Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-107175 — MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes

MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user ed…

misp | Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
2.9 LOW
CVE-2026-107170 — M17n-lib: null dereference in minput_open_im() after failed m17n_init()

A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion o…

enterprise_linux enterprise_linux | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.2 MEDIUM
CVE-2026-107168 — M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()

A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to…

enterprise_linux enterprise_linux | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-107162 — Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass

Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any vali…

express-gateway_docker_image | Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-107151 — Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated reques…

Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A …

satellite satellite | Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.2 MEDIUM
CVE-2026-105140 — Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group …

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlappin…

Remote | Race Condition
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-105139 — Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because prof…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-105138 — Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Ba…

Remote | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.7 HIGH
CVE-2026-103435 — Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This tim…

Remote | Race Condition
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-102256 — SMA1000 OS Command Injection Vulnerability

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions …

sma1000 | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-102255 — SonicWall SMA1000 Appliance Server-Side Request Forgery

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could …

sma1000 | Server-Side Request Forgery
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-42710 — WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: fr…

slider | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-42708 — WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Aut…

wp_post_author | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-107159 — MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header

MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a…

miniupnpd | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-106059 — GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript

GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Fin…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.7 HIGH
CVE-2026-106058 — GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames

GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by substituting crafted filenames into clean/smudge …

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.5 HIGH
CVE-2026-106057 — patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt

patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers c…

| Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.7 HIGH
CVE-2026-106056 — Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. At…

rundeck | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.4 CRITICAL
CVE-2026-96408 — Movable Type Code Injection Vulnerability

A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-92533 — Path Traversal in BugTracker.NET

Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacke…

bugtracker.net | Remote | Path Traversal
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15439 Results