Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-97291 — WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vul…

Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-97290 — WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.36 - Cross…

Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-97265 — WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a th…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.2 HIGH
CVE-2026-97256 — WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerability

Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-94171 — WordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.

curcy | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.1 HIGH
CVE-2026-87004 — Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes t…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-55224 — MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other…

mineadmin | Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
10.0 CRITICAL
CVE-2026-55107 — Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → pub…

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-par…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-55094 — Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` a…

Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskclu…

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.8 HIGH
CVE-2026-53605 — Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS…

| Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-103500 — Heap buffer overflow opening large email

An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, an…

thunderbird | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.9 MEDIUM
CVE-2026-103476 — yii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-download

yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers ca…

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.3 CRITICAL
CVE-2026-103475 — yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can …

Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-103474 — yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE

yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scri…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.2 CRITICAL
CVE-2026-103473 — Deno 2.7.0 through 2.9.7 Command Injection via node:child_process

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS comman…

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-103472 — restbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame Buffering

restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attacke…

Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-103471 — restbed through 5.0.0 Denial of Service via Unbounded Header Buffering

restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and s…

Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.4 HIGH
CVE-2026-103446 — WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments

Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extens…

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.2 LOW
CVE-2026-103445 — Stored XSS through PageForms #autoedit redirect links

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.2 LOW
CVE-2026-103440 — pagetriagelist discloses suppressed reviewer usernames

Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriag…

Remote | Information Disclosure
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14957 Results