DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2025-56563 A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85469 A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-62997 Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-dataset... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-75513 Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management p... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-81871 OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTE... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-81872 OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter ... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-81869 OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92816 ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the outp... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92815 changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addres... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92814 changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can pla... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92813 Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reac... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92812 decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separa... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92811 browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92810 PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers t... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92809 PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated at... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92806 phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce lo... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actio... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92804 Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authe... | HIGH | ????? | ????? | NVD | 6 days ago |