Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-96451 — WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13…

ultimate_member | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.1 HIGH
CVE-2026-103342 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-e…

unlimited_elements_for_elementor | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-103065 — WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.…

Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-105122 — OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri

OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated…

openam | Remote | Server-Side Request Forgery
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-105121 — OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Aut…

openam | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-105120 — OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding d…

openam | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.6 HIGH
CVE-2026-105119 — OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, …

openam | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
4.7 MEDIUM
CVE-2026-105118 — OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoin…

openam | Remote | Misconfiguration
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-105117 — OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json…

openam | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-105116 — OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachab…

openam | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.8 HIGH
CVE-2026-105115 — OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. …

openam | Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-105114 — OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 au…

openam | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.1 HIGH
CVE-2026-105113 — Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock

Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four …

Remote | Denial of Service
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.0 MEDIUM
CVE-2026-105112 — Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints

Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can concurrently …

Remote | Race Condition
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.8 CRITICAL
CVE-2026-105105 — Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command…

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker w…

Remote | Authentication
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-104983 — Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversal

A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipula…

xreader xreader | Remote | Path Traversal
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-97873 — Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider

In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrus…

bc-java | Remote | Denial of Service
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.2 HIGH
CVE-2026-85515 — OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check

In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 se…

bc-java | Remote | Cryptography
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-71892 — CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys

In Bouncy Castle for Java before 1.86, the opt-in key-size validation on CMS key-transport recipients, org.bouncycastle.cms.jcajce.JceKeyTransRecipient.setKeySizeValidation(true), never ran for a mes…

bc-java | Remote | Cryptography
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.1 HIGH
CVE-2026-71891 — BLS12-381 key validation accepts a public key built on a foreign curve

In Bouncy Castle for Java before 1.86, BLS12_381BasicScheme.keyValidate, and so BLSPublicKeyParameters and every BasicScheme, MessageAugmentation and ProofOfPossession verify and aggregateVerify that…

bc-java | Remote | Cryptography
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 14794 Results