Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-97263 — WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Stored XSS.This issue affects WPAdverts: from n/a throu…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.2 HIGH
CVE-2026-94676 — WordPress Tainacan plugin <= 1.3.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.9 MEDIUM
CVE-2026-66435 — WordPress WP Rollback plugin <= 3.1.2 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This issue affects WP Rollback: from n/a through 3.1.2.

Remote | Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-108165 — Immich through 3.3.1 Missing Authorization in Partner Sync Exposes Locked Folder Metadata

Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read Locked Folder asset metadata because sync queries …

immich | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-108164 — Open Source Social Network (OSSN) through 10.1 IDOR via Message Attachment Route

Open Source Social Network (OSSN) through 10.1 contains an insecure direct object reference vulnerability in components/OssnMessages/ossn_com.php that allows authenticated users to read other users' …

open_source_social_network | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-108163 — Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL

Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.9 MEDIUM
CVE-2026-108162 — Pingvin Share X before 1.22.0 Rate Limit Bypass via Spoofed X-Forwarded-For

Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts pro…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.7 HIGH
CVE-2026-108161 — FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller …

fusionpbx | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.8 HIGH
CVE-2026-105885 — WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

slider | Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
7.1 HIGH
CVE-2026-102388 — WordPress Forminator plugin <= 1.57.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through …

forminator | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107794 — ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an…

ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-107373 — ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may re…

ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg)…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2013-10076 — ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on …

ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_exte…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103636 — Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization…

Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103635 — Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deseria…

Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read …

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103513 — Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch des…

Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
0.0 NA
CVE-2026-103501 — Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow all…

Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupo…

| Memory Corruption
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.5 MEDIUM
CVE-2026-108506 — Unauthorized access vulnerability in ZTE Z80 Ultra product

ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant infor…

| Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-106139 — Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue

In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, i…

kendo_ui_for_vue | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-106138 — Cross-Site Scripting via Chart Tooltip in KendoReact

In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in bo…

kendoreact | Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
Showing 20 of 14071 Results