Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-107834 — OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart …

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() fo…

coraza | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.9 MEDIUM
CVE-2026-107833 — OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhausti…

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit va…

coraza | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107826 — OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-dep…

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after re…

coraza | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.0 MEDIUM
CVE-2026-107825 — OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failur…

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by …

coraza | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-107824 — x64dbg-MCP Server exposes debugger operations to unauthenticated network clients

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools o…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.2 HIGH
CVE-2026-107823 — MariaDB: privilege escalation via incorrect view frm parsing

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the MariaDB view FRM parser did not safely encode embedded newl…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.4 MEDIUM
CVE-2026-107822 — MariaDB: database privilege escalation via user / role name collision in the acl cache

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege …

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.0 HIGH
CVE-2026-107821 — MariaDB: insufficient validation of binary frm data when opening a table

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and …

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-107820 — x64dbg-MCP Server vulnerable to pre-authentication denial of service through Content-Leng…

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Conten…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.9 MEDIUM
CVE-2026-107819 — MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verifi…

MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authen…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.4 HIGH
CVE-2026-107818 — MariaDB: environment injection via wsrep bootstrap in the mariadb.service file

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster dur…

Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.4 MEDIUM
CVE-2026-107817 — MariaDB: mysql_json plugin OOB reads

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contai…

| Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.4 MEDIUM
CVE-2026-107816 — MariaDB: `qc_info` plugin can do OOB reads if query contains \0

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the qc_info plugin could be confused by a query containing embe…

Remote | Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-75597 — pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensiti…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 tem…

pyload | Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-75347 — EIPStackGroup OpENer Expired Pointer Dereference

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attac…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-55797 — Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it cl…

argo-cd | Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-48484 — pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termin…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole c…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-42695 — WordPress FV Flowplayer Video Player plugin <= 7.5.54.7212 - Cross Site Scripting (XSS) v…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Flowplayer Video Player fv-wordpress-flowplayer allows Stored XSS.This issue affec…

fv_flowplayer_video_player | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-108160 — AstronRPA through 1.1.6 Unsigned Update Installation via Plain-HTTP Feed

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechan…

Remote | Supply Chain
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-108159 — AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM outpu…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14134 Results