🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-93394 A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proo... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54604 OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-86049 Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-76846 ## Summary
`system/config/security.yaml`'s default `twig_sandbox.config_denied_paths` list
(`plugins`, `streams`, `security`, `backups`, `schedu... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-93393 A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endp... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-48977 OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-72701 ## Summary
`Grav\Common\Utils::verifyNonce()`, the core function Grav and its plugins use to validate CSRF nonces, compares the submitted nonce to th... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-72702 ## Summary
`Grav\Common\Uri::referrer()` and `Grav\Common\Page\Pages::referrerRoute()` both check whether an incoming request's `Referer` header... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54355 MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-45140 Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary c... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54354 MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-76154 A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary Jav... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-67071 HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54510 Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54521 FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/m... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54692 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54752 NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deseri... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-45726 Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54501 Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted ins... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54237 Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/tr... | CRITICAL | ????? | ????? | NVD | 4 days ago |