Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-105403 — ImageMagick before 7.1.2-31 Security Policy Bypass via Coder Domain

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder…

imagemagick | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105402 — ImageMagick before 7.1.2-31 Denial of Service via XMP Profile Parsing

ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that…

imagemagick | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.0 MEDIUM
CVE-2026-105401 — ImageMagick before 7.1.2-31 Heap Buffer Overflow in Distributed Pixel Cache Server

ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attack…

imagemagick | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105400 — ImageMagick before 7.1.2-31 Unclosed File Pointer via Magick Script

ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by supplying a crafted magick script. Attackers can process malicious magick scrip…

imagemagick | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105399 — ImageMagick before 7.1.2-31 Denial of Service via MVG Decoder

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that trigg…

imagemagick | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-105398 — ImageMagick before 7.1.2-31 Heap Buffer Overflow via GetVirtualPixels API

ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call to the GetVirtualPixels API. Attackers can trigger th…

imagemagick | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.2 MEDIUM
CVE-2026-105331 — mk-oracle: Local privilege escalation via malicious Oracle Instant Client

Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an a…

checkmk | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.3 HIGH
CVE-2026-91844 — Remote Code Execution via Unrestricted File Upload in İzometri Informatics' eimzamip

Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files. This issue affects eimzamip: from v1.…

Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
3.5 LOW
CVE-2026-89290 — HTML Injection in İzometri Informatics' eimzamip

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS. This issue affects…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-88257 — beam_mcp: nested tool argument constraints advertised but not enforced

Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server ad…

beam_mcp | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-42698 — WordPress Tutor LMS plugin <= 4.1.1 - Race Condition vulnerability

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leveraging Race Conditions.This issue affects Tutor LMS: fr…

tutor_lms | Remote | Race Condition
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-27420 — WordPress Zotpress plugin <= 7.4.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Seaborn Zotpress zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7…

zotpress | Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-16167 — IBM DataPower Gateway Out-of-bounds Write

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to im…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-16165 — IBM DataPower Gateway NULL Pointer Dereference

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a …

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-16164 — IBM DataPower Gateway Out-of-bounds Write

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a …

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-16163 — IBM DataPower Gateway Out-of-bounds Write

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause memory corruption due to an o…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-16161 — IBM DataPower Gateway Out-of-bounds Read

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to an…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-16159 — IBM DataPower Gateway Out-of-bounds Write

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain sensitive information and ca…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-16111 — IBM DataPower Gateway Type Confusion

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an attacker to cause a denial of service due to a type c…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.2 HIGH
CVE-2026-15824 — IBM DataPower Gateway Denial of Service

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a …

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15590 Results