🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-93026 This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update cr... | MEDIUM | ????? | ????? | NVD | 17 hours ago |
| CVE-2026-58068 This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | MEDIUM | ????? | ????? | NVD | 17 hours ago |
| CVE-2026-58069 This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host... | HIGH | ????? | ????? | NVD | 17 hours ago |
| CVE-2025-64393 This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server. | CRITICAL | ????? | ????? | NVD | 17 hours ago |
| CVE-2026-5703 Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an a... | HIGH | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-107104 This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated re... | CRITICAL | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-107103 This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthen... | CRITICAL | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-107121 A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to s... | MEDIUM | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-107102 This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API en... | CRITICAL | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-102782 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=c... | CRITICAL | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-102781 Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired thro... | MEDIUM | ????? | ????? | NVD | 18 hours ago |
| CVE-2026-53631 R Impact Any connected user can craft a request to change the visibility of any knowbase items, reminders and RSS feeds, and therefore access their cont... | MEDIUM | ????? | ????? | NVD | 18 hours ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 18 hours ago |
| CVE-2026-97354 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-suppl... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-97331 The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returnin... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-97188 The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through ... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-96530 The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashb... | MEDIUM | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-87971 The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a lin... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-87782 The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a ... | HIGH | ????? | ????? | NVD | 19 hours ago |
| CVE-2026-86816 The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooC... | MEDIUM | ????? | ????? | NVD | 19 hours ago |