🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-105693 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row f... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105692 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and ver... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105691 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-colo... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105690 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the cor... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105688 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owne... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105687 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105684 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105683 Ghost is a Node.js content management system. From 6.14.0 until 6.27.0, an input validation issue may have allowed staff users to access local files o... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105682 Ghost is a Node.js content management system. From 1.18.0 until 6.27.0, an SSRF vulnerability in the webhooks feature allowed staff users to probe int... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105681 Ghost is a Node.js content management system. From 5.9.0 until 6.44.1, an input validation issue allowed members to access comments they were not auth... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105680 Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not auth... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105679 Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent brow... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105676 Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenti... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105675 Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the se... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105652 Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105651 Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105678 Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105677 Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenti... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105650 Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted s... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105649 Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension wer... | HIGH | ????? | ????? | NVD | 1 day ago |