🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-21833 HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks s... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-14316 The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final ... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12540 A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12541 A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12544 A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where c... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12423 A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logi... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-12405 A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations).... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103921 GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor()... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2025-31980 HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malforme... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2023-54404 Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by sub... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-73976 djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL int... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-73975 djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary S... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-101890 The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary Java... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-101889 The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-101888 The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write a... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-9864 Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Ac... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-79896 Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated a... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-46729 NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.
This issue affects Apache HTTP Server: from 2... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-47360 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.
When SessionC... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-42528 A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child... | MEDIUM | ????? | ????? | NVD | 6 days ago |