🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-106496 Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsiste... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106497 Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsiste... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105268 The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belon... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105267 The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, but shares its handler with re... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104633 When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginat... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-101023 Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token w... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106586 In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different ... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106582 In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossin... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106555 In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts. | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106553 In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt. | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106585 In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106584 In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slight... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106550 Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution pr... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106552 In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106491 Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper in... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106494 Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106493 Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object p... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106492 Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by impr... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106486 Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106463 Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected... | MEDIUM | ????? | ????? | NVD | 1 day ago |