🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-106447 StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-94114 Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared name... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102167 On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthentic... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102165 On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102164 On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless cli... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102163 On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) prox... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102169 On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102168 On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102162 On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gate... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-101157 A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that ... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102156 Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-101156 A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configurati... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102161 An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102160 An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafte... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102159 An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102158 Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102157 An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under sp... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102155 An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious reque... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106445 Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.pro... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-101155 An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specia... | HIGH | ????? | ????? | NVD | 1 day ago |