🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104449 YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104448 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET re... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104447 YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed pack... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104446 YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through th... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104445 YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104444 YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege user... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104443 YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary s... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104442 YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbit... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-86535 Loop with unreachable exit condition ('infinite loop'), Improperly controlled modification of object prototype attributes ('prototype p... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104441 YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbit... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104440 YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side re... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104439 YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered e... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104438 YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pag... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104437 Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SING... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104436 Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sendin... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104435 Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that la... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104434 ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which ca... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104432 Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, false... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104431 Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transacti... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104430 Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, o... | HIGH | ????? | ????? | NVD | 5 days ago |