🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 1 day ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | MEDIUM | ????? | ????? | SA | 1 day ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 3 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 3 days ago |
| CVE-2026-108583 zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_... | LOW | ????? | ????? | NVD | 56 minutes ago |
| CVE-2026-108582 GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to r... | MEDIUM | ????? | ????? | NVD | 56 minutes ago |
| CVE-2026-108581 TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provid... | HIGH | ????? | ????? | NVD | 56 minutes ago |
| CVE-2026-108580 AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allow... | MEDIUM | ????? | ????? | NVD | 56 minutes ago |
| CVE-2026-108579 OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplyin... | LOW | ????? | ????? | NVD | 56 minutes ago |
| CVE-2026-108555 PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms... | LOW | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108554 PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108553 OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython f... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108551 openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject Java... | CRITICAL | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108550 SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated a... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108549 cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts ... | CRITICAL | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108548 AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108547 AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' sha... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-97264 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts all... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-97263 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts all... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-94676 Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a ... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-66435 Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This i... | MEDIUM | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-105885 Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-102388 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows ... | HIGH | ????? | ????? | NVD | 2 hours ago |
| CVE-2026-108546 Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by... | HIGH | ????? | ????? | NVD | 2 hours ago |