Threat intelligence dashboard
Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.
Attack reports – last 7 days · through Monday 27 July 2026 (26)
-
Confidence 100 4 CVEs 12 MITREs 4 IOCs 4 Observables
-
Confidence 100 20 MITREs 4 Malwares 2 IOCs 2 Observables 1 APT
-
Confidence 100 20 MITREs 2 Malwares 23 IOCs 23 Observables 1 APT
-
Confidence 100 1 IOC 1 Observable 1 APT
-
Confidence 100 7 CVEs 16 MITREs 5 Malwares 17 IOCs 5 Observables
Vulnerabilities today (198)
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and …
- Attack vector
- Network
- Complexity
- Low
- Published
- 27/07/2026
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- Attack vector
- Network
- Complexity
- Low
- Published
- 27/07/2026
A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges …
- Published
- 27/07/2026
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
- Attack vector
- Network
- Complexity
- Low
- Published
- 27/07/2026
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/07/2026