Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-76142 — Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface

Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

genian_nac genian_ztna | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.4 MEDIUM
CVE-2026-12241 — Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authoriz…

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly secure capability check on the 'save_met…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.5 MEDIUM
CVE-2026-103539 — ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication

A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java …

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103538 — ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrd…

A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-103536 — ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing au…

A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-96561 — AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter →…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missi…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-92245 — Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sens…

The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it poss…

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-91109 — Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authentic…

The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missi…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.5 MEDIUM
CVE-2026-103641 — Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder

A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HD…

Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103534 — David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Mode…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-92537 — Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' …

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tr…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-103533 — David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path travers…

A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php …

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
3.5 LOW
CVE-2026-101887 — BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS

BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the …

| Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.0 HIGH
CVE-2026-93495 — ASUS Motherboard Arbitrary Memory Access Vulnerability

Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.

| Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.4 CRITICAL
CVE-2026-14157 — ASUS Router Format String Vulnerability

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interfa…

router | Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.9 HIGH
CVE-2026-13313 — ASUS Router Active Debug Code Command Injection Vulnerability

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and enable the Telnet service, thereby e…

router | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-103532 — immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorizat…

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. T…

Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.5 MEDIUM
CVE-2026-103531 — OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow

A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr …

Remote | Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-103530 — decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manip…

Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-103592 — simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist …

Remote | Authorization
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
Showing 20 of 14971 Results