Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.7 MEDIUM
CVE-2026-108501 — Unauthorized access vulnerability in ZTE Z80 Ultra product

ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface.

| Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.1 CRITICAL
CVE-2026-107645 — Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter

The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disa…

blocksy_companion | Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.8 MEDIUM
CVE-2026-104898 — Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Referen…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.4 via the 'id, wp_user_id…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.1 HIGH
CVE-2026-104797 — Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authen…

The Advanced Form Integration — Connect Forms to 300+ Apps plugin for WordPress is vulnerable to Authentication Bypass via Unverified Password Change in all versions up to, and including, 2.9.0 The `…

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-104732 — Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1…

The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no …

Remote | Authentication
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.3 MEDIUM
CVE-2026-103365 — Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Info…

The Bookly – Online Scheduling and Appointment Booking System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 28.4 via the classic booking form'…

Remote | Information Disclosure
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.4 HIGH
CVE-2026-101947 — ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during …

ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded…

Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.4 MEDIUM
CVE-2026-93883 — Advanced Classifieds & Directory Pro <= 3.4.4 - Authenticated (Custom+) Stored Cross-Site…

The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone' parameter in all versions up to, and including, 3.4.4 due to insufficient in…

Remote | Cross-Site Scripting
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
6.5 MEDIUM
CVE-2026-104915 — Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy…

The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugi…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
5.4 MEDIUM
CVE-2026-104022 — Academy LMS <= 4.0.3 - Authenticated (Custom+) Privilege Escalation to add_child REST end…

The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the `add_…

Remote | Authorization
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
9.8 CRITICAL
CVE-2026-108474 — JetBrains Exposed SQL Injection

In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions

Remote | Injection
Oct 10, 2026 Oct 10, 2026
Oct 10, 2026
Oct 10, 2026
8.2 HIGH
CVE-2026-22061 — CVE-2026-22061 Debug Log Information Disclosure Vulnerability in Trident

Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory cre…

trident | Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108269 — ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session

Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was …

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108268 — enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session

Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed th…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108267 — Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS sess…

Privasys Go is a maintained fork of the Go programming language that adds RA-TLS support to crypto/tls. Prior to privasys-v0.5.1-go1.26.5, challenge-mode RA-TLS certificates bound quote ReportData to…

Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.8 HIGH
CVE-2026-92705 — Aegisub executes arbitrary code through automatically loaded Automation scripts

Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects withou…

| Supply Chain
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-62376 — Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables acc…

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. …

vikunja | Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-62367 — Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-accou…

Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, V…

vikunja | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-57458 — Vikunja: Scoped API token can mint unrestricted OAuth session credentials

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAu…

vikunja | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108266 — Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS …

Privasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support. Prior to privasys-v0.8.1, the fork emitted RA-TLS challenge certificates whose q…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14118 Results