🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-105122 OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make O... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105121 OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms be... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105120 OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to ... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105119 OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105118 OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_tok... | LOW | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105117 OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105116 OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-ba... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105115 OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote a... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105114 OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying craft... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105113 Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. A... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-105112 Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock th... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-104983 A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the compo... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71890 In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.valid... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71891 In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-18040 In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by ... | MEDIUM | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71885 In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode'... | CRITICAL | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71886 In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any compon... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71887 In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature ca... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71883 In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller'... | HIGH | ????? | ????? | NVD | 3 days ago |
| CVE-2026-71888 In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagr... | HIGH | ????? | ????? | NVD | 3 days ago |