Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-102375 — WordPress Optimole plugin <= 4.2.14 - Broken Access Control vulnerability

Subscriber Broken Access Control in Optimole <= 4.2.14 versions.

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.8 CRITICAL
CVE-2026-100512 — WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability

Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.

Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-100510 — WordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-75969 — PTZOptics Missing Authentication in Firmware Upload

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware up…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-62308 — Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoi…

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to a…

tugtainer | Remote | Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.8 CRITICAL
CVE-2026-55494 — Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SE…

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not c…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.4 CRITICAL
CVE-2026-55181 — Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oid…

tugtainer | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.6 HIGH
CVE-2026-55177 — CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched…

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a f…

Remote | Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.0 CRITICAL
CVE-2026-55176 — Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET`…

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticat…

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.3 HIGH
CVE-2026-46711 — Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfil…

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Mach…

| Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.6 HIGH
CVE-2026-19553 — SSLContext.wrap_bio() missing validation of server_hostname parameter

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname ar…

python cpython cpython | Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.2 CRITICAL
CVE-2026-19445 — Use-after-free of a server-side SSLContext when sni_callback switches contexts

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certi…

python cpython cpython | Remote | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103444 — Stored XSS through system messages in WikiForum

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki …

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103443 — API permits session-seeded javascript URL XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements.…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.5 MEDIUM
CVE-2026-103241 — vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service

A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a ma…

vllm | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-103233 — AdithyaYelloju Restaurant-Management-System Admin Area admin authorization

A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the c…

restaurant-management-system | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.5 HIGH
CVE-2026-103232 — AdithyaYelloju Restaurant-Management-System table_booking.php mysqli_query sql injection

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.ph…

restaurant-management-system | Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.4 CRITICAL
CVE-2026-102490 — Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

zammad | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.4 CRITICAL
CVE-2026-102489 — Undisclosed RCE in Zammad v6.3 and higher

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.…

zammad | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-80490 — Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length…

Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING ty…

| Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14960 Results