Security Intelligence
Feed

Real-time CVE tracking, exploit analysis, and vulnerability intelligence curated for security professionals.

199 New today
64,510 Total advisories
Live Monitoring

Daily Security Trends (Last 14 Days)

658
Jun 9
351
Jun 10
245
Jun 11
336
Jun 12
60
Jun 13
68
Jun 14
443
Jun 15
630
Jun 16
464
Jun 17
3
Jun 18
352
Jun 19
56
Jun 20
104
Jun 21
189
Jun 22
Critical
High
Medium
Low

Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-4259

Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions_CVE-2026-4259

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page,...

Unknown ultimate-woocommerce-auction-pro CVE
MEDIUM 5.1 CVE-2026-12863

Open redirect_CVE-2026-12863

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

pretix Venueless 0.0.0 CVE
CRITICAL 9.4 CVE-2026-56422

MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields_CVE-2026-56422

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope fore...

misp misp CVE
MEDIUM 4.3 CVE-2026-9162

Global session revocation does not invalidate active WebSocket connections_CVE-2026-9162

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
HIGH 7.3 CVE-2026-9029

Stored XSS via Geomap Panel Template Variable Attribution Injection_CVE-2026-9029

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before g...

Grafana Grafana OSS 12.4.0 CVE
LOW 3.8 CVE-2026-8074

Improper Permission Check Allows User Manager to Deactivate Bot Accounts_CVE-2026-8074

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 6.9 CVE-2026-7167

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7167

The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fak...

Gaudire Assassin game last version CVE
CRITICAL 9.2 CVE-2026-7166

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7166

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘...

Gaudire Assassin game last version CVE
CRITICAL 9.4 CVE-2026-7165

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7165

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of ot...

Gaudire Assassin game last version CVE