🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-21140 Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104052 A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_co... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104480 Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker ... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-86345 A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allo... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103766 ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject S... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103765 Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticate... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103764 Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103761 Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenti... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103760 Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the han... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2025-71427 Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-86344 A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LD... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51897 RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger atta... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51896 infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perf... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51895 Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51894 infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant ident... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51893 infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object o... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51892 infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51888 langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundar... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51886 langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflo... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51884 The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malic... | CRITICAL | ????? | ????? | NVD | 6 days ago |