🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-96613 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shad... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104847 ### Impact
When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run i... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104910 MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-101104 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations o... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104908 MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new ... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104907 MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104906 MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104843 ### Impact
In versions of uv from 0.12.7 to 0.12.18 on Windows, uv could be induced into writing a file outside of the installation prefix during whe... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104901 MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queri... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-90970 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 befo... | CRITICAL | ????? | ????? | NVD | 4 days ago |
| CVE-2026-5782 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in MRV Technology Foreign Trade Ltd. Co. ... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-39717 Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This is... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-39601 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar book... | LOW | ????? | ????? | NVD | 4 days ago |
| CVE-2026-39600 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.T... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-39444 Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Confi... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-39439 Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This i... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-32585 Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Lev... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-32584 Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smar... | MEDIUM | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104026 In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository... | HIGH | ????? | ????? | NVD | 4 days ago |
| CVE-2026-104900 MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template esc... | MEDIUM | ????? | ????? | NVD | 4 days ago |