Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-102670 — Joyland AI enables HTTP

Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.

| Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102669 — Joyland AI hostname checking disabled

Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102668 — Joyland AI accepts TLS certificates without validation

The Joyland AI app accepts any TLS certificates from any server without validation.

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.0 CRITICAL
CVE-2026-102667 — Joyland AI WebView command injection

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitr…

| Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102666 — Joyland AI hard-coded credentials for push notifications

The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content …

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-102628 — Cadmos LTI exposure of sensitive information via debug mode

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GE…

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-100251 — Wormhole.app SSRF

Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to …

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-8618 — Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x…

A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fix…

| Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-84682 — TDDPv2 setProductVer Command Injection in Archer AX90

A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute…

| Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-55232 — Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oE…

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and nev…

vvveb | Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-55231 — Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read …

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel use…

vvveb | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-55230 — Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than c…

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a…

vvveb | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.1 CRITICAL
CVE-2026-55083 — DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHI…

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.6 MEDIUM
CVE-2026-27872 — EasyIO FG

- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.

Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.4 HIGH
CVE-2026-15911 — Confluent Kafka Python Improper TLS Certificate Validation

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

confluent-kafka | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.1 HIGH
CVE-2026-104059 — Lektor 3.3.14 CSRF via Admin API Endpoints

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-orig…

Remote | Cross-Site Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.3 MEDIUM
CVE-2026-104058 — Podgrab Missing Authentication on WebSocket /ws Endpoint

Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-104057 — Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshand…

Remote | Race Condition
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-104056 — CVE-2026-104056

Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all …

authlib | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-9032 — Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerabili…

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validat…

tapo_c200 tapo_c120 | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14904 Results