Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-107799 — Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107798 — Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Fil…

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attri…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-107797 — Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters

Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can …

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-107796 — Jivejdon through commit ee67a65e Reflected XSS via taggedThreadList.jsp tagID and count P…

Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107793 — Jivejdon through 5.0 IDOR via subSaveAction Subscription Delete

Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers …

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107792 — Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Th…

Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attacke…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.3 CRITICAL
CVE-2026-107726 — Hazelcast: Arbitrary member memory access by low-privileged client

Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able t…

hazelcast | Remote | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-107725 — Hazelcast: Authorization bypass in IMap Predicates API

Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a m…

hazelcast | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.4 HIGH
CVE-2026-107724 — fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgori…

fast-jwt | Remote | Cryptography
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.1 HIGH
CVE-2026-107723 — fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the p…

fast-jwt | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.8 CRITICAL
CVE-2026-107722 — fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS…

fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its P…

fast-jwt | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107721 — fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and pers…

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts Infinity for clockTolerance because its option validation checks type and negativity but no…

fast-jwt | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.4 HIGH
CVE-2026-107720 — fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is e…

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist…

fast-jwt | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.2 MEDIUM
CVE-2026-107719 — fast-jwt: Verifier cache accepts expired JWTs without iat.

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.4, the fast-jwt createVerifier cache can continue accepting a previously valid, signed JWT after its exp time when caching is …

fast-jwt | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-107718 — AdonisJS: Unencoded route parameters can produce open redirects

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. Prior to 8.2.3 and 9.3.0, AdonisJS HTTP Server inserts route parameter values into URLs without encodeURICompon…

http-server | Remote | Server-Side Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107717 — Banks: User-controlled prompt input can be parsed as privileged chat messages

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. Whe…

Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.3 HIGH
CVE-2026-107716 — Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegist…

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja …

| Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-107715 — Mechanize sends credential headers to another host after an HTTP redirect

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#reque…

mechanize | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107714 — Mechanize sends credential headers to a different scheme or port after a redirect

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#response_redirect treats redirects as same-origin when the host matches without consist…

mechanize | Remote | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.5 CRITICAL
CVE-2026-107406 — Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, s…

Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 14144 Results