🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-105288 A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105287 A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.c... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105286 A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-19395 In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value.... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-39721 Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-19185 The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-97071 Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-19184 The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against t... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105064 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements Fo... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105069 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirect... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105068 Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105062 Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105060 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcas... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105056 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ec... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105055 Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.Thi... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104675 Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Secu... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104409 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Til... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104400 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stor... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104673 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Rad... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104408 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allow... | HIGH | ????? | ????? | NVD | 1 day ago |