🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-103628 Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103627 Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Ch... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103626 Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103625 Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103624 Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer pr... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103623 Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a cra... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103622 Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTM... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-103621 Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104848 `tinypool` passes worker options to `new Worker()` by reading them off a plain object whose prototype is `Object.prototype`. Options the application d... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104914 MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints.
When a user queries for soft-d... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104912 MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers corr... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-96613 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shad... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104847 ### Impact
When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run i... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104910 MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-101104 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations o... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104908 MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104907 MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104906 MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104843 ### Impact
In versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during whe... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104901 MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queri... | MEDIUM | ????? | ????? | NVD | 4 days ago |