🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-102370 Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader. Altho... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104020 Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-96780 ### Impact
A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when
**both**:
- `whitespaceBreak: true` is set, **and**
- `width`... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56662 GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE upda... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56661 GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handle... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56660 GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handle... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55251 NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workfl... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-54049 Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-53953 GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset e... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-53964 Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104286 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, F... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103484 IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102514 Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and e... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55396 Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55395 Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticat... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55394 Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hij... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55393 Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthentica... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-14984 Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to in... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-14983 Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102628 The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environ... | CRITICAL | ????? | ????? | NVD | 6 days ago |