🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-77614 Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the defaul... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92987 roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers ca... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92986 SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles t... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92985 SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft mal... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92984 HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated att... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-92983 InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facin... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-81829 A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Bala... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-88952 Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identi... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-81453 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92879 A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulati... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-81443 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attack... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-81442 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker w... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92963 vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can a... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92962 vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/set... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92961 vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arb... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92960 vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92959 vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler t... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-71568 In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmct... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92958 vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92957 vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard r... | CRITICAL | ????? | ????? | NVD | 5 days ago |