Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-104077 — Obsidian Desktop < 1.14.0 RCE via Slides Plugin Markdown

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-ifram…

| Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-107302 — msgpack5: Truncated map32 headers throw an unexpected error

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is av…

Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-95208 — wolfSSL Certificate Authority Validation Denial of Service

An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority ce…

| Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-19585 — Go-getter vulnerable to a path traversal in S3/GCS directory download handling

HashiCorp go-getter versions before 1.8.10 and go-getter/v2 versions before 2.2.5 are vulnerable to path traversal during S3 and GCS directory downloads, which may allow files to be written outside t…

go-getter | Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.7 MEDIUM
CVE-2026-107678 — FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes

FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the…

ffmpeg | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.7 MEDIUM
CVE-2026-107677 — FFmpeg through 9.0.2 DASH Demuxer Infinite Loop via Empty SegmentTemplate Media

FFmpeg through 9.0.2 contains a denial of service vulnerability in the DASH demuxer that allows attackers to trigger an infinite loop by supplying an empty SegmentTemplate media URL. Attackers can cr…

ffmpeg | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.8 MEDIUM
CVE-2026-107676 — FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer

FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attacke…

ffmpeg | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.0 MEDIUM
CVE-2026-107675 — FFmpeg through 9.0.2 Missing SSH Host Key Verification in sftp Protocol

FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing m…

ffmpeg | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.3 MEDIUM
CVE-2026-107660 — FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts

FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper certificate validation vulnerability in tls_open() of libavformat/tls_mbedtls.c, which skips hostname checks for IP-address hosts. Networ…

ffmpeg | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-107289 — Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifier (incomplete fi…

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local net…

pydantic_ai | Remote | Server-Side Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
3.7 LOW
CVE-2026-107288 — Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes…

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback comp…

pydantic_ai | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107287 — Pydantic AI: Excessive resource use when local web fetching converts nested HTML

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can …

pydantic_ai | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.4 MEDIUM
CVE-2026-106177 — HP Sure Click Kernel Buffer Overflow

A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulne…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.8 CRITICAL
CVE-2026-9209 — mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx

mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod…

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-95125 — Libming Heap Buffer Overflow

libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can cause a denial of service.

| Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-93034 — CVE-2026-93034

SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without typ…

sglang | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.7 HIGH
CVE-2026-93017 — Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy an…

The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to eve…

openshift_container_platform | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.4 HIGH
CVE-2026-14999 — IBM DataPower Gateway Improper Verification of Cryptographic Signature

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to bypass authentication by forging va…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.8 CRITICAL
CVE-2026-14992 — IBM DataPower Gateway Out-of-bounds Write

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-14988 — IBM DataPower Gateway Out-of-bounds Read

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to buffer overflow.

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15590 Results