Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-105295 — GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error …

Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.1 CRITICAL
CVE-2026-105294 — Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers…

Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.2 CRITICAL
CVE-2026-105293 — Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers ru…

Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.0 MEDIUM
CVE-2026-105292 — Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Atta…

Remote | Cross-Site Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.1 CRITICAL
CVE-2026-105223 — maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecur…

Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105175 — SourceCodester Drug Recommendation System Student Registration add_student.php sql inject…

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The man…

drug_recommendation_system | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.5 MEDIUM
CVE-2026-105174 — Gerapy Project Management views.py project_create path traversal

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipula…

gerapy | Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.0 MEDIUM
CVE-2026-105173 — code-projects Human Resource Management Event Creation EventStore.php cross site scripting

A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation.…

human_resource_management | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105172 — itsourcecode Online Admission System login1.php sql injection

A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User …

online_admission_system | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105171 — kishor-23 food-waste-management-system Role Attribute admin.php authorization

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability …

food-waste-management-system | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105170 — kishor-23 food-waste-management-system Admin Signup signup.php missing authentication

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file…

food-waste-management-system | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105169 — kishor-23 food-waste-management-system Take Order delivery.php sql injection

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of th…

food-waste-management-system | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105168 — kishor-23 food-waste-management-system Order Assignment Block admin.php sql injection

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the fil…

food-waste-management-system | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.1 CRITICAL
CVE-2026-105222 — alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_ver…

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_V…

google_maps | Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.1 CRITICAL
CVE-2026-105221 — Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NON…

Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.5 HIGH
CVE-2026-105220 — Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file w…

| Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-105167 — kishor-23 food-waste-management-system donate.php sql injection

A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function…

food-waste-management-system | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-105166 — kishor-23 food-waste-management-system Food Donation Form fooddonateform.php insert sql i…

A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of t…

food-waste-management-system | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.5 MEDIUM
CVE-2026-105165 — devopspolis secrets-replicator AssumeRole handler.py process_single_secret permission ass…

A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. Such manip…

secrets-replicator | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.1 MEDIUM
CVE-2026-105164 — NASA cFS cfe_fs_api.c CFE_FS_ParseInputFileNameEx out-of-bounds

A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read…

cfs | Remote | Memory Corruption
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
Showing 20 of 14277 Results