Threat Intelligence Feed

Aggregating 9349 articles from trusted cybersecurity sources

LATEST CVEs
MED · CVE-2026-89182 With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still app HIGH · CVE-2026-86684 The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file syste HIGH · CVE-2026-65142 NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A success MED · CVE-2026-65122 NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this CVE-2026-106589 In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpected CVE-2026-106588 In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is CVE-2026-106587 In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but w HIGH · CVE-2026-106509 Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node pack MED · CVE-2026-106508 Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node pack MED · CVE-2026-106507 Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node pack MED · CVE-2026-106506 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend HIGH · CVE-2026-106505 Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdoc MED · CVE-2026-106504 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend HIGH · CVE-2026-106503 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/pl MED · CVE-2026-106502 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend CRIT · CVE-2026-106501 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/pl HIGH · CVE-2026-106500 Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/pl MED · CVE-2026-106499 Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend HIGH · CVE-2026-106498 Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backs MED · CVE-2026-106497 Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend pac CVE-2026-106496 Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend pac MED · CVE-2026-105268 The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also a HIGH · CVE-2026-105267 The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, MED · CVE-2026-104633 When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API se CRIT · CVE-2026-101023 Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, CVE-2026-43598 Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank o CVE-2026-19029 A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets an attacke CVE-2026-106586 In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar MED · CVE-2026-106585 In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decom CVE-2026-106584 In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mish CVE-2026-106582 In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the CVE-2026-106555 In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentica CVE-2026-106553 In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authenticati MED · CVE-2026-106552 In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended loca HIGH · CVE-2026-106550 Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete CVE-2026-106547 A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an app MED · CVE-2026-106494 Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package CVE-2026-106493 Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not HIGH · CVE-2026-106492 Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaul MED · CVE-2026-106491 Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend pack
6520 general 1093 advisories 750 research 665 vendor 321 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.