🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-104872 OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104994 Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occur... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103918 oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPl... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103036 oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoerci... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82042 UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by present... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82041 UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /com... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104019 OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x befor... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104873 LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82040 UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticate... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-82039 UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inj... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104871 A Path Traversal vulnerability exists in the prerendered (SSG) page retrieval logic of `CommonEngine` in `@angular/ssr/node` (and `@angular/ssr` in ea... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104991 Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, singl... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-96940 Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-19856 The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103958 Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote u... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103957 Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the acces... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103956 Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2020-37278 Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host syste... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2014-125130 CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerab... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2023-54405 H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability ... | CRITICAL | ????? | ????? | NVD | 4 days ago |