Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-102256 — SMA1000 OS Command Injection Vulnerability

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions …

sma1000 | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-102255 — SonicWall SMA1000 Appliance Server-Side Request Forgery

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could …

sma1000 | Server-Side Request Forgery
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-98374 — tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()

In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack() replaces the cloned SYN skb at the hea…

| Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-98373 — mm/hugetlb: preserve mremap address delta when skipping page tables

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: preserve mremap address delta when skipping page tables move_hugetlb_page_tables() optimizes mremap() by advancing to…

| Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-41958 — VisiData Path Traversal Vulnerability

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file w…

Remote | Path Traversal
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.5 MEDIUM
CVE-2026-42532 — VisiData Path Traversal Vulnerability

A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An…

| Path Traversal
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-103435 — Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This tim…

| Race Condition
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-107180 — MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instan…

On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only to standard browser requests. An authenti…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-107177 — Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens

Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.ciphe…

Remote | Cryptography
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-107162 — Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass

Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any vali…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
2.9 LOW
CVE-2026-107170 — M17n-lib: null dereference in minput_open_im() after failed m17n_init()

A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion o…

enterprise_linux enterprise_linux | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-107175 — MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes

MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or sharing group is modified. When a user ed…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.2 MEDIUM
CVE-2026-107168 — M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()

A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to…

enterprise_linux enterprise_linux | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-107151 — Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated reques…

Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A …

satellite satellite | Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.2 MEDIUM
CVE-2026-105140 — Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group …

Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlappin…

Remote | Race Condition
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-105139 — Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because prof…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.5 MEDIUM
CVE-2026-105138 — Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API

Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Ba…

Remote | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-42710 — WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: fr…

slider | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-42708 — WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Aut…

wp_post_author | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-107159 — MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header

MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a…

miniupnpd | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15455 Results