🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-106558 Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package imprope... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106510 Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106556 Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configurati... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-106064 A heap-based buffer overflow was found in GIMP’s GIF export plug-in. Exporting an image with very large width and height can cause 32-bit overflow w... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70521 The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of ... | CRITICAL | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70522 The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request per... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70520 The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lac... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70519 The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sani... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70518 The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of ... | CRITICAL | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70517 The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request per... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70516 The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lac... | CRITICAL | ????? | ????? | NVD | 13 hours ago |
| CVE-2025-70515 The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sani... | UNKNOWN | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-33586 Authenticated users are able to manipulate both the SMTP
envelope “Envelope-from” and “From” fields when sending
emails through OVH mail serve... | MEDIUM | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-77214 libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser... | HIGH | ????? | ????? | NVD | 13 hours ago |
| CVE-2026-104074 Coturn 4.10.0 contains an uninitialized memory disclosure vulnerability that allows remote unauthenticated attackers to leak stack memory contents by ... | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-88514 An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information. | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-46572 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory i... | HIGH | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-46569 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memor... | UNKNOWN | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-46571 In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confi... | MEDIUM | ????? | ????? | NVD | 14 hours ago |
| CVE-2026-45161 wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `dja... | MEDIUM | ????? | ????? | NVD | 14 hours ago |