Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-105219 — Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attack…

Remote | Denial of Service
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.1 CRITICAL
CVE-2026-105218 — gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present …

Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
3.1 LOW
CVE-2026-105217 — Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers …

cockpit | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.1 CRITICAL
CVE-2026-105216 — go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by …

micro-ecc | Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.9 MEDIUM
CVE-2026-105161 — invariant-systems-ai aiir Policy Gate signature verification

A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verific…

aiir | Remote | Cryptography
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.4 MEDIUM
CVE-2026-105224 — YesWiki before 4.6.7 Stored XSS via Bazar valeur Action

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attacker…

yeswiki | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105089 — WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rende…

avideo | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105086 — WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because …

avideo | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
4.3 MEDIUM
CVE-2026-104402 — WordPress Mindio Magic MCP plugin <= 0.5.6 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a thr…

Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-105215 — ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external …

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
2.3 LOW
CVE-2026-105214 — Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The chall…

zitadel | Remote | Server-Side Request Forgery
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-105213 — ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold val…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.7 HIGH
CVE-2026-105212 — ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.2 CRITICAL
CVE-2026-105211 — ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. …

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-105210 — ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only se…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.6 CRITICAL
CVE-2026-105209 — ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollme…

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitad…

zitadel | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.7 HIGH
CVE-2026-105208 — ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted f…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.8 CRITICAL
CVE-2026-105207 — ZITADEL before 4.17.3 Account Takeover via External IdP Linking

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on id…

zitadel | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.3 MEDIUM
CVE-2026-105206 — ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Servi…

ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organiz…

zitadel | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.9 MEDIUM
CVE-2026-105205 — SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled doc…

siyuan | Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
Showing 20 of 14290 Results