Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-105167 — kishor-23 food-waste-management-system donate.php sql injection

A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function…

| Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.4 HIGH
CVE-2026-105222 — alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_ver…

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_V…

Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.4 HIGH
CVE-2026-105221 — Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NON…

Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.8 HIGH
CVE-2026-105220 — Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file w…

| Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-105166 — kishor-23 food-waste-management-system Food Donation Form fooddonateform.php insert sql i…

A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of t…

Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.1 MEDIUM
CVE-2026-105164 — NASA cFS cfe_fs_api.c CFE_FS_ParseInputFileNameEx out-of-bounds

A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read…

cfs | Remote | Memory Corruption
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.9 MEDIUM
CVE-2026-105163 — crossplane crossplane-runtime ImageConfig client.go Get toctou

A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulat…

crossplane-runtime | Remote | Race Condition
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-105165 — devopspolis secrets-replicator AssumeRole handler.py process_single_secret permission ass…

A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manip…

secrets-replicator | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.7 HIGH
CVE-2026-105219 — Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attack…

Remote | Denial of Service
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.1 CRITICAL
CVE-2026-105218 — gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present …

Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
3.1 LOW
CVE-2026-105217 — Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers …

cockpit | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.1 CRITICAL
CVE-2026-105216 — go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by …

micro-ecc | Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.9 MEDIUM
CVE-2026-105161 — invariant-systems-ai aiir Policy Gate signature verification

A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verific…

aiir | Remote | Cryptography
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.4 MEDIUM
CVE-2026-105224 — YesWiki before 4.6.7 Stored XSS via Bazar valeur Action

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attacker…

yeswiki | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105089 — WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rende…

avideo | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105086 — WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because …

avideo | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
4.3 MEDIUM
CVE-2026-104402 — WordPress Mindio Magic MCP plugin <= 0.5.6 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a thr…

Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105215 — ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external …

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
2.3 LOW
CVE-2026-105214 — Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The chall…

zitadel | Remote | Server-Side Request Forgery
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-105213 — ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold val…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
Showing 20 of 14242 Results