Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-107726 — Hazelcast: Arbitrary member memory access by low-privileged client

Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able t…

| Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-107725 — Hazelcast: Authorization bypass in IMap Predicates API

Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a m…

| Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.4 HIGH
CVE-2026-107724 — fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgori…

fast-jwt | Remote | Cryptography
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.3 MEDIUM
CVE-2026-107831 — Jivejdon through 5.0 CSRF via GET-based Account and Thread Actions

Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers ca…

Remote | Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107830 — Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpo…

Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can lo…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107829 — Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql

Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table th…

Remote | Cryptography
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107828 — Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login

Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user …

Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107801 — Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. At…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107800 — Jivejdon through 5.0 Stored XSS via Private Short Messages

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfi…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107799 — Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107798 — Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Fil…

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attri…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-107797 — Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters

Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can …

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-107796 — Jivejdon through commit ee67a65e Reflected XSS via taggedThreadList.jsp tagID and count P…

Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.3 MEDIUM
CVE-2026-107793 — Jivejdon through 5.0 IDOR via subSaveAction Subscription Delete

Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers …

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.3 MEDIUM
CVE-2026-107792 — Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Th…

Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attacke…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.9 MEDIUM
CVE-2025-71428 — Jivejdon through 5.0 SQL Injection via username in userListAction

Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with t…

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.1 HIGH
CVE-2026-107723 — fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the p…

fast-jwt | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.8 CRITICAL
CVE-2026-107722 — fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS…

fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its P…

fast-jwt | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.8 HIGH
CVE-2026-89091 — Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows …

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107721 — fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and pers…

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but no…

fast-jwt | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 14435 Results