Common Vulnerabilities and Exposures (CVE)

CVE-2026-103870

Oct 7, 2026 05:46:18 UTC

A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task ...

CVE-2026-103869

Oct 7, 2026 05:46:15 UTC

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token ...

CVE-2026-103868

Oct 7, 2026 05:46:12 UTC

A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that rem...

CVE-2026-59347

Oct 7, 2026 05:40:05 UTC

VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX proce...

CVE-2026-59346

Oct 7, 2026 05:40:03 UTC

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. A...

CVE-2026-102173

Oct 7, 2026 05:30:40 UTC

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in ...

CVE-2026-87114

Oct 7, 2026 04:17:08 UTC

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote atta...

CVE-2025-6020

Oct 7, 2026 04:06:35 UTC

A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

CVE-2025-5914

Oct 7, 2026 04:06:34 UTC

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a do...

CVE-2026-19572

Oct 7, 2026 04:04:19 UTC

A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session ...

CVE-2026-106414

Oct 7, 2026 03:56:13 UTC

Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur...

CVE-2026-106329

Oct 7, 2026 03:56:12 UTC

Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security seve...

CVE-2026-106239

Oct 7, 2026 03:56:11 UTC

Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-106426

Oct 7, 2026 03:56:11 UTC

Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-76742

Oct 7, 2026 03:56:10 UTC

Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.