🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-20305 A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-20306 A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the und... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92402 A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the fi... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-87031 n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/User... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-87028 Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance th... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-57173 vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls Audio... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85386 Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were va... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85756 ## Summary
Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that c... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85385 Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user m... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92401 A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-84993 MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-86359 Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote acces... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85731 ### Summary
The `content/file.Store` in oras-go v2 unpacks OCI layer tarballs when a descriptor carries `io.deis.oras.content.unpack=true`. The extrac... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85732 ## Summary
oras-go's pagination helper `parseLink()` in `registry/remote/utils.go` follows the `Link` response header from a registry without va... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-68904 node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive set... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-76104 Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privile... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-70416 Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote acces... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2025-43936 Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote ac... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-69200 node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/no... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92399 A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component W... | HIGH | ????? | ????? | NVD | 6 days ago |