🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104018 An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user comm... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103884 A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to prope... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103922 Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-8618 A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted r... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104058 Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-104057 Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allCo... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102369 Tapo C120 v1 and C200 V5
do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An una... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-78578 Tapo C120 v1 and C200 v5
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjace... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-78577 Tapo C120 v1 and C200 V5
contain a vulnerability in the HTTPS onboarding scan function due to missing authentication.
After initial setup, an unauthen... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-9032 Tapo C120 v1 and C200 v5
contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without
authe... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103923 KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property a... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-97662 An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat acto... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102294 TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improper... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-96659 A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information discl... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-96658 A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sa... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-93546 Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-79768 Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-73637 Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote cli... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-77387 geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-e... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-73636 Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the... | HIGH | ????? | ????? | NVD | 6 days ago |