Common Vulnerabilities and Exposures (CVE)

CVE-2026-87910

Oct 2, 2026 00:35:07 UTC

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the locatio...

CVE-2026-56256

Oct 2, 2026 00:25:05 UTC

Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the backen...

CVE-2026-103098

Oct 2, 2026 00:15:17 UTC

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor networ...

CVE-2026-103097

Oct 2, 2026 00:14:46 UTC

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and m...

CVE-2026-103096

Oct 2, 2026 00:14:08 UTC

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misu...

CVE-2026-93463

Oct 2, 2026 00:04:22 UTC

A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

CVE-2026-16529

Oct 1, 2026 23:23:06 UTC

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for...

CVE-2026-16527

Oct 1, 2026 23:22:57 UTC

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVE-2026-16526

Oct 1, 2026 23:22:50 UTC

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

CVE-2026-16524

Oct 1, 2026 23:22:29 UTC

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

CVE-2026-103765

Oct 1, 2026 23:19:58 UTC

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can po...

CVE-2026-103764

Oct 1, 2026 23:19:57 UTC

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can se...

CVE-2026-15816

Oct 1, 2026 23:16:34 UTC

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_P...

CVE-2026-6893

Oct 1, 2026 23:16:13 UTC

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's...

CVE-2026-85887

Oct 1, 2026 23:01:22 UTC

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.