🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-86684 The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[s... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-65142 NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerabil... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-65122 NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to den... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-96594 The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-89182 With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106588 In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected. | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106587 In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean ... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106589 In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This ... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106509 Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper va... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106508 Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential f... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106507 Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs ar... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106505 Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106506 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by imprope... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106504 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensiti... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106502 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106503 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend packag... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106500 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend packag... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106501 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend packag... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106499 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-de... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106498 Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend pa... | HIGH | ????? | ????? | NVD | 1 day ago |