🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
| Title | Severity | Proof of Concept | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-52297 FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/m... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-52296 FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c. | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-35867 A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 vi... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-90600 A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-90599 A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-90598 A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-90597 A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pa... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-89050 The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before m... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-88802 The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-88793 The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it p... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-85129 The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-49030 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed ... | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-81648 The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenti... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-74933 The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-36989 A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-37008 CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-38332 TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length. | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-36453 Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-90596 A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-90595 A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of th... | MEDIUM | ????? | ????? | NVD | 6 days ago |