🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-85999 Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the r... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86000 Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defin... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86040 libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floods... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-91039 Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86038 libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy i... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-87742 A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85077 Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93015 BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93014 RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93013 RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that all... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-76834 b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serial... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-63459 Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-ce... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-12284 Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mat... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-75588 Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected serve... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92880 A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85078 Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the tr... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-26950 Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-54471 Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privil... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-71538 @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmR... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-63472 Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service... | CRITICAL | ????? | ????? | NVD | 5 days ago |