CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-105268
4.3 MEDIUM

The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of an issue may …

Oct 6, 2026
CVE-2026-104633
6.5 MEDIUM

When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. …

Oct 6, 2026
CVE-2026-106585
6.5 MEDIUM

In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed …

Oct 6, 2026
CVE-2026-106552
4.2 MEDIUM

In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.

Oct 6, 2026
CVE-2026-106494
4.4 MEDIUM

Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url …

Oct 6, 2026
CVE-2026-106491
6.4 MEDIUM

Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated …

Oct 6, 2026
CVE-2026-106490
6.5 MEDIUM

Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content …

Oct 6, 2026
CVE-2026-106489
6.5 MEDIUM

Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. …

Oct 6, 2026
CVE-2026-106463
5.4 MEDIUM

Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organizational user ingestion. …

Oct 6, 2026
CVE-2026-106462
6.4 MEDIUM

Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user …

Oct 6, 2026
CVE-2026-106461
4.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An …

Oct 6, 2026
CVE-2026-106460
6.8 MEDIUM

Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not consistently honor explicit negative email …

Oct 6, 2026
CVE-2026-106458
6.5 MEDIUM

Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server …

Oct 6, 2026
CVE-2026-106457
6.8 MEDIUM

Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare …

Oct 6, 2026
CVE-2026-106456
4.8 MEDIUM

Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy …

Oct 6, 2026
CVE-2026-106032
5.7 MEDIUM

Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated …

Oct 6, 2026
CVE-2026-105811
6.5 MEDIUM

Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md ), available with QnABot on AWS versions …

Oct 6, 2026
CVE-2026-104046
6.2 MEDIUM

A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP) authentication is enabled, pre-authentication requests retain state in memory without being …

Oct 6, 2026
CVE-2026-104045
4.7 MEDIUM

A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder …

Oct 6, 2026
CVE-2026-96589
4.3 MEDIUM

When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can …

Oct 6, 2026
CVE-2026-96400
4.3 MEDIUM

With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, …

Oct 6, 2026
CVE-2026-94114
5.9 MEDIUM

Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing …

Oct 6, 2026
CVE-2026-79818
5.3 MEDIUM

A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow …

Oct 6, 2026
CVE-2026-79817
5.5 MEDIUM

A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access …

Oct 6, 2026
CVE-2026-79816
6.3 MEDIUM

A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) …

Oct 6, 2026
CVE-2026-79815
6.5 MEDIUM

A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could …

Oct 6, 2026
CVE-2026-79814
6.7 MEDIUM

An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges …

Oct 6, 2026
CVE-2026-79813
6.7 MEDIUM

A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges …

Oct 6, 2026
CVE-2026-79812
6.1 MEDIUM

A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to …

Oct 6, 2026
CVE-2026-76749
6.5 MEDIUM

A sensitive information disclosure vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated remote attacker to access sensitive information.

Oct 6, 2026
CVE-2026-76741
6.5 MEDIUM

Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to cause a denial-of-service condition on the …

Oct 6, 2026
CVE-2026-76061
5.5 MEDIUM

A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime …

Oct 6, 2026
CVE-2026-106454
4.3 MEDIUM

Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegexp() in twisted/mail/imap4.py translates the IMAP asterisk and percent wildcards …

Oct 6, 2026
CVE-2026-106453
5.3 MEDIUM

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, …

Oct 6, 2026
CVE-2026-106452
5.3 MEDIUM

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative …

Oct 6, 2026
CVE-2026-106450
5.3 MEDIUM

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header …

Oct 6, 2026
CVE-2026-106444
4.7 MEDIUM

Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text …

Oct 6, 2026
CVE-2026-106063
6.3 MEDIUM

A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates …

Oct 6, 2026
CVE-2026-105244
5.3 MEDIUM

Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record …

Oct 6, 2026
CVE-2026-105243
5.3 MEDIUM

Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts …

Oct 6, 2026
CVE-2026-105242
5.3 MEDIUM

Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying …

Oct 6, 2026
CVE-2026-105241
5.3 MEDIUM

Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 …

Oct 6, 2026
CVE-2026-105240
5.3 MEDIUM

Improper Neutralization of Null Byte or NUL Character vulnerability in the OutputDebugStringAppender of Apache log4net. A NUL character in logged content ended the debug output …

Oct 6, 2026
CVE-2026-105239
5.3 MEDIUM

Improper Neutralization of Null Byte or NUL Character vulnerability in the EventLogAppender of Apache log4net. A NUL character in logged content ended the Windows Event …

Oct 6, 2026
CVE-2026-105111
4.7 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Commons BCEL. This only happens when you're using Class2HTML to generate webpages …

Oct 6, 2026
CVE-2026-104048
6.8 MEDIUM

A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only …

Oct 6, 2026
CVE-2026-104047
5.3 MEDIUM

A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query …

Oct 6, 2026
CVE-2026-103667
5.4 MEDIUM

Gitea's container registry served blob downloads with a `Content-Type` taken from the media type declared in pushed image manifests, without a `Content-Disposition` or restrictive content …

Oct 6, 2026
CVE-2026-103008
6.5 MEDIUM

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a …

Oct 6, 2026
CVE-2026-103006
6.5 MEDIUM

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.