🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92811 browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92810 PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers t... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92809 PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated at... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92806 phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce lo... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actio... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92804 Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authe... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92803 LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attac... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92802 kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despit... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92801 cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers ca... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92800 Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked acce... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92796 Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only use... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92795 Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fe... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92794 OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92793 GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92792 OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing th... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92791 Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92790 Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continu... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92789 Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Att... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92788 Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92787 Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access contro... | CRITICAL | ????? | ????? | NVD | 6 days ago |