🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-13683 An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology Disk... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13623 An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation M... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13666 An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-56590 HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-6205 An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13673 An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13635 An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13639 An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-21848 HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit imprope... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13684 An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-860... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-11757 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. B... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93493 A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certifica... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-67103 HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious s... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-67102 HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unau... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-67100 HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authentica... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75157 Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authentica... | UNKNOWN | ????? | ????? | NVD | 1 day ago |
| CVE-2026-67101 HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an atta... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-12384 Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.
This issue affects TECHIN2B A... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-92249 The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-85705 The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameter... | HIGH | ????? | ????? | NVD | 1 day ago |