Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-70414 — Dell Command | Configure Plaintext Storage of Password Vulnerability

Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabi…

| Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.6 HIGH
CVE-2026-63697 — Dell System Update Improper Certificate Validation Vulnerability

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, l…

system_update | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-56952 — Android Platform Message Handler Privilege Escalation

In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution…

android | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-56936 — Wacom HID Driver Out-of-Bounds Write Vulnerability

In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution pr…

android | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.0 HIGH
CVE-2026-56906 — Linux Kernel Eventpoll Use-After-Free Vulnerability

In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

android | Race Condition
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-55330 — Bluetooth Use-After-Free Vulnerability

In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution priv…

android | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.4 MEDIUM
CVE-2026-55307 — KDN Hardware Cryptography Driver Information Disclosure

In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privilege…

android | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.9 MEDIUM
CVE-2026-106513 — MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Confi…

MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to …

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.4 HIGH
CVE-2026-106512 — MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Unsanitized F…

The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value withou…

sachertortephp_\(cakephp-based_misp_application\) | Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-106511 — CVE-2026-106511

MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent aut…

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.8 HIGH
CVE-2026-106443 — WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image refer…

weasyprint | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-106442 — Hydra instantiate target blacklist bypasses permit code execution

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the ef…

| Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-106441 — Hydra logging configuration permits unsafe callable resolution

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's t…

| Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-106440 — Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_met…

Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.s…

| Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106439 — Hydra: Mutable instantiate policy sets allow target blocklist bypass

Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections…

| Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-106427 — Google Chrome iOS Confused Deputy Vulnerability

Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium se…

chrome chrome | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-106426 — Google Chrome Fonts Race Condition Vulnerability

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severit…

chrome chrome | Race Condition
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-106425 — Google Chrome BrowserTag Authorization Bypass

Missing authorization in BrowserTag in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolatio…

chrome chrome | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-106424 — Google Chrome Audio Information Disclosure

Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension.…

chrome chrome | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.8 HIGH
CVE-2026-106423 — Google Chrome Media Use-After-Free Vulnerability

Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 15384 Results