🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2025-13882 IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Ma... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93576 A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP co... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2025-1350 IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16515 net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 er... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16514 gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing ea... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16512 gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type witho... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2024-56344 IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-85511 A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would a... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93569 A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77929 ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a P... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93567 A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header inste... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93660 SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93659 Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated at... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93658 uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged u... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93657 hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, all... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77928 ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93676 xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Fl... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93566 A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within th... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-10832 A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93565 A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time ... | HIGH | ????? | ????? | NVD | 1 day ago |