Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-105290 — feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php server-side reque…

A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint…

feelcrm-os | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.6 MEDIUM
CVE-2026-59788 — Stored XSS vulnerability in OAuth configuration form

The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media…

Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-59787 — SNMP trap injection in zabbix_trap_receiver.pl

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record target…

Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.9 MEDIUM
CVE-2026-59786 — Active agent heartbeat missing TLS check

Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report …

Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.1 MEDIUM
CVE-2026-59785 — Hidden host credentials inferable via multiselect.get filtering

Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whe…

| Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
2.3 LOW
CVE-2026-59783 — Server DoS via binary items

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MyS…

Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.9 MEDIUM
CVE-2026-59782 — JavaScript preprocessing memory disclosure

The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running …

Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-39763 — WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP…

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.6 MEDIUM
CVE-2026-19395 — An empty <img> attribute value in styled text triggers a parser error that halts the devi…

In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal …

qt_for_mcus | Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.0 MEDIUM
CVE-2026-105288 — feelec-yishu feelcrm-os Crm Endpoint functions.php index cross site scripting

A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component C…

feelcrm-os | Remote | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.5 MEDIUM
CVE-2026-105287 — feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql in…

A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpo…

feelcrm-os | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105286 — Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal

A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation o…

a3002mu | Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
10.0 CRITICAL
CVE-2026-105285 — Totolink A3002MU QoS Rule formIpQoS stack-based overflow

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation…

a3002mu | Remote | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-105289 — feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php htmlspecial…

A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the com…

feelcrm-os | Cross-Site Scripting
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.3 MEDIUM
CVE-2026-97071 — WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability

Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.

curcy | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-39721 — WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: fro…

starter_templates | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.8 HIGH
CVE-2026-19185 — Unvalidated user-supplied buffer pointers in the I3C do_ccc system call handler allow ker…

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validat…

zephyr zephyr | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
8.4 HIGH
CVE-2026-19184 — Out-of-bounds write in the NXP GAU ADC driver due to byte-versus-sample buffer size valid…

The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample coun…

zephyr zephyr | Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
10.0 CRITICAL
CVE-2026-105284 — Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipu…

a3002mu | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.8 MEDIUM
CVE-2026-105263 — Shaarli Admin Metadata Endpoint MetadataController.php MetadataController server-side req…

A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the compo…

shaarli | Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14287 Results