🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104056 Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This all... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-15911 Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-27872 - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force).
This issue affects Easy IO FG: before 2.0b52. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-84682 A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exp... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104059 Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to per... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-68496 The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property n... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-68495 The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property na... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56098 A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56097 A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to s... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12542 A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script take... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12545 A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104018 An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user comm... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103884 A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to prope... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103922 Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-8618 A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted r... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104058 Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104057 Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allCo... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102369 Tapo C120 v1 and C200 V5
do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An una... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-78578 Tapo C120 v1 and C200 v5
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjace... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-78577 Tapo C120 v1 and C200 V5
contain a vulnerability in the HTTPS onboarding scan function due to missing authentication.
After initial setup, an unauthen... | MEDIUM | ????? | ????? | NVD | 6 days ago |