🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104433 Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthe... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105051 Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyper... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105049 Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the p... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105048 The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105050 PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation chara... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104887 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78409. Reason: This candidate is a duplicate of CVE-2026-78409. N... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104886 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78410. Reason: This candidate is a duplicate of CVE-2026-78410. N... | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105043 MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code ... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-105046 Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-94591 Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-94592 Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rathe... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-94593 Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-94594 Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party wit... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104874 Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, ope... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104055 The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-75937 A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system com... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82045 UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNet... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82044 UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82043 UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-39718 Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from... | HIGH | ????? | ????? | NVD | 4 days ago |