CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data Vulner…
CISA KEV·13d
exploited
CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate P…
CISA KEV·14d
exploited
CVE-2026-9198 — IBM Langflow Code Injection Vulnerability
CISA KEV·14d
exploited
CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data Vulnerab…
CISA KEV·14d
exploited
CVE-2026-18737 — Shlink contains a blind SQL injection vulnerability that allows…
NVD·14d
CVE-2026-18736 — Shlink contains a server-side request forgery vulnerability tha…
NVD·14d
CVE-2026-18733 — A prompt injection vulnerability in the shell tool in Amazon St…
NVD·14d
CVE-2026-18648 — A vulnerability was detected in Blix Email Blue Mail Calendar A…
NVD·14d
CVE-2026-18647 — A security vulnerability has been detected in jina-ai reader up…
NVD·14d
CVE-2026-18646 — A weakness has been identified in danpros HTMLy up to 3.1.1. Th…
NVD·14d
CVE-2026-18645 — A security flaw has been discovered in danpros HTMLy up to 3.1.…
NVD·14d
CVE-2026-69198 — ip-address is a library for parsing and manipulating IPv4 and I…
NVD·14d
CVE-2026-69192 — ip-address is a library for parsing and manipulating IPv4 and I…
NVD·14d
CVE-2026-69185 — Socket.IO enables bidirectional and low-latency communication f…
NVD·14d
CVE-2026-68981 — Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requ…
NVD·14d
CVE-2026-68980 — Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and…
NVD·14d
CVE-2026-68979 — Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context u…
An attacker could change critical settings in your data flow tool without proper permission checks, potentially disrupting operations or stealing data.
NVD·14d
patch now
CVE-2026-67599 — ClearOS 7.9 contains an OS command injection vulnerability in t…
NVD·14d
CVE-2026-67598 — Emlog Pro through 2.6.23 contains a disabled TLS certificate va…
NVD·14d
CVE-2026-66296 — Improper Neutralization of Input During Web Page Generation (XS…
NVD·14d
CVE-2026-62354 — Authorization handling for Parameter Context validation request…
NVD·14d
CVE-2026-58139 — The DuckDB AWS extension for DuckDB contains a security policy …
NVD·14d
CVE-2026-48031 — go-base is a Go RESTful API Boilerplate template with JWT Authe…
NVD·14d
CVE-2026-47211 — Ouroboros is a local-first runtime for AI coding agents that re…
NVD·14d
CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate P…