Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-107216 — Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entr…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calcu…

| Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-107215 — Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-ent…

| Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-56851 — Panic parsing crafted input in x/text/secure/precis in golang.org/x/text

The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.

| Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-107214 — Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before …

| Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-107213 — Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but n…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the ind…

| Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.3 MEDIUM
CVE-2026-106067 — Gimp: gimp: heap buffer overflow in hot color filter on oversized image

A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while th…

enterprise_linux enterprise_linux | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.3 MEDIUM
CVE-2026-106066 — Gimp: gimp: heap buffer overflow in raw data export on oversized image dimensions

A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far le…

enterprise_linux enterprise_linux | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107212 — Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop f…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit e…

Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-95606 — WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-95605 — WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Dat…

wp_data_access | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-95595 — WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2.0.2 - Cross…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts a…

disable_and_remove_google_fonts_gdpr_dsgvo_friendly | Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-95534 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Element…

unlimited_elements_for_elementor | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-94670 — WordPress Everest Forms plugin <= 3.6.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1.

Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-94662 — WordPress Unlimited Elements For Elementor plugin <= 2.0.19 - Cross Site Scripting (XSS) …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stor…

unlimited_elements_for_elementor | Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-92543 — Docker Engine insecure-registry fallback via malicious DNS responses

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all …

moby engine | Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.9 MEDIUM
CVE-2026-92542 — Blind VXLAN injection into encrypted overlay networks from cluster peer

The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent fr…

engine | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76501 — Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability

A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attack…

nx-os | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76500 — Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Impr…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal …

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76499 — Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Impr…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal …

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.8 CRITICAL
CVE-2026-76498 — Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Impr…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal …

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15475 Results