🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-102383 Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This iss... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-100509 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105388 A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controlle... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105387 A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105386 A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is t... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-78411 Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-78413 Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-42700 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget image-sli... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105633 Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105631 Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAss... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105630 Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an ima... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105629 Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-k... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105628 Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104979 Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104978 Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104977 Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurli... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104971 Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104975 Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104974 Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104973 Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is cr... | HIGH | ????? | ????? | NVD | 1 day ago |