Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-97264 — WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Reflected XSS.This issue affects WPAdverts: from n/a th…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-97263 — WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Stored XSS.This issue affects WPAdverts: from n/a throu…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-94676 — WordPress Tainacan plugin <= 1.3.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.9 MEDIUM
CVE-2026-66435 — WordPress WP Rollback plugin <= 3.1.2 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This issue affects WP Rollback: from n/a through 3.1.2.

Remote | Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108165 — Immich through 3.3.1 Missing Authorization in Partner Sync Exposes Locked Folder Metadata

Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read Locked Folder asset metadata because sync queries …

immich | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-108164 — Open Source Social Network (OSSN) through 10.1 IDOR via Message Attachment Route

Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' …

open_source_social_network | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-108163 — Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL

Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-108162 — Pingvin Share X before 1.22.0 Rate Limit Bypass via Spoofed X-Forwarded-For

Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts pro…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.7 HIGH
CVE-2026-108161 — FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller …

fusionpbx | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.8 HIGH
CVE-2026-105885 — WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

slider | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-102388 — WordPress Forminator plugin <= 1.57.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through …

forminator | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.7 HIGH
CVE-2026-108546 — Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attacker…

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.2 HIGH
CVE-2026-108545 — SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing

SillyTavern 1.12.13 through 1.19.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust resources because body-parser middleware runs before authenticati…

Remote | Denial of Service
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.9 MEDIUM
CVE-2026-108115 — Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses

Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that emb…

suna | Remote | Server-Side Request Forgery
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108114 — Strapi 5.47.0 through 5.57.0 Improper Authorization via Admin API Token Field Permissions

Strapi 5.47.0 through 5.57.0 contains an improper authorization vulnerability that allows admin API tokens to retain all-field Content Manager access after the owner's role is field-restricted. Becau…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107794 — ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an…

ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107373 — ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may re…

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg)…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2013-10076 — ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on …

ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_exte…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103636 — Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization…

Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103635 — Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deseria…

Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read …

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14121 Results