Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-29183: SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution
SiYuan unauthenticated Reflected XSS in the getDynamicIcon API via SVG injection executes arbitrary JS for authenticated API abuse and data exfiltration.
Analysis:
Available
9.3
critical
3/6/2026
CVE-2026-29074: SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
SVGO DoS from crafted SVG DOCTYPEs triggers a Billion Laughs attack, causing exponential entity expansion that exhausts memory and crashes the Node.js process.
Analysis:
Available
7.5
high
3/6/2026
CVE-2026-29062: jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
jackson-core DoS in UTF8DataInputJsonParser from deeply nested JSON input bypasses nesting constraints, triggering a StackOverflowError and resource exhaustion.
Analysis:
Available
8.7
high
3/6/2026
CVE-2026-29042: Nuclio Shell Runtime Command Injection Leading to Privilege Escalation
Nuclio Shell Runtime command injection via unsanitized HTTP headers grants root RCE in containers, enabling ServiceAccount token theft for cluster compromise.
Analysis:
Available
8.9
high
3/6/2026