🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-97307 Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embe... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105147 A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of th... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-104204 R Summary I found a server-side denial-of-service issue in bacnet-stack 1.6.0 affecting the Structured View object implementation. The issue is reachabl... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-97692 R Summary The BACnet/SC message decoder walks the header-option list by following each option's MORE bit. Nothing rejects a list whose last option ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-82414 R Summary The BACnet MS/TP receive path decodes COBS frames into an output pointer inside the same fixed input buffer, but passes the full input-buffer ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-102612 R Summary `bws_srv_start()` in `ports/linux/websocket-srv.c` builds the libwebsockets server context with a CA certificate loaded but never sets `LWS_SE... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-102537 R Summary `bws_cli_connect()` in `ports/linux/websocket-cli.c` loads the trusted CA cert into the libwebsockets context, then always sets `LCCSCF_ALLOW_... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-100403 R ## Summary The BACnet/SC hub's Linux WebSocket server reassembles fragmented WebSocket messages into a per-connection `fragment_buffer`. It grows... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105146 A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the f... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-97276 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103355 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements ... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103354 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Block... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103344 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103062 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepre... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105145 A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/c... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 2 days ago |
| CVE-2026-105144 A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFile... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105141 A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/mo... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105137 A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-97332 The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite... | MEDIUM | ????? | ????? | NVD | 2 days ago |