🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
| Title | Severity | Proof of Concept | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-15815 Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when
extracting plugin archives. A crafted plugin archive can chain relative ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93395 A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-l... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54597 ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated use... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54596 ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Tec... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54907 Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email a... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93394 A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proo... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54604 OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-86049 Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-76846 ## Summary
`system/config/security.yaml`'s default `twig_sandbox.config_denied_paths` list
(`plugins`, `streams`, `security`, `backups`, `schedu... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93393 A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endp... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-48977 OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-72701 ## Summary
`Grav\Common\Utils::verifyNonce()`, the core function Grav and its plugins use to validate CSRF nonces, compares the submitted nonce to th... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-72702 ## Summary
`Grav\Common\Uri::referrer()` and `Grav\Common\Page\Pages::referrerRoute()` both check whether an incoming request's `Referer` header... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54355 MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-45140 Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary c... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54354 MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-76154 A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary Jav... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54339 Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_ur... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-67071 HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54510 Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() ... | HIGH | ????? | ????? | NVD | 2 days ago |