Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.3 LOW
CVE-2026-103439 — Various rawParams() and escaped() updates to prevent XSS in Wikibase extension

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affe…

| Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.3 LOW
CVE-2026-103438 — Various rawParams() and escaped() updates to prevent XSS in Wikistories extension

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue …

| Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103437 — ReadingLists imported metadata permits JavaScript URL XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects Medi…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.3 MEDIUM
CVE-2026-103399 — Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the bod…

enterprise_linux enterprise_linux | Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-102397 — WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.2 HIGH
CVE-2026-102392 — WordPress Extra Product Options For WooCommerce | Custom Product Addons and Fields plugin…

Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-102391 — WordPress JetFormBuilder plugin <= 3.6.5.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-102377 — WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vulnerability

Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-102376 — WordPress Branda plugin <= 3.4.32 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.

branda | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-102375 — WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability

Subscriber Broken Access Control in Optimole <= 4.2.14 versions.

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.8 CRITICAL
CVE-2026-100512 — WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability

Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-100510 — WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-75969 — PTZOptics Missing Authentication in Firmware Upload

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware up…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-62308 — Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoi…

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to a…

tugtainer | Remote | Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.8 CRITICAL
CVE-2026-55494 — Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SE…

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not c…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.4 CRITICAL
CVE-2026-55181 — Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oid…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.6 HIGH
CVE-2026-55177 — CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched…

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a f…

Remote | Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.0 CRITICAL
CVE-2026-55176 — Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET`…

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticat…

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.3 HIGH
CVE-2026-46711 — Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfil…

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Mach…

| Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.6 HIGH
CVE-2026-19553 — SSLContext.wrap_bio() missing validation of server_hostname parameter

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname ar…

python cpython cpython | Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14957 Results