🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-61586 R Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-64818 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | ????? | ????? | NVD | 4 days ago |
| CVE-2026-59265 A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbit... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104861 probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104859 Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipelin... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-102795 Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 th... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104855 Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.c... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104851 fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.R... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-102626 An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104854 ## Summary
Nx creates the Unix domain sockets for its daemon and its plugin workers in a shared temporary directory with default permissions, so any ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104853 ## Summary
`nx migrate` reads each target package's `nx-migrations.migrations` value from its manifest and extracts the referenced file to a pat... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104849 Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-67989 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51922 agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attack... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51907 In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files t... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51906 In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51904 SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51918 FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51917 FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-51916 TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py.... | HIGH | ????? | ????? | NVD | 4 days ago |