Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-28350: lxml_html_clean: <base> tag injection through default Cleaner configuration
lxml-html-clean default Cleaner fails to sanitize base tags, causing HTML injection that hijacks relative URLs for phishing, credential theft, and stored XSS.
Analysis:
Available
6.1
medium
3/5/2026
CVE-2026-28348: lxml_html_clean: CSS @import Filter Bypass via Unicode Escapes
lxml-html-clean CSS filter bypass from improper backslash stripping of Unicode escapes in style tags grants attackers external CSS loading and potential XSS.
Analysis:
Available
6.1
medium
3/5/2026
CVE-2026-29054: Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
Traefik auth bypass via lowercase Connection header tokens deletes trusted X-Forwarded headers, causing downstream access control bypass and IP spoofing.
Analysis:
Available
7.5
high
3/5/2026
CVE-2026-29053: Ghost Vulnerable to Remote Code Execution via Malicious Themes
Ghost RCE via malicious theme uploads grants attackers arbitrary code execution within the Node.js process through insecure Handlebars template rendering.
Analysis:
Available
7.6
high
3/5/2026