🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-102295 A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaS... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102576 A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Becaus... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-101919 A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privile... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2025-15643 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97309 Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects Re... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97305 Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorre... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97070 Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access C... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105632 Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any proj... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104976 Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that res... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105385 A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerabil... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104905 FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attack... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-78412 Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions a... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104970 Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-11... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104969 Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104967 Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ acc... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104965 Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validatin... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104956 Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query pa... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104964 Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104963 Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and GET /api/works... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104962 Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{project_id}/members/ returns the complete pro... | MEDIUM | ????? | ????? | NVD | 1 day ago |