Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-103276 — Ghost before 6.20.0 File Read via URL Encoding Bypass

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL encoding to bypa…

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-103275 — Ghost 5.42.2 before 6.58.0 Password Hash Disclosure

Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.pa…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-103274 — Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settin…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-103273 — Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff cred…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-103272 — Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API

Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in A…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-103271 — Ghost 4.0.0 before 6.63.0 Restricted Content Bypass

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly qu…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-103269 — Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts

Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-103268 — Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspende…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-103267 — Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-103266 — Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification

Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription to an existing member, modify th…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-103265 — Fleet before 4.89.0 Information Disclosure via MDM Command Results

Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other team…

fleet | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.1 CRITICAL
CVE-2026-103264 — Fleet before 4.87.0 Authentication Bypass via Device Identifiers

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthe…

fleet | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.9 MEDIUM
CVE-2026-103263 — Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a sym…

tornado | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-103262 — Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. A…

tornado | Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-103261 — Tornado before 6.5.9 Denial of Service via Query String

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query…

tornado | Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.0 MEDIUM
CVE-2026-103260 — n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verific…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-103259 — n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capab…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.8 MEDIUM
CVE-2026-103258 — n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters …

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-103257 — n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can…

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-103256 — n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated…

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 15066 Results