Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-103530 — decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manip…

Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-103592 — simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist …

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-103591 — DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_ur…

Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103590 — QloApps through 1.7.0 Reflected XSS via Length of Stay Fields

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit …

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103589 — QloApps through 1.7.0 Reflected XSS via Room Type Editor

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. A…

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103588 — QloApps through 1.7.0 Reflected XSS via exceptions field

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing Java…

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103587 — QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into te…

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.2 LOW
CVE-2026-103585 — attacker-controlled javascript license URL via XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue …

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103584 — attacker-controlled javascript license URL via XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This is…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.1 MEDIUM
CVE-2026-47096 — AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter

AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanit…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-103001 — PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification byp…

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signat…

Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.2 CRITICAL
CVE-2026-101283 — iperf3 Heap Buffer Overflow

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an…

Remote | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-92173 — Meta Horizon OS Improper Privilege Management Vulnerability

Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listen…

| Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-92172 — Meta Horizon OS OVRMediaService Privilege Escalation Vulnerability

Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering …

| Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51872 — Devika Code Injection Vulnerability

Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.

| Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51871 — Devika Code Injection Vulnerability

Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct executi…

| Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51870 — DeepTutor Command Injection Vulnerability

DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.

| Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51869 — DB-GPT Sandbox API Arbitrary Code Execution

DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.

| Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51867 — AgentGPT Incorrect Access Control Vulnerability

agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reache…

| Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-51866 — DB-GPT Arbitrary Code Execution

In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.

| Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14965 Results