🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-76744 Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to ex... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76743 A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumven... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76742 Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote at... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76741 Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to caus... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-76061 A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local at... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-73278 Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second fa... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-70357 Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently re... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106452 yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen fiel... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106450 yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buf... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106454 Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegexp() in twisted/mail/imap4... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106453 yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decomp... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106449 yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false ... | LOW | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106446 Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile... | CRITICAL | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106444 Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-106063 A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export pat... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105244 Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net.
Every character outside visible ASCII and space ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105243 Insufficient Logging vulnerability in the EventLogAppender of Apache log4net.
Long messages were truncated to a fixed size that exceeds what the Wind... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-105242 Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net.
Reading request parameters trigg... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104636 Gitea validated the initial remote URL for push mirrors, wiki remote checks, and fetches of migrated pull request heads, but the subsequent raw Git op... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-104632 Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only... | HIGH | ????? | ????? | NVD | 1 day ago |