Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-92245 — Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sens…

The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it poss…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-91109 — Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authentic…

The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missi…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.5 MEDIUM
CVE-2026-103641 — Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder

A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HD…

Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103534 — David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Mode…

databasement | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-92537 — Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' …

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tr…

newsletter | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-103533 — David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path travers…

A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php …

databasement | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
3.5 LOW
CVE-2026-101887 — BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS

BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the …

| Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.0 HIGH
CVE-2026-93495 — ASUS Motherboard Arbitrary Memory Access Vulnerability

Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.

| Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.4 CRITICAL
CVE-2026-14157 — ASUS Router Format String Vulnerability

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interfa…

asus_firmware router | Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.9 HIGH
CVE-2026-13313 — ASUS Router Active Debug Code Command Injection Vulnerability

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby e…

asus_firmware router | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-103532 — immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorizat…

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. T…

immich | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103531 — OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow

A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr …

opensc | Remote | Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-103530 — decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manip…

Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-103592 — simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist …

Remote | Authorization
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-103591 — DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_ur…

Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103590 — QloApps through 1.7.0 Reflected XSS via Length of Stay Fields

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit …

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103589 — QloApps through 1.7.0 Reflected XSS via Room Type Editor

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. A…

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103588 — QloApps through 1.7.0 Reflected XSS via exceptions field

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing Java…

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-103587 — QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into te…

qloapps | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.2 LOW
CVE-2026-103585 — attacker-controlled javascript license URL via XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue …

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 15013 Results