🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92762 Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92761 WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers wit... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92760 Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92759 SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92754 PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is c... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92753 PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Auth... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92752 metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92751 CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authentic... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92750 Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92749 SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92748 BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write file... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-63506 Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled cl... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-76426 A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20121 A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) S... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-76431 A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, rem... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-76427 A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are store... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-76447 A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attac... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20287 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive I... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20285 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20286 A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify ... | MEDIUM | ????? | ????? | NVD | 6 days ago |