🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104420 Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossipe... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104419 Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104418 Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme t... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104417 Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104416 Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pen... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104415 Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relati... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104414 Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post conten... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104413 Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrar... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104412 Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own r... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104411 Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-104410 SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled datab... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103763 SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded docu... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103762 SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoi... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85088 Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift.
Both libraries install a default access manager ... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85087 Improper certificate validation, Return of wrong status code vulnerability in Apache Thrift python bindings.
This issue affects Apache Thrift: befo... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85086 Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.
This issue aff... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-82459 Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport.
This issue affects Apache T... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-82458 Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerability in Apache Thrift Go, netstd, OCaml, E... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-96288 Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings.
This issue affects Apa... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-97876 A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB ... | MEDIUM | ????? | ????? | NVD | 5 days ago |