216.73.216.145

Threat intelligence dashboard

Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.

Attack reports – last 7 days · through Saturday 25 July 2026 (31)

Vulnerabilities today (19)

Sorted by CVSS severity (highest first)

10.0 Critical

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth …

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
9.8 Critical

The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty …

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
9.3 Critical

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets …

Published
25/07/2026
8.8 High

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
8.8 High

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
8.1 High

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the …

Attack vector
NETWORK
Complexity
HIGH
Published
25/07/2026
8.1 High

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

Attack vector
NETWORK
Complexity
HIGH
Published
25/07/2026
7.8 High

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls …

Attack vector
LOCAL
Complexity
LOW
Published
25/07/2026
7.5 High

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload …

Attack vector
NETWORK
Complexity
HIGH
Published
25/07/2026
6.5 Medium

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. …

Attack vector
LOCAL
Complexity
HIGH
Published
25/07/2026
6.5 Medium

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, …

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
6.5 Medium

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header …

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
6.5 Medium

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart …

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
6.5 Medium

Weintek cMT3092X HMI stores user account passwords in plaintext.

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026
6.5 Medium

An attacker can modify data that should be restricted to read‑only access.

Attack vector
NETWORK
Complexity
LOW
Published
25/07/2026