Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-34499 — Johnson Controls ADVMS Hard-Coded Cryptographic Key Vulnerability

Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable. This issue affects ADVMS: before 3.10.

| Cryptography
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.9 MEDIUM
CVE-2026-107353 — traverse: set() can write to built-in prototypes via an untrusted path

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primit…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-107176 — Cluster-samples-operator: role reads all secrets in openshift-config, not just pull-secret

A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grants get, list, and watch permissions on all Secret resources without resourc…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107161 — Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows malicious server…

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST…

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.2 MEDIUM
CVE-2026-107313 — pgjdbc stores bytes of earlier messages in place of a large value on GSS-encrypted connec…

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 and 42.7.5 can send the previous contents of the GSS send buffer in place of the first part of a value on a connection with GSS encryption (gssEncM…

postgresql_jdbc_driver | Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-107225 — Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attac…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-107224 — Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative in…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-107223 — Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded p…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the wor…

excelize | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-107222 — Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no …

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to 2.11.0, conditional-format extraction indexes required child slices or dereferences an optional c…

excelize | Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-107221 — Excelize: a row whose earlier cell has a higher column reference than its last cell panic…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0, checkRow sizes its target cell slice from the last cell in XML document order and then re…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-107220 — Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached rectangle empty for an empty mergeCell ref and then pa…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107219 — Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password…

excelize | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-107218 — Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune arra…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107217 — Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil e…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, Column…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.3 HIGH
CVE-2026-106164 — Infinite Loop in Telerik Document Processing XLS Import

In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corrupt…

telerik_document_processing_libraries | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-103371 — Apache Geode: Management REST API: Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File in Apache Geode Web Management. This issue affects Apache Geode: from 2.0.0 before 2.0.3. Users are recommended to upgrade to version 2.0.3, whi…

geode | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-96335 — WordPress Forminator plugin <= 1.57.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.

forminator | Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-56851 — Panic parsing crafted input in x/text/secure/precis in golang.org/x/text

The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.

| Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107216 — Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entr…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calcu…

excelize | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107215 — Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers…

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-ent…

excelize | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15528 Results