Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-97257 — WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.

simple_event_planner | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-95265 — Feehi CMS Server-Side Request Forgery

Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an …

| Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-95264 — Feehi CMS Directory Traversal Vulnerability

Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used…

| Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-95263 — Feehi CMS Incorrect Access Control Vulnerability

Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator accou…

| Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.2 HIGH
CVE-2026-94201 — Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom table in Ash

Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced through Ash.Type.Atom. Because the type de…

ash | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.2 HIGH
CVE-2026-93617 — WordPress Sunshine Photo Cart plugin <= 3.7.1 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.

sunshine_photo_cart | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-78862 — Mercusys AC12 Arbitrary Code Execution via UART Interface

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed circuit board (PCB)

| Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-78861 — Mercusys AC12 Arbitrary Code Execution via Hardcoded RSA Private Key

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key

| Cryptography
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-78860 — Mercusys AC12 Arbitrary Code Execution

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext

| Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-71299 — Maestro: maestro: rest api write endpoints registered without authentication middleware

A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as cre…

multicluster_engine_for_kubernetes | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.4 MEDIUM
CVE-2026-71298 — Maestro: sql identifier injection via properties.* search filter and orderby field

A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentic…

multicluster_engine_for_kubernetes | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-71297 — Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional

A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to o…

multicluster_engine_for_kubernetes | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.3 LOW
CVE-2026-105767 — Chainguard Academy (edu) integrate-platform-docs composite action interpolates inputs int…

Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16…

Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.1 LOW
CVE-2026-105766 — Chainguard Academy (edu) Nginx directory redirect downgrades HTTPS requests to HTTP

Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e…

Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105696 — Penpot: Share-link page-scope escalation: a share-link holder reads pages outside the lin…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selecte…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.9 MEDIUM
CVE-2026-105695 — Penpot: Missing authorization in chunked-upload assembly lets another authenticated user …

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the…

penpot | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-105694 — Penpot: Stored XSS via Unsanitised SVG Uploads

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObjec…

penpot | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-105693 — Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-105692 — Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did…

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent fi…

penpot | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.9 CRITICAL
CVE-2026-105691 — Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and execute…

penpot | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14456 Results