🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-105133 A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java... | MEDIUM | ????? | ????? | NVD | 2 days ago |
| CVE-2026-77473 R Summary `SFTPClient._copy()`, used by `get()`, `mget()`, and `copy()` when recursing into a remote directory, builds the local destination path for ea... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105099 A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/tick... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105098 A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the componen... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-88779 Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and befor... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105097 A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105131 ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session tok... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105096 A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105130 LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105129 LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to rea... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105128 LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105127 LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS look... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105126 LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105125 LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang}... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105124 W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts v... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105123 W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by a... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-96451 Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This iss... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-103342 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-103065 Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACL... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105105 CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through ... | CRITICAL | ????? | ????? | NVD | 3 days ago |