Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-101029 — Gitea migration and pull mirror SSRF through multi-answer DNS

Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address …

| Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-101027 — Gitea migration SSRF through ALLOWED_DOMAINS address check bypass

When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start …

| Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-104626 — Gitea fork workflow job revival through later approval

A user who can open a fork pull request can place workflow content with a shared run-level concurrency group into a Gitea Actions run that is awaiting approval. When a later run in that group cancels…

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-103059 — Gitea built-in SSH server authentication bypass through key case folding

When Gitea's built-in SSH server is enabled (`START_SSH_SERVER = true`), the presented public key was looked up with an SQL `LIKE` comparison of its encoded content, which is case-insensitive on some…

| Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-104632 — Gitea fork workflow approval bypass through cancel and rerun

Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new …

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-9226 — Devolutions Server Azure AD Authentication Bypass

Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session to…

devolutions_server | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.7 HIGH
CVE-2026-96890 — Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that…

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled int…

enterprise_server | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.2 HIGH
CVE-2026-86362 — Dell System Update Improper Access Control Vulnerability

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …

system_update | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.2 HIGH
CVE-2026-86361 — Dell System Update Incorrect Permission Assignment Elevation of Privilege Vulnerability

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit t…

system_update | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.6 CRITICAL
CVE-2026-86360 — Dell System Update Path Traversal Vulnerability

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access…

system_update | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.1 HIGH
CVE-2026-83550 — Postgres-exporter: net/http/pprof exposed on metrics listener

A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network c…

| Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.4 HIGH
CVE-2026-82162 — Dell Command | Configure Improper Handling of Mixed Encoding Vulnerability

Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this…

Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.3 HIGH
CVE-2026-71168 — Dell System Update Path Traversal Vulnerability

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access co…

system_update | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.5 MEDIUM
CVE-2026-70414 — Dell Command | Configure Plaintext Storage of Password Vulnerability

Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabi…

| Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.6 HIGH
CVE-2026-63697 — Dell System Update Improper Certificate Validation Vulnerability

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, l…

system_update | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.7 MEDIUM
CVE-2026-56952 — Android Platform Message Handler Privilege Escalation

In platform_msg_handler_init of default_msg_handlers.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution…

android | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-56936 — Wacom HID Driver Out-of-Bounds Write Vulnerability

In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution pr…

android | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.0 HIGH
CVE-2026-56906 — Linux Kernel Eventpoll Use-After-Free Vulnerability

In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

android | Race Condition
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-55330 — Bluetooth Use-After-Free Vulnerability

In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution priv…

android | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.4 MEDIUM
CVE-2026-55307 — KDN Hardware Cryptography Driver Information Disclosure

In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privilege…

android | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 15337 Results