🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-107271 Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwa... | MEDIUM | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-107270 Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' group... | HIGH | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-107278 MISP contains a validation flaw in its object synchronization logic. When a MISP Object is created without a description, it is stored correctly on th... | MEDIUM | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-107269 Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usern... | MEDIUM | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-107276 MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted... | MEDIUM | ????? | ????? | NVD | 12 hours ago |
| CVE-2026-107207 LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107206 LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attacker... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107205 LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess coordinator that allows remote unauthenticated attackers to ... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107204 LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting s... | CRITICAL | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-62179 PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-46570 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memo... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107202 A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configura... | CRITICAL | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107174 A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107169 A flaw was found in m17n-lib. An attacker could provide specially crafted or truncated UTF-8 input to trigger an unhandled null pointer dereference du... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-107167 A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state tran... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106559 Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106563 Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improp... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106562 Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-searc... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106561 Backstage is an open framework for building developer portals. Prior to 0.21.9, the @backstage/plugin-kubernetes-backend package is affected by sensit... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106560 Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown... | HIGH | ????? | ????? | NVD | 13 hours ago |