Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-87004 — Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes t…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-55224 — MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other…

mineadmin | Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
10.0 CRITICAL
CVE-2026-55107 — Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → pub…

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-par…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-55094 — Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` a…

Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskclu…

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.8 HIGH
CVE-2026-53605 — Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS…

| Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-103500 — Heap buffer overflow opening large email

An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, an…

thunderbird | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.9 MEDIUM
CVE-2026-103476 — yii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-download

yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers ca…

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.3 CRITICAL
CVE-2026-103475 — yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can …

Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-103474 — yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE

yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scri…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.2 CRITICAL
CVE-2026-103473 — Deno 2.7.0 through 2.9.7 Command Injection via node:child_process

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS comman…

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-103472 — restbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame Buffering

restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attacke…

Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-103471 — restbed through 5.0.0 Denial of Service via Unbounded Header Buffering

restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and s…

Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.4 HIGH
CVE-2026-103446 — WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments

Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extens…

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.2 LOW
CVE-2026-103445 — Stored XSS through PageForms #autoedit redirect links

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.2 LOW
CVE-2026-103440 — pagetriagelist discloses suppressed reviewer usernames

Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriag…

Remote | Information Disclosure
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.3 LOW
CVE-2026-103439 — Various rawParams() and escaped() updates to prevent XSS in Wikibase extension

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affe…

| Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.3 LOW
CVE-2026-103438 — Various rawParams() and escaped() updates to prevent XSS in Wikistories extension

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue …

| Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103437 — ReadingLists imported metadata permits JavaScript URL XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects Medi…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.3 MEDIUM
CVE-2026-103399 — Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the bod…

enterprise_linux enterprise_linux | Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-102397 — WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14940 Results