🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-103435 R Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105315 A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-39783 Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a throu... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105073 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retri... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-103684 Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63270 URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remot... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63269 LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63268 LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder o... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63267 LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the docume... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63266 LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-63277 LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-94669 Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access C... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-39763 Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Acc... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105307 A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API End... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105396 Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review l... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105291 A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcr... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105290 A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleControlle... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-59788 The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is ex... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-59787 The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone a... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-59786 Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone w... | MEDIUM | ????? | ????? | NVD | 1 day ago |