Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-15340 — Savannah lwIP SMTP client Classic Buffer Overflow

lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108125 — WordPress Post Author Authenticated SQLi

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This issue affects wp-post-author version 4.0.0 prior to 4.1.0.

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.9 MEDIUM
CVE-2026-108124 — WordPress Post Author Authenticated SQLi

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author. This issue affects wp-post-author before 4.1.0.

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-108109 — PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108108 — PHPNuxBill through 2025.3.20 CHAP Authentication Bypass via Password::chap_verify()

PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attack…

| Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-108107 — PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers…

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.7 HIGH
CVE-2026-108106 — Xerial snappy-java before 1.1.10.9 Unbounded Memory Allocation Denial of Service

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Atta…

snappy-java | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.2 HIGH
CVE-2026-108105 — Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request

Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs…

open5gs | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-108104 — Xerial snappy-java 1.1.7.4 before 1.1.10.10 Double Release of Pooled Buffers in SnappyFra…

Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can …

snappy-java | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.9 MEDIUM
CVE-2026-108103 — Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short …

open5gs | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.9 MEDIUM
CVE-2026-108102 — Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Volume Measurement IE

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers.…

open5gs | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-108101 — HortusFox through 6.3 Unrestricted File Upload via Plant Attachments

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under p…

hortusfox | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108100 — HortusFox before 6.2 SQL Injection via /api/locations/list include_info Parameter

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. …

hortusfox | Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.4 CRITICAL
CVE-2026-107806 — Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite

Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key mate…

nginx_ui | Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107805 — Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage

Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and sy…

nginx_ui | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-107804 — Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout

Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trus…

nginx_ui | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-105278 — Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials

The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate usin…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
1.9 LOW
CVE-2026-104117 — Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP gro…

A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/s…

illumos-gate | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
1.9 LOW
CVE-2026-104116 — Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enu…

A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt zonestat in other zones and to determine which zones are running. The zones…

illumos-gate | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-104115 — Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash th…

A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the n…

illumos-gate | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14134 Results