Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-40486: Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate
Kimai User Preferences API auth bypass grants users unauthorized modification of hourly_rate and internal_rate via a PATCH request, causing financial tampering.
Analysis:
Available
4.3
medium
4/17/2026
CVE-2026-40353: wger: Stored XSS via Unescaped License Attribution Fields
wger stored XSS in Ingredient license attribution fields executes arbitrary scripts for visitors, enabling session hijacking via unescaped HTML generation.
Analysis:
Available
5.1
medium
4/17/2026
CVE-2026-40265: Note Mark has Broken Access Control on Asset Download
Note Mark auth bypass on the asset download API discloses private note assets via direct requests using known note and asset UUIDs to an unprotected route.
Analysis:
Available
5.9
medium
4/17/2026
CVE-2026-40263: Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
Note Mark login endpoint timing side-channel leaks account existence, enabling unauthenticated username enumeration by measuring bcrypt verification latency.
Analysis:
Available
3.7
low
4/17/2026