Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-102994 — pypdf: Possible long runtimes/large memory usage when parsing indirect objects

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whites…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-102993 — pypdf: Possible large memory usage when retrieving Roman page labels

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively la…

pypdf | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
9.2 CRITICAL
CVE-2026-102992 — piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadB…

piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applic…

Remote
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-102991 — Mako: Path traversal via drive-letter URI on Windows in TemplateLookup

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/temp…

mako | Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.2 HIGH
CVE-2026-102990 — basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing p…

basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LIN…

basic-ftp | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.5 HIGH
CVE-2026-101885 — ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path

ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convinc…

| Path Traversal
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-101884 — OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Atta…

openclaw | Remote | Injection
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
5.4 MEDIUM
CVE-2026-101883 — OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers w…

openclaw | Remote | Server-Side Request Forgery
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-101882 — OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundl…

openclaw | Remote | Authorization
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-101881 — OpenClaw Windows Node before 2026.7.1 Denial of Service

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attack…

openclaw | Remote | Denial of Service
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-101880 — OpenClaw Windows Node before 2026.7.1 Authorization Bypass

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators o…

openclaw | Remote | Authorization
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-101879 — OpenClaw Windows Node before 2026.7.1-3 Missing Authorization

OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera sna…

openclaw | Remote | Authorization
Sep 30, 2026 Oct 01, 2026
Sep 30, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-97291 — WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vul…

Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-97290 — WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.36 - Cross…

Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-97265 — WordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a th…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.2 HIGH
CVE-2026-97256 — WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerability

Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-94171 — WordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.

curcy | Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.1 HIGH
CVE-2026-87004 — Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes t…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-55224 — MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other…

mineadmin | Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
10.0 CRITICAL
CVE-2026-55107 — Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → pub…

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-par…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14952 Results