🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-51873 Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intende... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51881 deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer ... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51880 deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51879 deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can en... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51878 deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote call... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-18397 This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknes... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-27873 - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.
This issue affects EasyIO FG: before 2.0b52. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-64893 - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
This issue affects ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-64892 - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.
This issue affe... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104356 PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-34494 - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.
This issue affects Ne... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-34493 - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.
This issue affects EasyIO... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104182 stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104183 stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materiali... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104181 Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authe... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71449 : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.
This issue affects Eas... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71448 : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.
This issue affects EasyIO ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71454 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71453 - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.
This issue affects EasyIO FS32: befo... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104051 PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and upl... | HIGH | ????? | ????? | NVD | 6 days ago |