Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-39601 — WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Bo…

wp_booking_calendar | Remote | Race Condition
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.7 MEDIUM
CVE-2026-39600 — WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Forwards vulne…

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.…

Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.4 MEDIUM
CVE-2026-39444 — WordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object References (IDOR) …

Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-39439 — WordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7.

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-32585 — WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-32584 — WordPress Smart One Click Setup – Complete Demo Import &amp; Export plugin <= 1.4.3 - Sen…

Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import &amp; Export smart-one-click-setup allows Retrieve Embedded Sensitiv…

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.5 MEDIUM
CVE-2026-104638 — onetwothreeneth HospitalManagementSystem sessions.php improper authentication

A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is an unknown function of the file php/sess…

hospitalmanagementsystem | Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-104637 — onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted upload

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/u…

hospitalmanagementsystem | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104625 — CodeAstro Simple Loan Management System index.php sql injection

A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name resu…

simple_loan_management_system | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.8 HIGH
CVE-2026-104026 — Sapling SCM Git Subtree URL Control Character Injection Remote Code Execution

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execu…

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-94422 — xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial…

Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-93875 — JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime…

The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitizat…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.1 HIGH
CVE-2026-85215 — SQL Injection in GG Soft's Paperwork

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue affects Paperwork: thr…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-19652 — Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new us…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-104721 — Logback: Incomplete protection against CVE-2026-19880

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitize…

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104614 — CodeAstro Simple Pharmacy Management System delete.php sql injection

A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of …

simple_pharmacy_management_system | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104613 — CodeAstro Simple Pharmacy Management System view.php sql injection

A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the a…

simple_pharmacy_management_system | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-96289 — Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have …

Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-96287 — Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining …

Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes…

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-96286 — Apache Thrift: Perl servers end `serve()` when serving one connection fails

Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

thrift | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14950 Results