Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-54179: backpack/crud: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk
Laravel Backpack CRUD's SingleBase64Image uploader executes stored XSS by writing malicious base64 SVG payloads from authenticated admins to public disks.
Analysis:
Available
4.4
medium
8/31/2026
CVE-2026-53552: Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
Goploy project handler IDOR grants managers RCE via a cross-namespace attack, rewriting git remote URLs through a malicious JSON body to execute arbitrary code.
Analysis:
Available
9.6
critical
8/31/2026
CVE-2026-53508: oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
oasdiff SSRF and LFI via malicious $ref in specs on the git-revision path bypasses external reference controls, granting local file reads and network access.
Analysis:
Available
6
medium
8/31/2026
CVE-2026-45694: LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters
LibreNMS Proxmox app reflected XSS via unsanitized 'instance' GET parameter injection into document.title executes arbitrary script, stealing session cookies.
Analysis:
Available
5.4
medium
8/26/2026