Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-108711 — Plastic Labs Honcho through 3.3.0 Incorrect Authorization via POST /v3/workspaces

Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks o…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108710 — NornicDB through 1.4.1 Missing Authorization via Vector Search Endpoints

NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints.…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.5 MEDIUM
CVE-2026-108584 — FunnyWolf Viper config hard-coded credentials

A security flaw has been discovered in FunnyWolf Viper up to 3.1.11. The affected element is an unknown function of the file /root/viper/.git/config. Performing a manipulation results in hard-coded c…

viper | Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108578 — Neterbit NW-431F Embedded Web Server sms.json information disclosure

A vulnerability was identified in Neterbit NW-431F 20250715. Impacted is an unknown function of the file /sms.json of the component Embedded Web Server. Such manipulation leads to information disclos…

nw-431f | Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.0 MEDIUM
CVE-2026-108577 — Konstanty Bialkowski libmodplug ABC Music Format load_abc.cpp abc_add_gchord resource con…

A vulnerability was determined in Konstanty Bialkowski libmodplug up to 0.8.9.1. This issue affects the function abc_add_gchord of the file src/load_abc.cpp of the component ABC Music Format Parser. …

libmodplug | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
10.0 CRITICAL
CVE-2026-108576 — TOZED X300 IPPingDiagnostics process_ping os command injection

A vulnerability was found in TOZED X300 up to 6.01.3. This vulnerability affects the function process_ping of the component IPPingDiagnostics Handler. The manipulation of the argument Host results in…

x300 | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108575 — BerriAI LiteLLM Secret Resolution main.py get_secret improper authorization

A vulnerability has been found in BerriAI LiteLLM up to 1.94.0. This affects the function get_secret of the file secret_managers/main.py of the component Secret Resolution. The manipulation of the ar…

litellm | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108574 — BerriAI LiteLLM Spend Tracking spend_management_endpoints.py ui_view_session_spend_logs a…

A flaw has been found in BerriAI LiteLLM up to 1.95.0. Affected by this issue is the function ui_view_session_spend_logs of the file litellm/proxy/spend_tracking/spend_management_endpoints.py of the …

litellm | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108573 — Open Asset Import Library Assimp PLY File getNextBlock out-of-bounds

A vulnerability was detected in Open Asset Import Library Assimp up to 6.0.5. Affected by this vulnerability is the function IOStreamBuffer::getNextBlock of the component PLY File Handler. Performing…

assimp | Remote | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108572 — Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery

A security vulnerability has been detected in Casdoor up to 3.164.0/4.10.0. Affected is the function CasP3ProxyValidate of the file controllers/cas.go of the component Proxy Validation. Such manipula…

casdoor | Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.5 HIGH
CVE-2026-108571 — Xinhu Rainrock RockOA Openkqj Action openkqjAction.php returnchuli sql injection

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Act…

rainrock_rockoa | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108570 — Furion .NET Framework View ViewEngine.cs RunCompile special elements in template engine

A security flaw has been discovered in Furion .NET Framework up to 4.9.9.95. This affects the function RunCompile of the file framework/Furion/ViewEngine/Engines/ViewEngine.cs of the component View E…

.net_framework | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108569 — Furion .NET Framework StringRenderExtensions.cs String.Replace sql injection

A vulnerability was identified in Furion .NET Framework up to 4.9.9.92. The impacted element is the function String.Replace of the file framework/Furion/Templates/Extensions/StringRenderExtensions.cs…

.net_framework | Remote | Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108568 — InstantSoft icms2 Billing paypal.php validatePaypalOrder data authenticity

A vulnerability was determined in InstantSoft icms2 up to 2.18.2. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component B…

icms2 | Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108567 — InstantSoft icms2 Image image.php files_delete_file path traversal

A vulnerability was found in InstantSoft icms2 up to 2.18.2. Impacted is the function files_delete_file of the file system/fields/image.php of the component Image Handler. Performing a manipulation o…

icms2 | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.0 MEDIUM
CVE-2026-108566 — InstantSoft icms2 Private Message index.tpl.php index cross site scripting

A vulnerability has been found in InstantSoft icms2 up to 2.18.2. This issue affects the function index of the file templates/default/controllers/messages/index.tpl.php of the component Private Messa…

icms2 | Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.5 HIGH
CVE-2026-108544 — Lippu Docx Reader Office Viewer App path traversal

A vulnerability was identified in Lippu Docx Reader Office Viewer App up to 1.4.5 on Android. This affects the function word.office.docxviewer.document.docx.reader.ViewTxt. Such manipulation of the a…

docx_reader_office_viewer_app | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108543 — ag2ai ag2 UserProxyAgent os.path.join path traversal

A vulnerability was determined in ag2ai ag2 up to 0.13.4. Affected by this issue is the function os.path.join of the component UserProxyAgent. This manipulation of the argument filename causes path t…

ag2 | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.5 MEDIUM
CVE-2026-108542 — 021is elvix-sdk MCP Request index.ts server-side request forgery

A vulnerability was found in 021is elvix-sdk up to 0.10.1. Affected by this vulnerability is an unknown functionality of the file src/mcp/index.ts of the component MCP Request Handler. The manipulati…

elvix-sdk | Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-97183 — WP-Invoice <= 4.3.1 - Subscriber+ User PII Disclosure via Unprotected AJAX Handlers

The WP-Invoice WordPress plugin through 4.3.1 does not perform capability checks in several of its AJAX handlers, allowing any authenticated user, such as a Subscriber, to retrieve the email address…

wp-invoice | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 14194 Results