🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-105648 Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abuse... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105647 Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abus... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104030 A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authenti... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104029 A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. ... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103348 Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affec... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103337 Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103066 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-bookin... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-100511 Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.Thi... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-100506 Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Ch... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105689 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that d... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105767 Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) f... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105686 Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but n... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105766 Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105392 A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/s... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105389 A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Co... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-94201 Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is c... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97303 Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploit... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97304 Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97283 Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This iss... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97275 Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-... | MEDIUM | ????? | ????? | NVD | 1 day ago |