Daily digest · in progress
Friday 9 October 2026
No new CVEs landed this day so far. 8 existing records changed (re-scores, KEV additions, exploit evidence).
0
New CVEs
0
Critical
0
KEV additions
8
Records changed
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL pathsseverity, cvss37
- CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methodsexploit_available45
- CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.cvss42
- CVE-2025-70517The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applicationsseverity, cvss48
- CVE-2025-70522The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applicationsseverity, cvss48
- CVE-2026-106261Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML pageseverity, cvss36
- CVE-2026-106289Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML pageseverity, cvss36
- CVE-2026-106353Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed appcvss36