Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-82627 — Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Us…

The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi…

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-102488 — Octopus Server Privilege Escalation Vulnerability

In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to …

octopus_server | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-87681 — Brocade Fabric OS Access Control Bypass Vulnerability

An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operat…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-87680 — Brocade Fabric OS Command Injection Vulnerability

A command injection vulnerability in the REST API management interface of Brocade Fabric OS versions before 10.0.1 allows an authenticated user to execute arbitrary system commands via crafted input …

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-87679 — Brocade Fabric OS Heap-Based Buffer Overflow

When Brocade Fabric OS versions before 10.0.1 processes trunk configuration operations, the application parses user-supplied list strings into dynamically allocated heap arrays without enforcing boun…

fabric_operating_system fabric_os | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2024-8122 — Potential brute force vulnerability due to non-expiring SMS OTPs

The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, pres…

identity_server wso2_identity_server | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-94154 — Aurora Heatmap <= 1.7.2 - Unauthenticated Stored Cross-Site Scripting via 'url' Parameter

The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and out…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-17538 — Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.9 - A…

The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process_step_custo…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107315 — pgjdbc pads a value shorter than its declared length with bytes of earlier statements (ra…

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores th…

postgresql_jdbc_driver | Remote | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.2 HIGH
CVE-2026-89322 — Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypas…

vault | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-107314 — pgjdbc does not enforce requireAuth when the value excludes every authentication method

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for exam…

postgresql_jdbc_driver | Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-107285 — AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a CONNECT tun…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried throu…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
3.7 LOW
CVE-2026-107284 — AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-Accept check

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a han…

Remote | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
3.7 LOW
CVE-2026-107283 — AsyncHttpClient: Digest authentication cnonce generated with a non-cryptographic random s…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Dig…

Remote | Cryptography
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.4 CRITICAL
CVE-2026-107282 — AsyncHttpClient: Replay to a different host sends the original host request and credentia…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates th…

Remote | Server-Side Request Forgery
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.6 HIGH
CVE-2026-107281 — AsyncHttpClient: Connection pool key omits the authenticated principal, so an NTLM or Neg…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excl…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.9 MEDIUM
CVE-2026-107280 — AsyncHttpClient: Cookie Domain attribute is not checked against the public suffix list, s…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Doma…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-107279 — AsyncHttpClient: Digest mutual authentication is switched off by a peer offering qop=auth…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.5 HIGH
CVE-2026-107232 — AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects the CONNECT

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that …

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.7 HIGH
CVE-2026-107231 — AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic and sends th…

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challen…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15508 Results