Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-104983 — Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversal

A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipula…

xreader xreader | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-97873 — Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider

In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrus…

bc-java | Remote | Denial of Service
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-85515 — OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 se…

bc-java | Remote | Cryptography
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-71892 — CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys

In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a mes…

bc-java | Remote | Cryptography
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.1 HIGH
CVE-2026-71891 — BLS12-381 key validation accepts a public key built on a foreign curve

In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that…

bc-java | Remote | Cryptography
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.7 HIGH
CVE-2026-71890 — MLS external commit can remove an arbitrary group member

In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by t…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.7 HIGH
CVE-2026-71889 — PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate

In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.5…

bc-java | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.7 HIGH
CVE-2026-71888 — CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent

In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were p…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-71887 — OpenPGP data signature accepted from a signing subkey without cross-certification

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-cert…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-71886 — OpenPGP certification accepted from a subkey without certification authority

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requi…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.2 CRITICAL
CVE-2026-71885 — MLS X.509 credential not bound to the LeafNode signature key

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's s…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-71883 — Native AES packet cipher returns the raw AES key on an alias

In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, IV and additional authenticated data arrays wit…

bc-java | Remote | Memory Corruption
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.9 MEDIUM
CVE-2026-18040 — HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depe…

In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a f…

bc-java | Information Disclosure
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-92767 — Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient inpu…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.1 CRITICAL
CVE-2026-92084 — Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution v…

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to …

beaver_builder | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.0 MEDIUM
CVE-2026-104982 — Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal

A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB Fil…

xreader xreader | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-97660 — WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scriptin…

The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 du…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
4.3 MEDIUM
CVE-2026-97343 — Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link…

The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, an…

Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-96267 — WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'ful…

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient esc…

visitor_statistics | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.1 HIGH
CVE-2026-94505 — Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary …

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not…

Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 15051 Results