🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-51878 deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote call... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-18397 This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknes... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-27873 - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.
This issue affects EasyIO FG: before 2.0b52. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-64893 - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
This issue affects ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-64892 - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.
This issue affe... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104356 PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-34494 - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.
This issue affects Ne... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-34493 - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.
This issue affects EasyIO... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104182 stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104183 stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materiali... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104181 Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authe... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71449 : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.
This issue affects Eas... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71448 : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.
This issue affects EasyIO ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71454 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71453 - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.
This issue affects EasyIO FS32: befo... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104051 PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and upl... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71452 - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection.
This issue affects EasyIO FS32: before 3.0b63. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104002 A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field valu... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-71451 - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection.
This issue affects EasyIO FS32: before 3.0b63. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-27874 : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials.
This issue ... | MEDIUM | ????? | ????? | NVD | 6 days ago |