Threat intelligence dashboard
Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.
Attack reports – last 7 days · through Monday 20 July 2026 (38)
-
Confidence 100 20 MITREs 14 Malwares 72 IOCs 58 Observables 1 APT
-
Confidence 100 19 MITREs 2 Malwares 13 IOCs 4 Observables 1 APT
-
Confidence 100 1 CVE 20 MITREs 1 Malware 3 IOCs 2 Observables
-
Confidence 100 24 MITREs 1 Malware
-
Confidence 100 18 MITREs 2 Malwares 16 IOCs 16 Observables
Vulnerabilities today (159)
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable …
- Attack vector
- Network
- Complexity
- Low
- EPSS
- 0.0014 (P3.7%)
- Published
- 20/07/2026
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into …
- Published
- 20/07/2026
lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's …
- Published
- 20/07/2026
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the …
- Attack vector
- NETWORK
- Complexity
- LOW
- EPSS
- 0.0014 (P3.4%)
- Published
- 20/07/2026
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 20/07/2026