s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

Threats

721 threats catalogued · filter, sort and triage below.

All Threats · 721 TOTAL
Reset
ID Title Severity Category RefsRemediations Published Source updated APEX Update Time
CVE-2026-82370 Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service high cve 0 0
CVE-2026-89078 Double Free in GitLab critical cve 0 0
CVE-2026-92470 Missing Authorization in GitLab high cve 0 0
CVE-2026-93577 Integer Overflow or Wraparound in GitLab critical cve 0 0
CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability high cve 0 0
TF-1931083 Unknown malware: ip:port combination that is used for botnet Command&control (C&C) 134.122.200.153:8151 high Unknown malware 3 0
CVE-2026-81537 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-81536 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-81208 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-93352 Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload critical cve 0 0
CVE-2026-80423 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-75887 Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler high cve 0 0
TF-1931073 Remcos: ip:port combination that is used for botnet Command&control (C&C) 185.215.151.9:2404 high Remcos 2 0
CVE-2026-80425 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-80412 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-80379 DataStage on Cloud Pak for Data has several vulnerabilities high cve 0 0
CVE-2026-6935 Multiple Vulnerabilities in IBM Concert Software high cve 0 0
CVE-2026-6928 Multiple Vulnerabilities in IBM Concert Software critical cve 0 0
CVE-2026-6794 Multiple Vulnerabilities in IBM Concert Software high cve 0 0
CVE-2026-75886 Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding high cve 0 0
CVE-2026-67231 RabbitMQ: Trust-store whitelist by Issuer+Serial only critical cve 0 0
CVE-2026-6730 Multiple Vulnerabilities in IBM Concert Software critical cve 0 0
CVE-2026-6721 Multiple Vulnerabilities in IBM Concert Software critical cve 0 0
CVE-2026-82369 Insufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1a high cve 0 0
CVE-2026-67232 RabbitMQ: Web-MQTT decompression bomb high cve 0 0
CVE-2026-67235 RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size high cve 0 0
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch critical cve 0 0
CVE-2026-66077 RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI high cve 0 0
CVE-2026-66079 RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS high cve 0 0
CVE-2026-66070 RabbitMQ: CORS * reflects Origin with Allow-Credentials high cve 0 0
CVE-2026-67238 RabbitMQ: Atom-table exhaustion via reply-to queue name decoding high cve 0 0
CVE-2026-87899 CVE-2026-87899 critical cve 0 0
CVE-2026-68492 CVE-2026-68492 high cve 0 0
CVE-2026-68490 CVE-2026-68490 high cve 0 0
CVE-2026-87900 CVE-2026-87900 critical cve 0 0
CVE-2026-87898 CVE-2026-87898 critical cve 0 0
TF-1931048 Tsundere: ip:port combination that is used for botnet Command&control (C&C) 2.26.29.7:443 high Tsundere 2 0
CVE-2026-96889 Librsvg: use-after-free when xml includes have duplicated entities high cve 0 0
CVE-2026-85475 Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote code execution in the control-plane rsyslog component high cve 0 0
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) critical cve 0 0
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment high cve 0 0
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment high cve 0 0
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups critical cve 0 0
CVE-2026-96826 WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability high cve 0 0
CVE-2026-82405 Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller high cve 0 0
CVE-2026-82409 Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery high cve 0 0
CVE-2026-82407 Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS high cve 0 0
CVE-2026-86065 Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) high cve 0 0
CVE-2026-86064 Klever-Go: /log controls global node logging high cve 0 0
CVE-2026-82406 Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace high cve 0 0
Showing 1–50 of 721 threats (page 1 of 15).