s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

Threats

8008 threats catalogued · filter, sort and triage below.

All Threats · 8008 TOTAL
Reset
ID Title Severity Category RefsRemediations Published Source updated APEX Update Time
CVE-2026-18897 UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow high cve 0 0
CVE-2026-18895 UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow high cve 0 0
CVE-2026-46334 OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning high cve 0 0
TF-1868565 Unknown malware: ip:port combination that delivery a malware payload 46.226.162.241:80 high Unknown malware 2 0
CVE-2026-45809 OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI high cve 0 0
CVE-2026-45537 OpenSIPS: Global Buffer Overflow in construct_uri critical cve 0 0
CVE-2026-45103 OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow high cve 0 0
CVE-2026-45100 OpenSIPS: Buffer Overflow in Base64 Encode Transformation critical cve 0 0
CVE-2026-45084 OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state high cve 0 0
CVE-2026-70619 Odysseus Missing Admin Authorization via Embedding Endpoint Routes high cve 0 0
CVE-2026-18814 H3C NX15 esps reload.reload_config command injection high cve 0 0
CVE-2026-18813 H3C NX15 esps delete command injection high cve 0 0
CVE-2026-70494 Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder high cve 0 0
CVE-2026-13227 ERPNext v16.25.0 - Improper authorization in Prospect opportunities API high cve 0 0
CVE-2026-70492 Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages high cve 0 0
CVE-2026-45538 OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy critical cve 0 0
CVE-2026-18812 H3C NX15 esps esps.ipv6.wan command injection high cve 0 0
CVE-2026-18811 H3C NX15 esps add command injection high cve 0 0
CVE-2026-65986 CVAT has stored XSS via annotation guide assets high cve 0 0
CVE-2026-70554 MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie critical cve 0 0
CVE-2026-70486 Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin high cve 0 0
CVE-2026-47682 CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes high cve 0 0
CVE-2026-70485 Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs high cve 0 0
CVE-2026-70482 Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client high cve 0 0
CVE-2026-16793 Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator high cve 0 0
CVE-2026-16792 Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator high cve 0 0
CVE-2026-70479 Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader high cve 0 0
CVE-2026-18657 Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows high cve 0 0
CVE-2026-70553 MaxSite CMS Unauthenticated RCE via Install Endpoint critical cve 0 0
CVE-2026-70478 Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service critical cve 0 0
CVE-2026-18656 Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows high cve 0 0
CVE-2026-70477 Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability critical cve 0 0
CVE-2026-70552 MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php critical cve 0 0
CVE-2026-70476 Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation high cve 0 0
CVE-2026-70475 Flowise: Missing Authorization on Execution Update Endpoint high cve 0 0
CVE-2026-49435 Keysight IxChariot-related products stack-based buffer overflow critical cve 0 0
CVE-2026-69704 Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() high cve 0 0
CVE-2026-47781 pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing high cve 0 0
CVE-2026-69703 Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit critical cve 0 0
CVE-2026-13229 Zammad 7.0.1 - Improper authorization in ticket article attachment cloning high cve 0 0
CVE-2026-70474 Flowise: Cross-Workspace OAuth2 Credential Metadata Leak high cve 0 0
CVE-2026-47764 pdm: Path traversal in wheel installation via overridden write_to_fs high cve 0 0
CVE-2026-70473 Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history high cve 0 0
CVE-2026-70472 Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store high cve 0 0
CVE-2026-69702 SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM high cve 0 0
CVE-2026-70471 Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure high cve 0 0
CVE-2026-18830 Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API high cve 0 0
CVE-2026-47623 CVE-2026-47623 high cve 0 0
CVE-2026-47618 CVE-2026-47618 high cve 0 0
CVE-2026-47617 CVE-2026-47617 high cve 0 0
Showing 1–50 of 8008 threats (page 1 of 161).