Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-104907 — MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler

MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline…

misp | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.2 MEDIUM
CVE-2026-104906 — MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output

MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pr…

misp | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.1 MEDIUM
CVE-2026-104901 — MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Ser…

MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding…

misp | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-104900 — MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index

MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the fie…

misp | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.5 HIGH
CVE-2026-104847 — ProseMirror: XSS vulnerability in prosemirror-view's paste handling

ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipbo…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-104846 — Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (by…

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node ca…

seroval | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-104845 — Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialize…

seroval | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.9 MEDIUM
CVE-2026-104844 — PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion

PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying…

postcss-selector-parser | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.9 MEDIUM
CVE-2026-104843 — uv: Path traversal on Windows through wheel extraction

uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installatio…

uv | Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.1 CRITICAL
CVE-2026-103648 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-d…

Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103631 — Google Chrome WebRTC Buffer Overflow

Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103630 — Google Chrome FedCM Use-After-Free Vulnerability

Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103629 — Google Chrome Skia Integer Overflow Vulnerability

Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103628 — Google Chrome WebGL Out-of-Bounds Write Vulnerability

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Crit…

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103627 — Google Chrome SVG Information Disclosure

Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

chrome chrome | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103626 — Google Chrome FileSystem Incorrect Authorization Arbitrary Code Execution

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the s…

chrome chrome | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103625 — Google Chrome V8 Type Confusion Vulnerability

Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103624 — Google Chrome Contextual Tasks Use-After-Free Vulnerability

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outsi…

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103623 — Google Chrome MediaStream Use-After-Free Vulnerability

Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-103622 — Google Chrome SVG Use-After-Free Vulnerability

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14935 Results