🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-19572 A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authenticatio... | CRITICAL | ????? | ????? | NVD | 21 hours ago |
| CVE-2026-106061 A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer usin... | MEDIUM | ????? | ????? | NVD | 22 hours ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | CRITICAL | ????? | ????? | SA | 22 hours ago |
| CVE-2026-84897 src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and S... | MEDIUM | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-83742 Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated... | MEDIUM | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-83540 When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connectio... | HIGH | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-81535 In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding p... | MEDIUM | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-16516 wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In Pars... | CRITICAL | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-106471 A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is acc... | HIGH | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-14911 Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM i... | CRITICAL | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-19396 A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthentic... | HIGH | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-19386 A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration fil... | CRITICAL | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-16528 Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from ... | HIGH | ????? | ????? | NVD | 23 hours ago |
| CVE-2026-102478 In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse res... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97680 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to impr... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97679 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97678 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation. | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97676 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97674 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of s... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97673 IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation. | HIGH | ????? | ????? | NVD | 1 day ago |