🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-105644 Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, SVG images included in content imports were stored without sanitization. An att... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105641 Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105639 Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105642 Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in it... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105640 Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105643 Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against store... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105638 Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 2... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105637 Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves asset... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105636 Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.po... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105634 Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105635 Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ us... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105326 An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that sup... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104714 Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localize... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104713 Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bo... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104712 Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (j... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104711 Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apac... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103349 Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This is... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103086 Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103352 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-bookin... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103334 Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reserva... | HIGH | ????? | ????? | NVD | 1 day ago |