Threat intelligence dashboard
Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.
Attack reports – last 7 days · through Saturday 25 July 2026 (31)
-
Confidence 100 4 CVEs 12 MITREs 4 IOCs 4 Observables
-
Confidence 100 20 MITREs 4 Malwares 2 IOCs 2 Observables 1 APT
-
Confidence 100 20 MITREs 2 Malwares 23 IOCs 23 Observables 1 APT
-
Confidence 100 1 IOC 1 Observable 1 APT
-
Confidence 100 7 CVEs 16 MITREs 5 Malwares 17 IOCs 5 Observables
Vulnerabilities today (19)
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets …
- Published
- 25/07/2026
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the …
- Attack vector
- NETWORK
- Complexity
- HIGH
- Published
- 25/07/2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
- Attack vector
- NETWORK
- Complexity
- HIGH
- Published
- 25/07/2026
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 25/07/2026
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload …
- Attack vector
- NETWORK
- Complexity
- HIGH
- Published
- 25/07/2026
In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. …
- Attack vector
- LOCAL
- Complexity
- HIGH
- Published
- 25/07/2026
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
Weintek cMT3092X HMI stores user account passwords in plaintext.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026
An attacker can modify data that should be restricted to read‑only access.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 25/07/2026