🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104427 Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchro... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104426 Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spen... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104425 ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushi... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104424 Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104423 Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104422 The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104421 Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving reje... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104420 Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossipe... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104419 Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104418 Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme t... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104417 Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104416 Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pen... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104415 Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relati... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104414 Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post conten... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104413 Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrar... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104412 Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own r... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104411 Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104410 SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled datab... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103763 SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded docu... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103762 SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoi... | MEDIUM | ????? | ????? | NVD | 5 days ago |