🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
| Title | Severity | Proof of Concept | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-53557 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet[&... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-53555 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-53556 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint i... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-53554 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54633 PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a hea... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54343 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-50291 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-16582 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up... | MEDIUM | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-14311 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to ... | MEDIUM | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-16750 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing author... | MEDIUM | ????? | ????? | Wordfence | 2 days ago |
| CVE-2026-93426 SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users t... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-73639 Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-73638 Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd.
tiff_load_ifd() validate... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93386 UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI ele... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93385 Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93378 Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass ... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93384 Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering t... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93383 Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93380 Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged ... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93377 Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside ... | UNKNOWN | ????? | ????? | NVD | 2 days ago |