🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-41958 A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A special... | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107170 A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error... | LOW | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107168 A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing functi... | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107151 Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accep... | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-102256 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identi... | HIGH | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-102255 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing th... | CRITICAL | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107180 On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup appli... | HIGH | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107177 Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAu... | HIGH | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107162 Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token ... | HIGH | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-107175 MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distributi... | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-105140 Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just ... | LOW | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-105139 Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts an... | MEDIUM | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-105138 Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-42710 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-42708 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-autho... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-107159 MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network at... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-106059 GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository file... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-106058 GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by ... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-106057 patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedde... | HIGH | ????? | ????? | NVD | 15 hours ago |
| CVE-2026-106056 Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Win... | HIGH | ????? | ????? | NVD | 15 hours ago |