Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-50018: Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
Hoverfly remote post-serve actions trigger a DoS via goroutine leak from untimed HTTP clients, causing unbounded memory growth and eventual process crash.
Analysis:
Available
6.5
medium
9/11/2026
CVE-2026-50013: Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
Hoverfly Diff mode race condition triggers unrecoverable process termination via concurrent unsynchronized map writes from simultaneous proxy requests.
Analysis:
Available
7.5
high
9/11/2026
CVE-2026-49992: Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
Kimai CSRF in team creation GET endpoints grants attackers unauthorized modification of team structures, teamleads, and project/customer/activity bindings.
Analysis:
Available
6.3
medium
9/11/2026
CVE-2026-48496: opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
opentelemetry-ebpf-profiler DoS occurs when an unprivileged process blocks the processPIDEvents goroutine in an openat2 syscall, halting ELF file analysis.
Analysis:
Available
6.2
medium
9/11/2026