VulnSea

Daily digest · in progress

Friday 9 October 2026

No new CVEs landed this day so far. 8 existing records changed (re-scores, KEV additions, exploit evidence).

0
New CVEs
0
Critical
0
KEV additions
8
Records changed

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2025-70517The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications48
  • CVE-2025-70522The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications48
  • CVE-2026-106261Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page36
  • CVE-2026-106289Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page36
  • CVE-2026-106353Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app36