Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-104054 — calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking auth…

A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine.…

cal.diy | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-103098 — GV-Eye Sensitive information exposure in URL query parameter Vulnerability

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An at…

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-103097 — GV-Eye Relay Payment API Key Vulnerability

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may …

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-103096 — GV-Eye Hardcoded API Key Vulnerability

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may all…

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-104053 — itsourcecode Pet Shop Management System admin_reservefilter.php sql injection

A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filte…

Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.9 MEDIUM
CVE-2026-21140 — ManagedProvisioning Improper Access Control Vulnerability

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-104052 — itsourcecode Pet Shop Management System admin_reject_completed.php sql injection

A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID…

Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.4 CRITICAL
CVE-2026-104480 — Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membe…

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice …

| Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.0 CRITICAL
CVE-2026-86345 — 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to …

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP…

Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.6 HIGH
CVE-2026-103766 — ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter

ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_man…

clipbucket | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.4 CRITICAL
CVE-2026-103765 — Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transf…

mooncake | Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-103764 — Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TC…

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the …

mooncake | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-103761 — Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue

Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without li…

mooncake | Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.2 HIGH
CVE-2026-103760 — Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon …

Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers…

mooncake | Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2025-71427 — Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manag…

Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ seq…

Remote
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-86344 — 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-ope…

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the ser…

Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.8 MEDIUM
CVE-2026-71454 — CAPEC-63 Cross-Site Scripting Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAP…

capec-63 | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.6 MEDIUM
CVE-2026-71453 — Johnson Controls EasyIO FS32 Path Traversal Vulnerability

- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.

easyio_fs32 | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.4 HIGH
CVE-2026-71452 — Johnson Controls EasyIO FS32 OS Command Injection

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.

easyio_fs32 | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
10.0 CRITICAL
CVE-2026-71449 — Johnson Controls EasyIO FS32 Hard-coded Cryptographic Key Vulnerability

: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.

easyio_fs32 | Remote | Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14871 Results