216.73.216.197

Threat intelligence dashboard

Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.

Attack reports – last 7 days · through Monday 20 July 2026 (38)

Vulnerabilities today (159)

Sorted by CVSS severity (highest first)

10.0 Critical

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
10.0 Critical

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.9 Critical

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.9 Critical

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.8 Critical

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.8 Critical

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.8 Critical

FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.8 Critical

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable …

Attack vector
Network
Complexity
Low
EPSS
0.0014 (P3.7%)
Published
20/07/2026
9.4 Critical

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.3 Critical

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.3 Critical

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into …

Published
20/07/2026
9.1 Critical

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's …

Published
20/07/2026
9.1 Critical

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the …

Attack vector
NETWORK
Complexity
LOW
EPSS
0.0014 (P3.4%)
Published
20/07/2026
9.0 Critical

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026
9.0 Critical

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but …

Attack vector
NETWORK
Complexity
LOW
Published
20/07/2026