FACTUALRISK Cyber Intelligence
Mise à jour : 29 Aug 2026 · 12:02
🗞 Briefing
💥 Menaces
🛡 Vulnérabilités
📋 Conformité
📚 Guides
← Retour FactualRisk
P0 — Urgence
31
KEV + signal fort
KEV exploité
29
14j: 20 nouveaux
EPSS élevé
15
≥ 0.20 (exploitation probable)
Total findings
166
Top 300 • tri score
⚠️ P0 • CVE-2026-60004 • Gitea Gitea — Gitea Code Injection Vulnerability • P0 • CVE-2026-8037 • Progress LoadMaster — Progress LoadMaster Command Injection Vulnerability • P0 • CVE-2021-23758 • Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability • P0 • CVE-2026-63077 • JetBrains TeamCity — JetBrains TeamCity Deserialization of Untrusted Data Vulnerability • P0 • CVE-2019-1068 • Microsoft SQL Server — Microsoft SQL Server Remote Code Execution Vulnerability • P0 • CVE-2026-34486 • Apache Tomcat — Apache Tomcat Missing Encryption of Sensitive Data Vulnerability • P0 • CVE-2026-72898 • Metabase Metabase — Metabase SQL Injection Vulnerability • P0 • CVE-2026-21962 • Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability • P0 • CVE-2026-33824 • Microsoft Internet Key Exchange (IKE) Service Extensions — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • P0 • CVE-2023-49105 • ownCloud ownCloud — ownCloud Improper Authentication Vulnerability • P0 • CVE-2026-59310 • Broadcom VMware vCenter — Broadcom VMware vCenter Path Traversal Vulnerability • P0 • CVE-2026-18577 • N-able N-central — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability • P0 • CVE-2026-9198 • IBM Langflow — IBM Langflow Code Injection Vulnerability • P0 • CVE-2026-55040 • Microsoft SharePoint — Microsoft SharePoint Weak Authentication Vulnerability • P0 • CVE-2026-18556 • N-able N-central — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability • P0 • CVE-2026-64849 • MLflow MLflow — MLflow Server-Side Request Forgery Vulnerability • P0 • CVE-2026-73570 • Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability • P0 • CVE-2025-62593 • Ray-Project Ray — Ray-Project Ray Code Injection Vulnerability
World Clocksmaj 1s
Status Sourceslatence
• CISA KEV0.10s
• OSV.dev0.38s
🐙 GHSA0.97s
📋 NVD4.88s
📊 EPSS0.33s
🦠 Ransomware.live41.43s
💣 Exploit-DB5.93s
• AlienVault OTX18.05s
📡 GreyNoise1.60s
🔗 URLhaus0.00s
🗺️ MITRE CVE0.10s
✅ VulnCheck Community1.07s
• Security Social0.06s
• Enhanced Vendor Feeds95.53s
• Press/Buzz1.60s
Tendances 7 jours KEV P0 P1 EPSS↑
Top Vendors
maven42
Ubuntu20
composer18
go17
pip14
npm7
Microsoft4
Linux2
Red Hat2
TrueConf2
N-able2
rust2
Top CWEs
CWE-2024
CWE-226
CWE-4166
CWE-4006
CWE-5025
CWE-895
CWE-6395
CWE-2874
🧩 CMS & E-commerceWordPress, Presta…
WordPress1
🌐 Threat Intel — 7 derniers jours
Chargement threat intel…
P1 P2 KEV only EPSS≥0.20 REMOTE PoC CRITICAL 🆕 Nouveaux
Visible: --
Heatmap CVSS × EPSS (visible)survol = détail CVE
Prio CVE Sev CVSS EPSS Score Vendor Produit CWE Description Signaux
P0 CVE-2026-60004 NOUVEAU CRITICAL 9.8 0.824 280.7 Gitea Gitea CWE-94 Gitea Code Injection Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2026-8037 CRITICAL 9.8 0.996 253.3 Progress LoadMaster CWE-77 Progress LoadMaster Command Injection Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2021-23758 MAJ CRITICAL 9.8 0.836 244.2 Ajax.NET Professional Ajax.NET Professional CWE-502 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability KEV EPSS↑ CWE! ⛓ SUPPLY 🗺 ATT&CK
P0 CVE-2026-63077 CRITICAL 9.8 0.847 235.5 JetBrains TeamCity CWE-502 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2019-1068 MAJ HIGH 8.8 0.528 234.2 Microsoft SQL Server NVD-CWE-noinfo Microsoft SQL Server Remote Code Execution Vulnerability KEV EPSS↑ 🗺 ATT&CK
P0 CVE-2026-34486 HIGH 7.5 0.986 233.3 Apache Tomcat CWE-311 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability KEV EPSS↑ 🗺 ATT&CK
P0 CVE-2026-72898 CRITICAL 10.0 0.792 230.1 Metabase Metabase CWE-89 Metabase SQL Injection Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2026-21962 MAJ CRITICAL 10.0 0.420 228.4 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in CWE-284 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability KEV EPSS↑
P0 CVE-2026-33824 CRITICAL 9.8 0.727 216.0 Microsoft Internet Key Exchange (IKE) Service Extensions CWE-415 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability KEV EPSS↑ 🗺 ATT&CK
P0 CVE-2023-49105 MAJ CRITICAL 9.8 0.412 191.2 ownCloud ownCloud CWE-287 ownCloud Improper Authentication Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2026-59310 CRITICAL 9.8 0.459 188.8 Broadcom VMware vCenter CWE-22 Broadcom VMware vCenter Path Traversal Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2026-18577 HIGH 8.1 0.541 183.5 N-able N-central CWE-288 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability KEV EPSS↑ 🗺 ATT&CK
P0 CVE-2026-9198 CRITICAL 9.8 0.347 175.5 IBM Langflow CWE-94 IBM Langflow Code Injection Vulnerability KEV EPSS↑ CWE! 🗺 ATT&CK
P0 CVE-2026-55040 CRITICAL 9.1 0.397 172.2 Microsoft SharePoint CWE-1390 Microsoft SharePoint Weak Authentication Vulnerability KEV EPSS↑ 🗺 ATT&CK
P0 CVE-2026-18556 HIGH 7.4 0.402 162.6 N-able N-central CWE-288 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability KEV EPSS↑ 🗺 ATT&CK
P0 CVE-2026-64849 CRITICAL 9.3 0.164 160.5 MLflow MLflow CWE-918 MLflow Server-Side Request Forgery Vulnerability KEV CWE! ⛓ SUPPLY 🗺 ATT&CK
P0 CVE-2026-73570 MAJ HIGH 8.9 0.015 148.2 Synacor Zimbra Collaboration Suite (ZCS) CWE-78 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability KEV CWE! ⛓ SUPPLY 🗺 ATT&CK
P0 CVE-2025-62593 HIGH 8.8 0.169 148.1 Ray-Project Ray CWE-94 Ray-Project Ray Code Injection Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-65400 CRITICAL 9.8 0.099 145.7 Apple macOS CWE-287 Apple macOS Improper Authentication Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-8452 MAJ CRITICAL 9.8 0.016 135.7 Citrix NetScaler ADC and NetScaler Gateway CWE-119 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-72529 CRITICAL 9.8 0.016 135.7 TrueConf Server CWE-306 TrueConf Server Missing Authentication for Critical Function Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-74232 NOUVEAU CRITICAL 9.8 0.005 134.4 CWE-300 China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access 📡 ITW ⛓ SUPPLY 🗺 ATT&CK
P0 CVE-2022-0995 MAJ HIGH 7.8 0.095 133.2 Linux Kernel CWE-787 Linux Kernel Out-of-Bounds Write Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-74233 NOUVEAU CRITICAL 9.8 0.026 132.0 CWE-78 China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access CWE! 📡 ITW 🗺 ATT&CK
P0 CVE-2026-72530 CRITICAL 9.0 0.018 131.2 TrueConf Server CWE-94 TrueConf Server Code Injection Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-53362 MAJ HIGH 7.8 0.003 130.1 Linux Kernel CWE-787 Linux Kernel Unspecified Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-68820 HIGH 7.0 0.062 124.4 Microsoft Windows Ancillary Function Driver for WinSock CWE-416 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability KEV CWE! 🗺 ATT&CK
P0 CVE-2026-20349 HIGH 8.6 0.022 124.3 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) CWE-244 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability KEV 🗺 ATT&CK
P0 CVE-2015-5287 MAJ HIGH 7.8 0.050 122.8 Red Hat Automatic Bug Reporting Tool CWE-59 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability KEV
P1 CVE-2015-3246 MAJ MEDIUM 5.1 0.088 121.2 Red Hat Libuser CWE-264 Red Hat Libuser Race Condition Vulnerability KEV ⛓ SUPPLY 🗺 ATT&CK
P0 CVE-2026-44017 MAJ HIGH 7.5 0.007 120.8 pip docling CWE-22 Docling: Unsafe Zip Extraction in EasyOCR Model Download CWE! 🦠 RANSOM 📡 ITW ⛓ SUPPLY 🗺 ATT&CK
P0 CVE-2026-19913 NOUVEAU HIGH 7.5 0.004 110.4 CWE-20 Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code CWE! 🦠 RANSOM 📡 ITW 🗺 ATT&CK
P1 CVE-2026-66384 MEDIUM 5.3 0.003 107.1 JFrog Artifactory CWE-22 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability KEV CWE! 🗺 ATT&CK
P2 CVE-2026-55761 NOUVEAU HIGH 5.9 0.005 101.0 go github.com/portainer/portainer CWE-287 Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances CWE! 🦠 RANSOM 📡 ITW 🗺 ATT&CK
P2 CVE-2026-44727 MAJ CRITICAL 5.4 0.004 97.9 pip jupyter-server CWE-79 Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP CWE! 🦠 RANSOM 📡 ITW 🗺 ATT&CK
P2 CVE-2026-55779 NOUVEAU MEDIUM 5.4 0.000 97.4 composer silverstripe/versioned CWE-79 silverstripe/versioned has XSS in archive admin restore CWE! 🦠 RANSOM 📡 ITW 🗺 ATT&CK
P1 CVE-2026-46456 MAJ CRITICAL 9.8 0.008 74.8 maven org.apache.camel:camel-aws2-sqs CWE-20 Apache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers CWE! ⛓ SUPPLY 🗺 ATT&CK
P1 CVE-2026-71300 NOUVEAU CRITICAL 9.8 0.005 74.3 maven org.apache.camel:camel-atmosphere-websocket CWE-20 Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection - the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace CWE! ⛓ SUPPLY 🗺 ATT&CK
P1 CVE-2026-78329 NOUVEAU CRITICAL 9.8 0.004 74.3 maven org.apache.camel:camel-undertow CWE-20 Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes CWE! ⛓ SUPPLY 🗺 ATT&CK
P1 CVE-2026-53247 NOUVEAU CRITICAL 9.8 0.005 72.4 Ubuntu CWE-416 USN-8643-5: Linux kernel vulnerabilities CWE! 🗺 ATT&CK
P1 CVE-2026-53246 NOUVEAU CRITICAL 9.8 0.004 72.3 Ubuntu CWE-787 USN-8644-3: Linux kernel (Azure) vulnerabilities CWE! 🗺 ATT&CK
P1 CVE-2026-57433 NOUVEAU CRITICAL 9.8 0.004 72.2 Ubuntu CWE-190 USN-8684-1: Perl vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2026-48203 MAJ CRITICAL 9.1 0.006 70.3 maven org.apache.camel:camel-solr CWE-20 Apache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (ser CWE! ⛓ SUPPLY 🗺 ATT&CK
P1 CVE-2026-46455 MAJ CRITICAL 9.8 0.007 69.6 maven org.apache.camel:camel-keycloak CWE-613 Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted ⛓ SUPPLY
P2 CVE-2026-46590 MAJ HIGH 8.8 0.008 68.8 maven org.apache.camel:camel-pqc CWE-502 Apache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-53043 NOUVEAU CRITICAL 9.1 0.005 68.2 Ubuntu CWE-787 USN-8644-3: Linux kernel (Azure) vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2026-53224 NOUVEAU CRITICAL 9.1 0.005 68.2 Ubuntu CWE-125 USN-8644-3: Linux kernel (Azure) vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2026-13221 NOUVEAU CRITICAL 9.1 0.004 68.1 Ubuntu CWE-190 USN-8684-1: Perl vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2026-12087 NOUVEAU CRITICAL 9.1 0.004 68.0 Ubuntu CWE-125 USN-8684-1: Perl vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2026-18963 CRITICAL 9.1 0.028 68.0 maven org.keycloak:keycloak-services CWE-640 Keycloak: Unauthenticated account takeover via reset-credentials flow bypass ⛓ SUPPLY 🗺 ATT&CK
P1 CVE-2026-53309 NOUVEAU CRITICAL 9.8 0.004 67.3 Ubuntu CWE-193 USN-8644-3: Linux kernel (Azure) vulnerabilities
P2 CVE-2026-55848 NOUVEAU HIGH 8.6 0.000 66.6 maven org.mapfish.print:print-lib CWE-611 MapFish Print has XXE that allows reading arbitrary files of certain types CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-66906 NOUVEAU CRITICAL 9.1 0.005 65.2 maven org.apache.camel:camel-azure-storage-blob CWE-23 Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir ⛓ SUPPLY 🗺 ATT&CK
P1 CVE-2026-55634 NOUVEAU CRITICAL 9.9 0.000 64.4 composer pimcore/pimcore CWE-89 Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name CWE! 🗺 ATT&CK
P2 CVE-2026-57432 NOUVEAU HIGH 8.4 0.002 63.6 Ubuntu CWE-125 USN-8684-1: Perl vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2025-27558 NOUVEAU CRITICAL 9.1 0.003 63.0 Ubuntu CWE-345 USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities
P2 CVE-2026-55638 NOUVEAU HIGH 8.6 0.006 62.3 npm 9router CWE-862 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55175 NOUVEAU HIGH 7.5 0.011 61.3 maven io.spinnaker.rosco:rosco-manifests CWE-502 Spinnaker: Improper yaml processing on kustomize bake operations CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-46726 MAJ HIGH 7.5 0.009 61.0 maven org.apache.camel:camel-vertx-websocket CWE-20 Apache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55993 MAJ HIGH 7.5 0.009 61.0 maven org.apache.camel:camel-atmosphere-websocket CWE-20 Apache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-55220 NOUVEAU CRITICAL 9.3 0.000 60.8 composer pimcore/pimcore CWE-502 Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502) CWE! 🗺 ATT&CK
P3 CVE-2026-46457 MAJ HIGH 7.5 0.007 60.8 maven org.apache.camel:camel-nats CWE-20 Apache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control header CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-46585 MAJ HIGH 7.5 0.006 60.8 maven org.apache.camel:camel-lucene CWE-20 Apache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search quer CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55994 MAJ HIGH 7.5 0.006 60.8 maven org.apache.camel:camel-iggy CWE-20 Apache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-46592 MAJ HIGH 7.5 0.006 60.8 maven org.apache.camel:camel-cxf-soap CWE-20 Apache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the inv CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55474 NOUVEAU HIGH 0.0 0.005 60.6 composer snipe/snipe-it CWE-23 Snipe-IT vulnerable to directory traversal in displaySig 🦠 RANSOM 📡 ITW
P3 CVE-2026-66908 NOUVEAU HIGH 7.5 0.004 60.4 maven org.apache.camel:camel-platform-http-main CWE-287 Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trust CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-39830 MAJ CRITICAL 9.1 0.006 60.4 go golang.org/x/crypto CWE-119 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses CWE! 🗺 ATT&CK
P3 CVE-2026-19912 NOUVEAU LOW 0.0 0.002 60.3 Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code 🦠 RANSOM 📡 ITW 🗺 ATT&CK
P2 CVE-2026-46591 MAJ HIGH 8.2 0.005 59.9 maven org.apache.camel:camel-neo4j CWE-943 Apache Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of ⛓ SUPPLY
P3 CVE-2026-49042 MAJ HIGH 7.3 0.007 59.6 maven org.apache.camel:camel-langchain4j-tools CWE-20 Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-46588 MAJ HIGH 7.3 0.007 59.6 maven org.apache.camel:camel-couchdb CWE-20 Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-46587 MAJ HIGH 7.3 0.007 59.6 maven org.apache.camel:camel-couchbase CWE-20 Apache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-55641 NOUVEAU HIGH 8.2 0.003 59.6 npm 9router CWE-290 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-76639 NOUVEAU HIGH 8.8 0.007 58.7 CWE-22 Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth CWE! 🗺 ATT&CK
P2 CVE-2026-76021 MAJ HIGH 8.8 0.004 58.3 CWE-416 Long Term Support Channel Update for ChromeOS CWE! 🗺 ATT&CK
P2 CVE-2026-76017 MAJ HIGH 8.8 0.004 58.3 CWE-416 Long Term Support Channel Update for ChromeOS CWE! 🗺 ATT&CK
P2 CVE-2026-19559 HIGH 8.8 0.004 58.3 CWE-416 Long Term Support Channel Update for ChromeOS CWE! 🗺 ATT&CK
P2 CVE-2026-76045 HIGH 8.8 0.003 58.2 CWE-416 Long Term Support Channel Update for ChromeOS CWE! 🗺 ATT&CK
P2 CVE-2026-55509 NOUVEAU HIGH 8.8 0.000 57.8 pip WsgiDAV CWE-89 WsgiDAV MySQL provider has a blind SQL injection CWE! 🗺 ATT&CK
P3 CVE-2026-55673 NOUVEAU HIGH 7.1 0.000 57.6 maven com.powsybl:powsybl-computation-local CWE-78 PowSyBl Core has Command Injection in LocalCommandExecutor-s CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-55764 NOUVEAU HIGH 8.7 0.000 57.2 go github.com/klever-io/klever-go CWE-190 klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply CWE! 🗺 ATT&CK
P2 CVE-2026-55245 NOUVEAU HIGH 8.7 0.000 57.2 go github.com/maximhq/bifrost/core CWE-918 Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL CWE! 🗺 ATT&CK
P3 CVE-2026-35397 MAJ HIGH 7.1 0.006 56.3 pip jupyter-server CWE-22 Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories PoC CWE! 🗺 ATT&CK
P3 CVE-2026-66907 NOUVEAU HIGH 7.5 0.006 55.7 maven org.apache.camel:camel-google-storage CWE-23 Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-6322 MAJ HIGH 7.5 0.005 55.6 npm fast-uri CWE-140 fast-uri vulnerable to host confusion via percent-encoded authority delimiters ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-13676 MAJ HIGH 7.5 0.004 55.5 npm fast-uri CWE-436 fast-uri vulnerable to host confusion via failed IDN canonicalization ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55841 NOUVEAU HIGH 7.5 0.000 55.0 maven org.graylog2:graylog2-server CWE-138 Fortigate syslog message parser can be exploited to modify or delete fields from the original message ⛓ SUPPLY
P3 CVE-2026-55215 NOUVEAU HIGH 7.5 0.000 55.0 npm mariadb CWE-295 MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-49086 MAJ MEDIUM 6.5 0.007 54.8 maven org.apache.camel:camel-dapr CWE-20 Apache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-49097 MAJ MEDIUM 6.5 0.007 54.8 maven org.apache.camel:camel-irc CWE-20 Apache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter CWE! ⛓ SUPPLY 🗺 ATT&CK
P2 CVE-2026-55247 NOUVEAU CRITICAL 9.1 0.000 54.6 pip plone.app.event CWE-400 plone.app.event vulnerable to denial of service via iCalendar import
P2 CVE-2026-55248 NOUVEAU CRITICAL 9.1 0.000 54.6 pip plone.app.portlets CWE-400 plone.app.portlets vulnerable to denial of service via RSS feed portlet 🗺 ATT&CK
P3 CVE-2026-59230 NOUVEAU MEDIUM 6.5 0.004 54.5 maven org.apache.camel:camel-mail CWE-20 Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55855 NOUVEAU MEDIUM 6.5 0.000 54.0 npm mariadb CWE-89 MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-40253 NOUVEAU MEDIUM 6.8 0.002 54.0 Ubuntu CWE-125 USN-8686-1: openCryptoki vulnerabilities CWE! 🗺 ATT&CK
P2 CVE-2026-55207 NOUVEAU HIGH 8.8 0.007 53.6 composer pimcore/studio-backend-bundle CWE-640 Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass 🗺 ATT&CK
P2 CVE-2026-76022 MAJ HIGH 8.8 0.005 53.4 CWE-122 Long Term Support Channel Update for ChromeOS 🗺 ATT&CK
P2 CVE-2026-76023 MAJ HIGH 8.8 0.005 53.4 CWE-913 Long Term Support Channel Update for ChromeOS 🗺 ATT&CK
P2 CVE-2026-76018 MAJ HIGH 8.8 0.004 53.3 CWE-250 Long Term Support Channel Update for ChromeOS 🗺 ATT&CK
P2 CVE-2026-55485 NOUVEAU HIGH 8.8 0.000 52.8 pip piccolo-admin CWE-200 piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
P2 CVE-2026-55763 NOUVEAU HIGH 8.7 0.000 52.2 go github.com/klever-io/klever-go CWE-841 klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits 🗺 ATT&CK
P3 CVE-2026-55874 NOUVEAU HIGH 7.7 0.006 51.9 go github.com/seaweedfs/seaweedfs CWE-22 SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read CWE! 🗺 ATT&CK
P3 CVE-2026-55208 NOUVEAU HIGH 7.7 0.004 51.7 composer pimcore/studio-backend-bundle CWE-89 Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes CWE! 🗺 ATT&CK
P3 CVE-2026-44020 MAJ HIGH 7.5 0.006 50.7 pip docling CWE-611 Docling: Unsafe XML Entity Expansion in USPTO Patent Backend CWE! 🗺 ATT&CK
P3 CVE-2026-76640 NOUVEAU HIGH 7.5 0.003 50.4 CWE-306 Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth CWE! 🗺 ATT&CK
P2 CVE-2026-55830 NOUVEAU HIGH 8.3 0.004 50.3 pip RestrictedPython CWE-184 RestrictedPython guard hooks can be shadowed via positional-only arguments 🗺 ATT&CK
P2 CVE-2026-76019 MAJ HIGH 8.1 0.004 49.0 CWE-863 Long Term Support Channel Update for ChromeOS 🗺 ATT&CK
P3 CVE-2026-23893 NOUVEAU MEDIUM 6.8 0.002 49.0 Ubuntu CWE-59 USN-8686-1: openCryptoki vulnerabilities
P2 CVE-2026-61979 HIGH 8.1 0.003 48.9 CWE-266 Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access 🧩 WORDPRESS
P2 CVE-2026-55228 NOUVEAU HIGH 8.1 0.002 48.9 pip Weblate CWE-639 Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
P3 CVE-2026-55212 NOUVEAU HIGH 7.1 0.004 48.0 composer pimcore/studio-backend-bundle CWE-20 Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation CWE! 🗺 ATT&CK
P3 CVE-2026-49098 MAJ MEDIUM 5.3 0.006 47.5 maven org.apache.camel:camel-kafka CWE-20 Apache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-48206 MAJ MEDIUM 5.3 0.006 47.5 maven org.apache.camel:camel-jira CWE-20 Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-63621 NOUVEAU MEDIUM 5.3 0.004 47.2 maven org.apache.camel:camel-knative CWE-20 Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55516 NOUVEAU HIGH 7.7 0.004 46.6 composer snipe/snipe-it CWE-639 Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
P3 CVE-2026-55622 HIGH 7.7 0.002 46.4 go github.com/lxc/incus/v7/cmd/incusd CWE-284 Incus has a project restriction bypass in instance copy across projects
P3 CVE-2026-55621 HIGH 7.7 0.002 46.4 go github.com/lxc/incus/v7 CWE-284 Incus has a project restriction bypass for custom volume copy across projects
P3 CVE-2026-12681 MAJ HIGH 6.8 0.002 46.0 go github.com/google/go-attestation CWE-20 Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() CWE! 🗺 ATT&CK
P3 CVE-2026-55860 NOUVEAU MEDIUM 5.9 0.000 45.4 maven org.mariadb:r2dbc-mariadb CWE-319 org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport) ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55859 NOUVEAU MEDIUM 5.9 0.000 45.4 maven org.mariadb:r2dbc-mariadb CWE-116 org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output ⛓ SUPPLY
P3 CVE-2026-55858 NOUVEAU MEDIUM 5.9 0.000 45.4 maven org.mariadb.jdbc:mariadb-java-client CWE-838 org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55857 NOUVEAU MEDIUM 5.9 0.000 45.4 maven org.mariadb.jdbc:mariadb-java-client CWE-319 org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55856 NOUVEAU MEDIUM 5.9 0.000 45.4 maven org.mariadb.jdbc:mariadb-java-client CWE-522 MariaDB has cleartext password disclosure to a MITM on the initial-handshake ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55854 NOUVEAU MEDIUM 5.9 0.000 45.4 npm mariadb CWE-319 MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-13757 NOUVEAU MEDIUM 6.2 0.001 45.4 Ubuntu CWE-674 USN-8687-1: p11-kit vulnerabilities
P3 CVE-2026-18938 NOUVEAU MEDIUM 6.2 0.001 45.3 Ubuntu CWE-122 USN-8687-1: p11-kit vulnerabilities
P3 CVE-2026-55784 NOUVEAU HIGH 7.5 0.000 45.0 go github.com/free5gc/ausf CWE-362 free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI 🗺 ATT&CK
P3 CVE-2026-55484 NOUVEAU HIGH 7.5 0.000 45.0 go github.com/guno1928/alos-http CWE-248 alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server 🗺 ATT&CK
P3 CVE-2026-55584 NOUVEAU HIGH 7.5 0.000 45.0 composer phpsysinfo/phpsysinfo CWE-290 phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers 🗺 ATT&CK
P3 CVE-2026-60093 NOUVEAU MEDIUM 5.5 0.003 43.3 maven org.apache.camel:camel-azure-storage-datalake CWE-23 Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55520 NOUVEAU HIGH 7.1 0.000 42.6 pip Protego CWE-400 Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
P3 CVE-2026-49365 MAJ MEDIUM 5.3 0.006 42.5 maven org.apache.camel:camel-netty-http CWE-209 Apache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-56139 MAJ MEDIUM 5.3 0.006 42.5 maven org.apache.camel:camel-undertow CWE-209 Apache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-49099 MAJ MEDIUM 5.3 0.005 42.4 maven org.apache.camel:camel-salesforce CWE-74 Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55867 NOUVEAU MEDIUM 5.3 0.000 41.8 maven org.graylog2:graylog2-server CWE-639 Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens ⛓ SUPPLY
P3 CVE-2026-55678 NOUVEAU MEDIUM 6.9 0.000 41.4 go github.com/basekick-labs/arc CWE-284 arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset 🗺 ATT&CK
P3 CVE-2026-48710 MAJ MEDIUM 6.5 0.019 41.3 pip starlette CWE-444 Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
P3 CVE-2025-15649 NOUVEAU MEDIUM 5.5 0.001 41.1 Ubuntu CWE-248 USN-8684-1: Perl vulnerabilities
P3 CVE-2026-55425 NOUVEAU MEDIUM 5.0 0.000 40.0 maven org.graylog2:graylog2-server CWE-213 Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields ⛓ SUPPLY
P3 CVE-2026-55843 NOUVEAU HIGH 6.5 0.005 39.6 composer snipe/snipe-it CWE-269 Snipe-IT has an Improper Privilege Management issue
P3 CVE-2026-27878 MAJ MEDIUM 6.5 0.004 39.5 go github.com/grafana/tempo CWE-400 Grafana Tempo vulnerable to an out-of-memory crash
P3 CVE-2026-46584 MAJ LOW 3.7 0.006 37.9 maven org.apache.camel:camel-mail CWE-20 Apache Camel-Mail: The mail producer applied attacker-supplied mail.smtp.* / mail.smtps.* message headers as JavaMail session properties CWE! ⛓ SUPPLY 🗺 ATT&CK
P3 CVE-2026-55475 NOUVEAU MEDIUM 5.7 0.003 34.6 composer snipe/snipe-it CWE-863 Snipe-IT's import created_by can be overwritten
P3 CVE-2020-24588 MAJ LOW 3.5 0.035 33.2 Ubuntu CWE-327 USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities
P3 CVE-2026-39835 MAJ MEDIUM 5.3 0.005 32.4 go golang.org/x/crypto CWE-295 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow 🗺 ATT&CK
P3 CVE-2026-55696 NOUVEAU MEDIUM 4.3 0.000 30.8 composer privatebin/privatebin CWE-79 PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction CWE! 🗺 ATT&CK
P3 CVE-2026-76033 MEDIUM 4.2 0.003 30.5 CWE-20 Long Term Support Channel Update for ChromeOS CWE! 🗺 ATT&CK
P3 CVE-2026-55515 NOUVEAU MEDIUM 5.0 0.003 30.4 composer snipe/snipe-it CWE-639 Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
P3 CVE-2026-55873 NOUVEAU MEDIUM 4.3 0.003 26.2 go github.com/seaweedfs/seaweedfs CWE-863 SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets 🗺 ATT&CK
P3 CVE-2026-55227 NOUVEAU MEDIUM 4.3 0.002 26.0 pip weblate CWE-203 Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
P3 CVE-2026-55785 NOUVEAU LOW 3.7 0.000 22.2 go github.com/free5gc/ausf CWE-208 free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA 🗺 ATT&CK
P3 CVE-2026-55588 NOUVEAU LOW 2.0 0.003 12.4 go oras.land/oras CWE-400 ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption 🗺 ATT&CK
P3 CVE-2026-55481 NOUVEAU MEDIUM 0.0 0.003 5.4 composer snipe/snipe-it CWE-79 Snipe-IT has CSS Injection via `header_color` Setting CWE! 🗺 ATT&CK
P3 CVE-2026-55407 NOUVEAU MEDIUM 0.0 0.008 0.9 rust buffa CWE-400 Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
P3 CVE-2026-43406 NOUVEAU LOW 0.0 0.005 0.6 Ubuntu LSN-0121-1: Kernel Live Patch Security Notice 🗺 ATT&CK
P3 CVE-2026-31705 NOUVEAU LOW 0.0 0.004 0.5 Ubuntu USN-8661-3: Linux kernel vulnerabilities
P3 CVE-2026-55476 NOUVEAU MEDIUM 0.0 0.003 0.4 composer snipe/snipe-it CWE-862 Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter
P3 CVE-2026-55479 NOUVEAU MEDIUM 0.0 0.003 0.4 composer snipe/snipe-it CWE-863 Snipe-IT has incorrect permission for legacy license checkin API
P3 CVE-2026-43378 NOUVEAU LOW 0.0 0.003 0.4 Ubuntu USN-8661-3: Linux kernel vulnerabilities
P3 CVE-2026-55478 NOUVEAU MEDIUM 0.0 0.003 0.3 composer snipe/snipe-it CWE-639 Snipe-IT has missing object-level authorization in Kits API
P3 CVE-2026-55406 NOUVEAU MEDIUM 0.0 0.002 0.2 rust buffa CWE-200 Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
P3 CVE-2026-47333 NOUVEAU LOW 0.0 0.001 0.1 Ubuntu LSN-0121-1: Kernel Live Patch Security Notice 🗺 ATT&CK
P3 CVE-2026-55891 NOUVEAU LOW 0.0 0.000 0.0 composer privatebin/privatebin CWE-116 PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
P3 GHSA-73p9-6hrp-8qhr MAJ MEDIUM 0.0 0.000 0.0 pip aiir CWE-347 AIIR verification and policy gates could report success without enforcing the control (fail-open)
P3 CVE-2026-65643 NOUVEAU LOW 0.0 0.000 0.0 Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
--
--
Détails
🦠 Exploitation
🌍 Géo/Acteurs
🗺 ATT&CK
📋 Compliance
🎫 Ticket
CVE
--
Priority
--
CVSS / EPSS / Score
--
CVSS Vector
--
CWE
--
Vendor / Product
--
Source(s)
--
Publié
--
Description
--
Score breakdown
--
Références
--
Ransomware
Gang
In-the-Wild
GreyNoise
Exploit-DB
OTX Pulses
PoC public
Supply Chain
URLhaus URLs
PhishTank
IOC Count
Liens d'exploitation
Threat Actor
Pays d'origine
Campagne
Recherche contextuelle
Techniques ATT&CK associées
Tactiques
Liens MITRE
Obligations réglementaires déclenchées
Actions recommandées
Template ticket JIRA / ServiceNow — copier/coller dans votre ITSM
--

L'écosystème

Digimoove ESN Paris — Cyber · Cloud · Automatisation IA · Observabilité NAIvigate Veille & formation IA FactualRisk est une marque de l'écosystème Digimoove