Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-103956 — Missing authentication for critical function in Loom for AWS

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, includin…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2023-54405 — H3C CVM Unauthenticated File Upload via fileUpload/upload Token

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allow…

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2020-37278 — Weaver e-Bridge Unauthenticated Arbitrary File Read via saveYZJFile

Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl par…

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2014-125130 — CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_download.php

CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve se…

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-61586 — Copernik XML Factory XML External Entity Injection

Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.…

| Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
0.0 NA
CVE-2026-59265 — Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system tak…

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. …

openoffice | Injection
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-104861 — probe-image-size: Quadratic-time Denial of Service in the SVG Parser

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.3 HIGH
CVE-2026-104859 — Nx: OS command injection in the @nx/docker release pipeline

Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker pus…

| Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
2.0 LOW
CVE-2026-104855 — Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state

Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invali…

wasmtime | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.3 CRITICAL
CVE-2026-102795 — Apache Traffic Server: SNI to Host header matching policy is not properly enforced

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade…

traffic_server | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-102626 — LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question a…

An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When anoth…

limesurvey | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.5 HIGH
CVE-2026-104854 — Nx daemon and plugin worker sockets are accessible to other local users

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary loc…

| Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.8 MEDIUM
CVE-2026-104853 — Nx: Path traversal in nx migrate package-migrations extraction

Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest w…

| Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-104851 — fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execut…

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.5 CRITICAL
CVE-2026-104849 — Tinypool: Prototype Pollution Gadget to RCE in run() options

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own prop…

Remote | Supply Chain
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.5 CRITICAL
CVE-2026-104848 — Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in d…

Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.1 HIGH
CVE-2026-96613 — Missing Authorization in Meari IoT Cloud Platform OpenAPI Service

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. Thi…

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94544 — Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and …

Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regula…

next.js | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.3 MEDIUM
CVE-2026-94543 — Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental S…

next.js | Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
2.3 LOW
CVE-2026-94486 — Next.js: Information disclosure in the Next.js development server's Model Context Protoco…

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting…

next.js | Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 15050 Results