🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-62071 Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-56589 HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store mali... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103752 Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103347 Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103068 Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102378 Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-100517 Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-100514 Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103004 Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103687 A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of th... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2024-58388 Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-66253 iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling ... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-66249 iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-66248 iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-79901 In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-66247 iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-66246 iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure dire... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102505 Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp.
For a paletted image, getsa... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-102504 Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol.
Nothing ran... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103686 A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php o... | MEDIUM | ????? | ????? | NVD | 6 days ago |