Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-108158 — plugNmeet Server through 2.5.2 Path Traversal via /api/whiteboard/convert

plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Atta…

Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.2 CRITICAL
CVE-2026-108157 — Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108156 — LobsterAI 2026.5.27 through 2026.9.23 Arbitrary Directory Deletion via Skill _meta.json

LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during…

lobsterai | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-108119 — Busybox: busybox: tar extraction-root escape via deferred symlink/hardlink creation bypas…

A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains insi…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.5 MEDIUM
CVE-2026-108093 — Gimp: gimp: denial of service via null pointer dereference in xcf simulation parasite loa…

A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a speciall…

enterprise_linux enterprise_linux | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.5 HIGH
CVE-2026-107815 — MariaDB: one byte OOB write in DOS tables of the CONNECT engine

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary …

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2025-61560 — Argo CD SessionManager Race Condition Vulnerability

A race condition vulnerability in the SessionManager of CNCF: Cloud Native Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting and perform a brute force attack via repeated c…

| Race Condition
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2016-20098 — Moderator Toolbox before 4.0.14 Stored XSS via Removal Reasons Configuration

Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HT…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.2 HIGH
CVE-2026-90983 — OTP Code Exposure in Hayat Hospital's Hayat Mobile

Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-75349 — EIPStackGroup OpENer Out-of-Bounds Read Vulnerability

EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-75348 — EIPStackGroup OpENer Out-of-Bounds Read Vulnerability

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommon…

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-75346 — EIPStackGroup OpENer Out-of-Bounds Read Vulnerability

An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a den…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-75345 — OpENer Out-of-Bounds Read Denial of Service

OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-108113 — ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import

ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executab…

ilias | Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-108112 — ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via Workflow Delete Endpoint

ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability that allows authenticated users to delete other users' workflows via POST /workflow/del/{uuid}. Attackers can obtain workfl…

ruoyi-ai ruoyi_ai | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-108111 — ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via /workflow/search

ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query t…

ruoyi-ai ruoyi_ai | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.6 HIGH
CVE-2026-108110 — MOVO through 0.2.3 Authorization Bypass via Document Endpoints

MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary objec…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.4 HIGH
CVE-2026-107814 — MariaDB: Insecure $HOME in MariaDB rpm packages

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service accoun…

Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-107813 — Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in…

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart opera…

nginx_ui | Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107812 — Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RC…

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgra…

nginx_ui | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14115 Results