🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-102778 Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a sh... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102780 Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditio... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102776 Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which t... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102775 Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's or... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-102428 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided an... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104892 Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privil... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-89039 A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the con... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-88394 WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary fi... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-88391 Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-88392 Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code. | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-79820 A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware. | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105421 Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configur... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105329 A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManag... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105397 LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject s... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-92931 CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remo... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106119 LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77805 In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools la... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77804 In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77803 In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the prox... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-77802 In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request for... | MEDIUM | ????? | ????? | NVD | 1 day ago |