Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.2 MEDIUM
CVE-2026-108583 — zotero-mcp 0.10.0 through 0.14.1 SSRF via zotero_add_by_url Tool

zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destinatio…

Remote | Server-Side Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.8 MEDIUM
CVE-2026-108582 — GenOffice through 0.11.505 Insecure Permissions in HTTP MCP Server File Store

GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers c…

| Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-108581 — Octop through 1.0.2b6 Missing Authorization Exposes Provider API Keys via /api/providers

TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/v…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-108580 — AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords wi…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.2 MEDIUM
CVE-2026-108579 — OpenPanel through 2.3.0 CSV Formula Injection via Cohort Member Export

OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Att…

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.2 MEDIUM
CVE-2026-108555 — PairDrop through 1.11.2 IP Spoofing via cf-connecting-ip Header

PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attack…

Remote | Misconfiguration
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-108554 — PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input

PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The tra…

Remote | Server-Side Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.7 HIGH
CVE-2026-108553 — OpenRefine through 3.10.1 CSRF to RCE via get-rows Command

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a …

openrefine | Remote | Cross-Site Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-108551 — openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated…

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.8 HIGH
CVE-2026-108550 — SkillHub before 0.2.22 Account Takeover via Account Merge Flow

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing t…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.2 CRITICAL
CVE-2026-108549 — cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is…

cc-connect | Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.3 HIGH
CVE-2026-108548 — AstronRPA through 1.1.6 Authentication Bypass via Arbitrary Bearer Token

AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can sen…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-108547 — AstronRPA through 1.1.6 Cross-Tenant Shared Variable Disclosure via get-batch-shared-var

AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. A…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.7 HIGH
CVE-2026-108546 — Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attacker…

spotweb | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.2 HIGH
CVE-2026-108545 — SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing

SillyTavern 1.12.13 through 1.19.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust resources because body-parser middleware runs before authenticati…

sillytavern | Remote | Denial of Service
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.9 MEDIUM
CVE-2026-108115 — Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses

Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that emb…

suna | Remote | Server-Side Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108114 — Strapi 5.47.0 through 5.57.0 Improper Authorization via Admin API Token Field Permissions

Strapi 5.47.0 through 5.57.0 contains an improper authorization vulnerability that allows admin API tokens to retain all-field Content Manager access after the owner's role is field-restricted. Becau…

strapi | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-97264 — WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Reflected XSS.This issue affects WPAdverts: from n/a th…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-97263 — WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Stored XSS.This issue affects WPAdverts: from n/a throu…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-94676 — WordPress Tainacan plugin <= 1.3.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14096 Results