🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92756 Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption setting... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-68537 `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-19477 There
is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). This may result in information di... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92230 Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLoc... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54253 TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js pas... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54524 Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL th... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-52851 Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pa... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92992 A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54649 punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound de... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54571 ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54239 Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and ex... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-52727 lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-54551 WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /ap... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-44236 rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92927 A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendo... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-89038 Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applicatio... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92926 A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-90430 In the Linux kernel, the following vulnerability has been resolved:
iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized
tegra... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-90306 In the Linux kernel, the following vulnerability has been resolved:
ARM: 9481/2: breakpoint: CFI breakpoints only on demand
This removes the stub hw... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-90211 In the Linux kernel, the following vulnerability has been resolved:
bpf, s390: Clear fetch destination on faulting arena atomic
Same missing registe... | UNKNOWN | ????? | ????? | NVD | 4 days ago |