🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-57224 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-57226 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP ... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-57222 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, craft... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61720 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61723 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61722 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chu... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61714 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-61721 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled ws... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-58264 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_b... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76899 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76902 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configure... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76900 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceSer... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93873 Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93872 Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registere... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93871 Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93870 Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenti... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93869 Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular exp... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93868 Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space o... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76901 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{i... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-84239 IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of specia... | HIGH | ????? | ????? | NVD | 1 day ago |