Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.9 HIGH
CVE-2026-77805 — Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Class…

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before ex…

| Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.6 MEDIUM
CVE-2026-77804 — Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Pro…

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root c…

| Race Condition
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.6 LOW
CVE-2026-77803 — Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that conta…

| Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.3 MEDIUM
CVE-2026-77802 — HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Cont…

| Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.8 MEDIUM
CVE-2026-105315 — django-haystack more_like_this Template Tag elasticsearch_backend.py _to_python eval inje…

A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag …

django-haystack | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
10.0 CRITICAL
CVE-2026-92931 — CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an at…

Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.5 HIGH
CVE-2026-63277 — RCE via calcext:data-mappings, sql provider and jdbc connector

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote locat…

libreoffice | Supply Chain
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.7 MEDIUM
CVE-2026-63270 — Environment/ini-file leaks

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such li…

libreoffice | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.7 MEDIUM
CVE-2026-63269 — LFI and GET SSRF via GStreamer and HLS playlists

LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and rem…

libreoffice | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.7 MEDIUM
CVE-2026-63268 — LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a do…

libreoffice | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.7 MEDIUM
CVE-2026-63267 — LFI and GET SSRF via calcext:data-mappings and csv provider

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a loc…

libreoffice | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.8 MEDIUM
CVE-2026-63266 — Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup function…

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to …

libreoffice | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-39783 — WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability

Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-105396 — Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host heade…

Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105307 — Casdoor API Endpoint authz_filter.go ApiFilter missing authentication

A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missi…

casdoor | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-105073 — WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP…

Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-103684 — WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability

Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from…

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-94669 — WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Broken Access Control vulnerabi…

Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent …

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.7 MEDIUM
CVE-2026-59788 — Stored XSS vulnerability in OAuth configuration form

The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media…

zabbix | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-59787 — SNMP trap injection in zabbix_trap_receiver.pl

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record target…

zabbix | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14279 Results