🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-100403 R ## Summary The BACnet/SC hub's Linux WebSocket server reassembles fragmented WebSocket messages into a per-connection `fragment_buffer`. It grows... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105146 A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the f... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-97276 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103355 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements ... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103354 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Block... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103344 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements ... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-103062 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepre... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105145 A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/c... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| ???-????-???? ?????????????????????????????????? ?????????????????????????????????? | HIGH | ????? | ????? | SA | 2 days ago |
| CVE-2026-105144 A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFile... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105141 A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/mo... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105137 A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-97332 The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-93549 The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's... | HIGH | ????? | ????? | NVD | 2 days ago |
| CVE-2026-86817 The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default ... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-17005 The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-104119 The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings p... | LOW | ????? | ????? | NVD | 2 days ago |
| CVE-2026-104118 The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105135 A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py... | CRITICAL | ????? | ????? | NVD | 2 days ago |
| CVE-2026-105134 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the comp... | CRITICAL | ????? | ????? | NVD | 2 days ago |