Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-105131 — mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because Token…

ezbookkeeping | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-105096 — Omega Solution CoinEx Crypto Customer Profile API customer authorization

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the arg…

coinex_crypto | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.3 MEDIUM
CVE-2026-105130 — LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Atta…

lara_dashboard | Remote | Race Condition
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.1 HIGH
CVE-2026-105129 — LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attack…

lara_dashboard | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.4 MEDIUM
CVE-2026-105128 — LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder…

lara_dashboard | Remote | Misconfiguration
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.9 MEDIUM
CVE-2026-105127 — LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unau…

lara_dashboard | Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.6 HIGH
CVE-2026-105126 — LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.ed…

lara_dashboard | Remote | Authorization
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.3 MEDIUM
CVE-2026-105125 — LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can s…

lara_dashboard | Remote | Path Traversal
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.1 MEDIUM
CVE-2026-105124 — W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment websi…

wcms | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-105123 — W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media…

wcms | Remote | Path Traversal
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
8.8 HIGH
CVE-2026-96451 — WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13…

ultimate_member | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.1 HIGH
CVE-2026-103342 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-e…

unlimited_elements_for_elementor | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-103065 — WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.…

Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-105122 — OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri

OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated…

openam | Remote | Server-Side Request Forgery
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-105121 — OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Aut…

openam | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-105120 — OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding d…

openam | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.6 HIGH
CVE-2026-105119 — OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, …

openam | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
4.7 MEDIUM
CVE-2026-105118 — OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoin…

openam | Remote | Misconfiguration
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-105117 — OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json…

openam | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-105116 — OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachab…

openam | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 14726 Results