Security Intelligence
Feed

Real-time CVE tracking, exploit analysis, and vulnerability intelligence curated for security professionals.

307 New today
65,239 Total advisories
Live Monitoring

Daily Security Trends (Last 14 Days)

245
Jun 11
336
Jun 12
60
Jun 13
68
Jun 14
443
Jun 15
630
Jun 16
464
Jun 17
3
Jun 18
352
Jun 19
56
Jun 20
104
Jun 21
317
Jun 22
294
Jun 23
307
Jun 24
Critical
High
Medium
Low

Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-9773

Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability_CVE-2026-9773

Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar...

Unraid Unraid 1161ec120 CVE
HIGH 8.8 CVE-2026-9772

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability_CVE-2026-9772

Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary...

Unraid Unraid 1161ec120 CVE
HIGH 8.1 CVE-2026-55762

Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint_CVE-2026-55762

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, ...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 CVE
HIGH 7.4 CVE-2026-55759

Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay_CVE-2026-55759

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, ...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 CVE
CRITICAL 9.3 CVE-2026-55666

Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth_CVE-2026-55666

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, ...

RocketChat Rocket.Chat >= 8.5.0-rc.0, < 8.5.1 CVE
CRITICAL 9 CVE-2026-55570

SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescaped `data-obj` attribute (Bypass for CVE-2026-45375’s patch)_CVE-2026-55570

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, desc...

siyuan-note siyuan < 3.7.0 CVE
MEDIUM 5.3 CVE-2026-55455

Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist_CVE-2026-55455

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils...

appsmithorg appsmith < 2.1 CVE
CRITICAL 9.9 CVE-2026-55454

Appsmith: Caddy admin API exposed without authentication_CVE-2026-55454

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has...

appsmithorg appsmith < 2.1 CVE
HIGH 8.7 CVE-2026-54759

SiYuan: Lute HTML sanitizer allows `