216.73.216.6

Threat intelligence dashboard

Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.

Attack reports – last 7 days · through Sunday 28 June 2026 (35)

Vulnerabilities today (36)

Sorted by CVSS severity (highest first)

9.9 Critical

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
8.7 High

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen < pktinfo_len) before …

Attack vector
LOCAL
Complexity
LOW
Published
28/06/2026
8.6 High

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
8.1 High

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.6 High

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.4 High

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous …

Attack vector
NETWORK
Complexity
HIGH
Published
28/06/2026
7.3 High

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.3 High

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.3 High

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.3 High

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.3 High

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.3 High

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.2 High

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user …

Attack vector
NETWORK
Complexity
LOW
Published
28/06/2026
7.0 High

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) …

Attack vector
NETWORK
Complexity
HIGH
Published
28/06/2026
6.5 Medium

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes …

Attack vector
ADJACENT_NETWORK
Complexity
LOW
Published
28/06/2026