🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-93832 A component of one of the Motorola system applications was
exported without permission, allowing for the revocation of runtime permissions
from other ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102671 The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102670 Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102669 Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102668 The Joyland AI app accepts any TLS certificates from any server without validation. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102667 Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-82358 RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' th... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102666 The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-82357 RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user appli... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-63721 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-63724 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55232 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF gu... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55230 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sa... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55231 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central pat... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-55083 DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1,... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104056 Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This all... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-15911 Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-27872 - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force).
This issue affects Easy IO FG: before 2.0b52. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-84682 A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exp... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104059 Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to per... | HIGH | ????? | ????? | NVD | 6 days ago |