🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-103679 A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103678 A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (R... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103754 A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103336 Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve ... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103858 MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an exist... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-88789 Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 b... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103353 Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects F... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103082 Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forg... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-94276 Improper Authentication vulnerability in Apache APISIX.
On a route using openid-connect plugin with remote introspection against an authorization ser... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-94269 Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX.
In some configurations where a permissive route overlaps... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-94250 Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX.
An unauthenticated caller can drive a... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-94220 Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.
An attacker who can get a user to click ... | LOW | ????? | ????? | NVD | 6 days ago |
| CVE-2026-94212 Improper verification of cryptographic signature vulnerability in Apache APISIX.
Any unauthenticated attacker could impersonate any user on every r... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-82806 Exposure of data element to wrong session vulnerability in Apache APISIX.
This issue affects Apache APISIX: from 2.3.0 before 3.7.0.
Under a sup... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-78242 Insertion of sensitive information into log file vulnerability in Apache APISIX.
This vulnerability can cause the unmasked header value to be writt... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-62329 R Vulnerability Type: CWE-1392: Use of Default Credentials Attack type: Unauthenticated remote Impact: Unauthenticated users can access the default admi... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103758 Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI den... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103757 Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103292 Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} help... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103291 Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated s... | MEDIUM | ????? | ????? | NVD | 6 days ago |