Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-71890 — MLS external commit can remove an arbitrary group member

In Bouncy Castle for Java before 1.86, validation of an MLS (RFC 9420) external commit's proposal list, org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals, counted the proposals by t…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.7 HIGH
CVE-2026-71889 — PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate

In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.5…

bc-java | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.7 HIGH
CVE-2026-71888 — CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent

In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were p…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-71887 — OpenPGP data signature accepted from a signing subkey without cross-certification

In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-cert…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-71886 — OpenPGP certification accepted from a subkey without certification authority

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requi…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.2 CRITICAL
CVE-2026-71885 — MLS X.509 credential not bound to the LeafNode signature key

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's s…

bc-java | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-71883 — Native AES packet cipher returns the raw AES key on an alias

In Bouncy Castle for Java LTS before 2.73.13, the one-shot native packet ciphers for AES-CBC, CCM, CFB, CTR, GCM and GCM-SIV released the caller's key, IV and additional authenticated data arrays wit…

bc-java | Remote | Memory Corruption
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.9 MEDIUM
CVE-2026-18040 — HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-depe…

In Bouncy Castle for Java before 1.86, HQC leaked secret-derived data through two side channels: its GF(2^8) arithmetic used lookup tables indexed by field elements, making the cache line touched a f…

bc-java | Information Disclosure
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-92767 — Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient inpu…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.1 CRITICAL
CVE-2026-92084 — Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution v…

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to …

beaver_builder | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.0 MEDIUM
CVE-2026-104982 — Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal

A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB Fil…

xreader xreader | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-97660 — WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scriptin…

The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 du…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
4.3 MEDIUM
CVE-2026-97343 — Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link…

The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, an…

Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-96267 — WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'ful…

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient esc…

visitor_statistics | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.1 HIGH
CVE-2026-94505 — Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary …

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not…

Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-93896 — WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUEST_URI

The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) …

wpfront_notification_bar | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-93889 — Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_ma…

The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to i…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-92974 — Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_url' Paramet…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8…

photo_gallery | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.1 CRITICAL
CVE-2026-87115 — VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Dele…

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and…

Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-75028 — WPCafe <= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via 'food_menu_style…

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template sco…

wpcafe | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 14834 Results