🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-85756 ## Summary
Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that c... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85385 Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user m... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92401 A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-84993 MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-86359 Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote acces... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85731 ### Summary
The `content/file.Store` in oras-go v2 unpacks OCI layer tarballs when a descriptor carries `io.deis.oras.content.unpack=true`. The extrac... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85732 ## Summary
oras-go's pagination helper `parseLink()` in `registry/remote/utils.go` follows the `Link` response header from a registry without va... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-68904 node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive set... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-76104 Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privile... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-70416 Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote acces... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2025-43936 Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote ac... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-69200 node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/no... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92399 A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component W... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-59974 Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.res... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-59944 Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can by... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92603 ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92602 TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92601 Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not over... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92600 Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requir... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-92398 A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admi... | CRITICAL | ????? | ????? | NVD | 6 days ago |