Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-104112 — Missing release of passed file descriptors in illumos nscd allows local users to exhaust …

A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_fronte…

illumos-gate | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-104081 — KodExplorer < 4.55 Path Traversal via unzip_pre_name() ZIP Extraction

KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass …

kodexplorer | Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.8 MEDIUM
CVE-2026-102916 — Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pan…

A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() a…

illumos-gate | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-94067 — WordPress The Voux theme <= 6.9.5 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affe…

Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-94066 — WordPress Pond theme <= 2.6.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpabRice Pond pond allows Reflected XSS.This issue affects Pond: from n/a through 2.6.1.

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-94065 — WordPress ColorFolio theme <= 1.3 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-94064 — WordPress Neo | Barber Shop WordPress Theme theme <= 3.5 - PHP Object Injection vulnerabi…

Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through…

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-94063 — WordPress Education Center theme <= 3.6.12 - Reflected Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Education Center education allows Reflected XSS.This issue affects Education Center: fro…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-92085 — Stored XSS in TMT Machine's Talassoft Industrial Management Software

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TMT Machinery Industry and Trade Co. Ltd. Talassoft Industrial Management Software allows Stored …

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.9 MEDIUM
CVE-2026-85479 — Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fu…

The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchang…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-79363 — Cloudron Stored Cross-Site Scripting Vulnerability

Cloudron 9.1.7 and 9.2 contain a stored cross-site scripting (XSS) vulnerability in the Branding Footer feature. An authenticated administrator can store crafted HTML containing JavaScript event hand…

| Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-62026 — WordPress Dashboard Notes plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerabili…

Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.

Remote | Cross-Site Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.5 MEDIUM
CVE-2026-108063 — Libhangul: null pointer dereference in hanja_new() when looking up a malformed hanja dict…

A flaw was found in libhangul. When parsing Hanja dictionary files, the library fails to verify that an entry contains a valid value alongside its key. By providing a specially crafted dictionary fil…

enterprise_linux enterprise_linux | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-107803 — ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter

ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter …

processmaker | Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-107785 — Crux Agent silently fails SKA preshared key rotation when SHA-512 peering is negotiated

Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 by…

Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.2 HIGH
CVE-2026-106581 — Docker Desktop for Windows installer failed to verify external packages

Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convin…

desktop | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.7 HIGH
CVE-2026-105281 — Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Fu…

The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve …

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-104629 — Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to …

A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the…

Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-101022 — Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF)

A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connectio…

Remote | Server-Side Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-100730 — Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data

A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach thi…

Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14130 Results