Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-108854 — Wanwu before 0.6.3 IDOR AppKey Deletion via DELETE /v1/appspace/app/key

Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows any authenticated enabled user to delete other users' legacy AppKeys by supplying a numeric apiId. Attackers …

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.1 HIGH
CVE-2026-108853 — UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying t…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.7 MEDIUM
CVE-2026-108852 — Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass

Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attacke…

deepchat | Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108851 — phpMyFAQ through 4.1.10 Missing Authorization via MCP Server faq_search Tool

phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies…

phpmyfaq | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108850 — Company Research Agent through 2.2.0 SSRF via /generate-pdf ReportLab Markup

Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph…

Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108839 — thClaws through 0.141.0 Symlink Following File Write via POST /v1/inputs

thClaws through 0.141.0 contains a link-following vulnerability in the post_inputs handler of the v1 API POST /v1/inputs endpoint that allows writes outside the workspace by following symlinks. Attac…

Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.3 HIGH
CVE-2026-108699 — hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins

hyper-mcp through 0.8.3 contains an improper signature verification vulnerability that allows attackers to load malicious WebAssembly plugins because cosign_verify_args() accepts any signer identity …

Remote | Misconfiguration
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.3 HIGH
CVE-2026-108698 — hyper-mcp through 0.8.3 OCI Plugin Signature Verification TOCTOU Race Condition

hyper-mcp through 0.8.3 contains a signature verification bypass vulnerability in load_wasm in src/wasm/oci.rs that verifies the Cosign signature of a separately resolved tag rather than the loaded m…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108697 — CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction

CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips t…

coreshop | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.3 MEDIUM
CVE-2026-108681 — zhayujie CowAgent Web Console web_channel.py denial of service

A security flaw has been discovered in zhayujie CowAgent up to 2.1.7. Impacted is an unknown function of the file channel/web/web_channel.py of the component Web Console. The manipulation of the argu…

cowagent | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.6 HIGH
CVE-2026-108760 — LlamaFarm through 0.0.34 Unauthenticated API Exposed on All Interfaces

LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-…

| Misconfiguration
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.6 HIGH
CVE-2026-108759 — mistral.rs 0.9.0 through 0.9.4 Sandbox Escape via Symlink Following in mistralrs-code-exec

mistral.rs 0.9.0 through 0.9.4 contains a link following vulnerability in mistralrs-code-exec that allows sandboxed shell code to read and overwrite files outside the sandbox via symlinks. Attackers …

mistral.rs | Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.8 HIGH
CVE-2026-108758 — Easy!Appointments through 1.6.0 Authorization Bypass via booking/register Endpoint

Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id wi…

easyappointments | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108757 — Nexting pinclaw through 0.3.0 Missing Authentication via POST /pinclaw/send

Nexting pinclaw OpenClaw channel plugin through 0.3.0 contains a missing authentication vulnerability in src/core/http-router.ts that skips the authToken check on POST /pinclaw/send. Unauthenticated …

| Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108756 — Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes

Abilityai Trinity through 0.9.5 contains a missing authorization vulnerability in the Telegram router that allows agent-scoped MCP API keys to perform human-only binding operations. Attackers control…

trinity | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108755 — Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint

Hatchet through 0.110.5 contains an allocation of resources without limits vulnerability that allows unauthenticated attackers to exhaust memory via the SNS ingestion endpoint. Attackers can send arb…

hatchet | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108754 — GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key p…

| Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
9.4 CRITICAL
CVE-2026-108753 — Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose

Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can…

agnai | Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108752 — JupyterHub through 6.0.1 OAuth Client ID Collision via Unescaped Hyphen

JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Att…

jupyterhub | Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.8 MEDIUM
CVE-2026-108751 — MoAI-ADK through 3.1.2 Symlink Following via moai init Template Deployer

MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked …

| Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 13696 Results