🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-81178 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63445 Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system da... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63199 Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsave... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63458 Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-32641 Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap()... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93759 Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaS... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-69184 c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the t... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-69186 c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields befo... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61552 Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93760 Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building me... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61551 Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesti... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61550 Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validat... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93761 An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated par... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-91127 File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-84992 md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in pa... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63349 AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSI... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63374 ### Impact
Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's `connect_tcp... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-64847 AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts pro... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77386 Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flo... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77385 Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply ... | MEDIUM | ????? | ????? | NVD | 1 day ago |