🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-106489 Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106488 Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is aff... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106487 Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsup... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106459 Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106458 Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106457 Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-pro... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106461 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorre... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106460 Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not cons... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106456 Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inc... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106455 Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is af... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106062 A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width,... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104046 A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP) authentication is enabled, pre-authentication requests retain... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104045 A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchrono... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-101258 A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrar... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-41510 R ## Root Cause
File: `internal/corazawaf/transaction.go`, lines 770–808 (since commit 2fd87b89, PR #812, 2023-06-14)
```go
func (tx *Transaction) A... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-41508 R ## Root Cause
File: `internal/bodyprocessors/multipart.go` (since commit `3347961b`, PR #1453 *"feat: ignore unexpected EOF in MIME multipart re... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-41504 R ## Root Cause
File: `internal/auditlog/formats.go` — multiple sites write attacker-influenced bytes into the Native audit-log stream without escapi... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106032 Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105812 Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authent... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-96589 When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can r... | MEDIUM | ????? | ????? | NVD | 1 day ago |