Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-85493 — Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth…

Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-85483 — Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end

Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to v…

thrift | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-59668 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-59667 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-59666 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104606 — itsourcecode Online Admission System Project confirm.php sql injection

A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID resul…

online_admission_system_project | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-96292 — Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtra…

Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-96294 — Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-61373 — Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrad…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.1 MEDIUM
CVE-2026-97652 — WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Paramete…

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up t…

wp_statistics | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.8 MEDIUM
CVE-2026-95662 — Multiple vulnerabilities in the Repasat application

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s brow…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-94639 — Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death bl…

improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-94635 — Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the p…

Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-94634 — Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default

Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-94541 — WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Par…

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying …

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-94405 — WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.

download_manager | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.3 MEDIUM
CVE-2026-94180 — WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26.

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-87920 — W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficie…

w3_total_cache | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.1 MEDIUM
CVE-2026-85492 — All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-80298 — SQL Injection in HAVELSAN's Sef - AI Chatbot Platform

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This issue affects Sef - AI Chatbo…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14995 Results