Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-39760 — WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-39723 — WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-39599 — WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vulnerability

Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-32582 — WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability

Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-32576 — WordPress Faktur Pro for WooCommerce plugin <= 3.2.1 - Insecure Direct Object References …

Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-105775 — vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds

A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component …

vllm | Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.0 MEDIUM
CVE-2026-105708 — imgproxy SVG svg.go sanitizeElement cross site scripting

A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation…

imgproxy | Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105072 — WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.5 MEDIUM
CVE-2026-105707 — uptrace user_handler.go Login information exposure

A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to informati…

uptrace | Remote | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.0 MEDIUM
CVE-2026-105706 — SourceCodester Drug Recommendation System cross-site request forgery

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be pe…

drug_recommendation_system | Remote | Cross-Site Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.0 MEDIUM
CVE-2026-105705 — SourceCodester Drug Recommendation System add_drug.php cross site scripting

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site …

drug_recommendation_system | Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105704 — SourceCodester Drug Recommendation System Auth Guard improper authentication

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to impro…

drug_recommendation_system | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.8 MEDIUM
CVE-2026-105703 — PHPGurukul User Registration & Login and User Management System Change Password change-pa…

A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.5 MEDIUM
CVE-2026-105621 — jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDe…

A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.ja…

jsherp | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.3 LOW
CVE-2026-105611 — chillzhuang SpringBlade User Detail Endpoint RoleController.java improper authorization

A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleCont…

springblade | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.8 MEDIUM
CVE-2026-105610 — chillzhuang SpringBlade Parameter Submit Management ParamController.java improper authori…

A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/Pa…

springblade | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-105573 — newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logic error

A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quanti…

newbee-mall | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-105572 — PickMall Lilishop Buyer Invoice List receipt authorization

A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argume…

pickmall_lilishop | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105571 — PickMall Lilishop Mobile Binding bindMobile improper authorization

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of…

pickmall_lilishop | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-105487 — yogeshojha reNgine listTargets Endpoint tasks.py subdomain_discovery os command injection

A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint.…

rengine | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 14561 Results