🔔 Premium Features
(Level 1+ required)
(Level 2+ required)
(Level 3 required)
🔍 Filter Threats
| Title | Severity | Proof of Concept | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-86049 Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-76846 ## Summary
`system/config/security.yaml`'s default `twig_sandbox.config_denied_paths` list
(`plugins`, `streams`, `security`, `backups`, `schedu... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93393 A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endp... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-48977 OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-72701 ## Summary
`Grav\Common\Utils::verifyNonce()`, the core function Grav and its plugins use to validate CSRF nonces, compares the submitted nonce to th... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-72702 ## Summary
`Grav\Common\Uri::referrer()` and `Grav\Common\Page\Pages::referrerRoute()` both check whether an incoming request's `Referer` header... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54355 MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-45140 Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary c... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54354 MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-76154 A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary Jav... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54339 Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_ur... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-67071 HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54510 Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54565 rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser ex... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54521 FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/m... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-50277 dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54501 Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted ins... | UNKNOWN | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54237 Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/tr... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-45143 Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-54460 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passke... | CRITICAL | ????? | ????? | NVD | 2 days ago |