🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-77927 ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the databa... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93505 A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the compo... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93653 A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cau... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93564 A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93558 A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-25684 A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policie... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93019 Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read.
The reader unpack... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93018 Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p a... | UNKNOWN | ????? | ????? | NVD | 1 day ago |
| CVE-2026-62282 OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficientl... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93560 A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the max... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93606 vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Pro... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93605 vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking ot... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93604 vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93603 vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandbox... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93602 rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93601 rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-su... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93600 rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that a... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93599 rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93598 ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.qu... | UNKNOWN | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93597 ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticate... | HIGH | ????? | ????? | NVD | 1 day ago |