Threat intelligence dashboard
Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.
Attack reports – last 7 days · through Thursday 23 July 2026 (19)
-
Confidence 100 4 IOCs 4 Observables 1 APT
-
Confidence 100 20 MITREs 1 Malware 2 IOCs 2 Observables 1 APT
-
Confidence 100 4 CVEs 15 MITREs 6 Malwares 17 IOCs 11 Observables 1 APT
-
Confidence 100 2 CVEs 16 MITREs 1 Malware 3 IOCs 3 Observables
-
Confidence 100 8 IOCs 8 Observables
Vulnerabilities today (304)
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- Attack vector
- Network
- Complexity
- Low
- Published
- 23/07/2026
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- Attack vector
- Network
- Complexity
- Low
- Published
- 23/07/2026
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 23/07/2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
- Attack vector
- Network
- Complexity
- Low
- Published
- 23/07/2026
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- Attack vector
- Network
- Complexity
- Low
- Published
- 23/07/2026