Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-105147 — SciPhi-AI R2R JWT Secret hard-coded credentials

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL…

r2r | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-97307 — WordPress Cost Calculator Builder plugin <= 4.0.17 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calcu…

cost_calculator_builder | Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.8 MEDIUM
CVE-2026-105146 — Comsenz Discuz! Admin Medal Moderation mod.php modmedalsubmit sql injection

A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php …

discuz | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.5 MEDIUM
CVE-2026-105145 — Weaviate Verba generate_stream Endpoint util.py get_environment information disclosure

A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_strea…

verba | Remote | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.1 HIGH
CVE-2026-97276 — WordPress WP Statistics plugin <= 14.16.14 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: fro…

wp_statistics | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.5 MEDIUM
CVE-2026-105144 — Drogon Static File Router StaticFileRouter.cc route path traversal

A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static File Router. Ex…

drogon | Remote | Path Traversal
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
6.5 MEDIUM
CVE-2026-105141 — topoteretes cognee JWT Signing Key get_api_auth_backend.py get_user_id_by_email hard-code…

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.p…

cognee | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
5.1 MEDIUM
CVE-2026-105137 — Laradock Build Process Dockerfile code download

A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without…

laradock | Remote | Supply Chain
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
9.3 CRITICAL
CVE-2026-103355 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-e…

unlimited_elements_for_elementor | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.1 HIGH
CVE-2026-103354 — WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.11.1 - Cross Site Scripting (X…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This i…

Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.1 HIGH
CVE-2026-103344 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-e…

unlimited_elements_for_elementor | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.1 HIGH
CVE-2026-103062 — WordPress TranslatePress plugin <= 3.3.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects Transl…

translatepress | Remote | Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-97332 — User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrit…

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through…

| Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-93549 — CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an at…

| Cross-Site Request Forgery
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-86817 — Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure…

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-…

five_star_business_profile_and_schema | Information Disclosure
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-17005 — Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allo…

| Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
10.0 CRITICAL
CVE-2026-105135 — InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation…

mindsearch | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
10.0 CRITICAL
CVE-2026-105134 — Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulat…

ahsaycbs | Remote | Injection
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
7.5 HIGH
CVE-2026-105133 — Ahsay AhsayCBS API ApiStructsAction.java checkSysPwd improper authentication

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation …

ahsaycbs | Remote | Authentication
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
0.0 NA
CVE-2026-104119 — Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as admini…

| Cross-Site Scripting
Oct 04, 2026 Oct 04, 2026
Oct 04, 2026
Oct 04, 2026
Showing 20 of 14343 Results