Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2013-10076 — ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on …

ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_exte…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103636 — Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization…

Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103635 — Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deseria…

Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read …

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103513 — Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch des…

Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103501 — Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow all…

Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupo…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.5 MEDIUM
CVE-2026-108506 — Unauthorized access vulnerability in ZTE Z80 Ultra product

ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant infor…

| Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-106139 — Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue

In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, i…

kendo_ui_for_vue | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-106138 — Cross-Site Scripting via Chart Tooltip in KendoReact

In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in bo…

kendoreact | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.5 HIGH
CVE-2026-91136 — Divi Plus <= 2.4.0 - Unauthenticated Arbitrary File Read via 'svg_image' Parameter

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST …

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-4791 — PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross…

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
3.3 LOW
CVE-2026-108505 — Information disclosure vulnerability in ZTE Z80 Ultra product

ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.

| Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-107657 — HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribu…

The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom user attribute field name, e.g. profile_test>' …

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
4.9 MEDIUM
CVE-2026-104722 — Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authentic…

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV…

Remote | Path Traversal
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-97396 — Email Marketing for WordPress and WooCommerce <= 1.0.10 - Authenticated (Subscriber+) Sto…

The Email Marketing for WordPress and WooCommerce – Retainful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 1.0.10 d…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-97340 — Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Authenticated (Subscriber…

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Stored Cross-Site Scripting via the user profile 'Author Page' social link contact-method fields (author_f…

avada | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96765 — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenti…

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and incl…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.5 HIGH
CVE-2026-96662 — Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to,…

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-96653 — WP Directory Kit <= 1.5.9 - Authenticated (Subscriber+) SQL Injection via 'display_name' …

The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9 due to insufficient esc…

wp_directory_kit | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-96563 — Motors <= 1.4.123 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'stm_f_s'…

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 du…

motors_-_car_dealer\,_classifieds_\&_listing | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-96278 — WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUE…

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sa…

wp_photo_album_plus | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14061 Results