🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-45143 Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54460 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passke... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-50022 Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the cli... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-50275 The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ex... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54918 NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54916 NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the l... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-57846 No description available | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54594 OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues op... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54627 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_priv... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54626 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54618 Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, con... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54716 Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92757 Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field leve... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-93337 NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arb... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-90997 A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-52852 Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92758 If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92993 A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/mach... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92943 Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92756 Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption setting... | MEDIUM | ????? | ????? | NVD | 4 days ago |