Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-104081 — KodExplorer < 4.55 Path Traversal via unzip_pre_name() ZIP Extraction

KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass …

kodexplorer | Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.8 MEDIUM
CVE-2026-102916 — Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pan…

A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() a…

illumos-gate | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.9 MEDIUM
CVE-2026-108105 — Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request

Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs…

open5gs | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-108103 — Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short …

open5gs | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-108102 — Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Volume Measurement IE

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers.…

open5gs | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-108101 — HortusFox through 6.3 Unrestricted File Upload via Plant Attachments

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under p…

hortusfox | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-108100 — HortusFox before 6.2 SQL Injection via /api/locations/list include_info Parameter

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. …

hortusfox | Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-105278 — Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials

The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate usin…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.9 MEDIUM
CVE-2026-96396 — Affinity Heap-Based Buffer Overflow Vulnerability

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity docu…

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.6 LOW
CVE-2026-96395 — Affinity for macOS Heap-based Out-of-Bounds Read

The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading …

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
2.9 LOW
CVE-2026-96394 — Affinity Out-of-Bounds Heap Read Vulnerability

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews …

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.6 LOW
CVE-2026-96393 — Affinity Out-of-Bounds Pointer Dereference

The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat …

affinity | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-94062 — WordPress Werkstatt theme <= 4.8.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affe…

Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-94061 — WordPress Whistle - Sports Club theme <= 4.2 - Reflected Cross Site Scripting (XSS) vulne…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Wh…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-94060 — WordPress Voldor theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Voldor voldor allows Reflected XSS.This issue affects Voldor: from n/a through 1.0.0.

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-94059 — WordPress Ogency theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Ogency ogency allows Reflected XSS.This issue affects Ogency: from n/a through 1.0.0.

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-94058 — WordPress Treck theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Treck treck allows Reflected XSS.This issue affects Treck: from n/a through 1.0.0.

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.5 HIGH
CVE-2026-8374 — Misuse and Misconfiguration of Cryptographic Algorithm in Bluetooth Communication

Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.

| Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-86405 — Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. Thi…

Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-85531 — Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x

Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation. This …

Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14152 Results