Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.6 HIGH
CVE-2026-105076 — WordPress Vitepos plugin <= 3.6.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a throu…

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.8 MEDIUM
CVE-2026-44038 — Global buffer out-of-bounds read in DCMTK JPEG Huffman decoding

A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_…

dcmtk | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-44037 — Uncontrolled recursion in DCMTK JSON reader allows denial of service

Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an atta…

dcmtk | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-44036 — Uncontrolled recursion in DCMTK xml2dcm allows denial of service

Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows …

dcmtk | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-44035 — Uncontrolled recursion in DCMTK DICOMDIR parsing allows denial of service

Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a…

dcmtk | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.8 MEDIUM
CVE-2026-44034 — Heap out-of-bounds read in DCMTK RLE decodeFrame()

A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a c…

dcmtk | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-44033 — Uncontrolled recursion in the DCMTK bundled XML parser allows denial of service

Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service…

dcmtk | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-44031 — Uncontrolled recursion in the DCMTK DICOM dataset parser allows unauthenticated remote de…

Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exha…

dcmtk | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.3 MEDIUM
CVE-2026-102783 — Joomla Extension - balbooa.com - Path Traversal in image preview Gridbox < 2.20.4.0

Joomla Extension - balbooa.com - Path Traversal in image preview Gridbox < 2.20.4.0 - Gridbox contains the same prefix-only containment logic in its site UploaderHelper . The showImage action resolve…

Remote | Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-102784 — Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. add…

gridbox | Remote | Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.8 HIGH
CVE-2026-62142 — WordPress WP 2FA plugin <= 4.1.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.

wp_2fa | Remote | Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-105878 — WordPress YITH WooCommerce Product Bundles plugin <= 2.29.0 - Broken Access Control vulne…

Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-106603 — WordPress HollerBox plugin <= 2.3.14 - Insecure Direct Object References (IDOR) vulnerabi…

Authorization Bypass Through User-Controlled Key vulnerability in Groundhogg HollerBox holler-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HollerBox:…

hollerbox | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-66479 — WordPress WPComplete plugin <= 2.9.5.6 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.

Remote | Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-106600 — WordPress GiveWP plugin <= 4.18.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through 4.18.0.

givewp | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.1 CRITICAL
CVE-2026-92555 — Database Credentials Disclosure in AKIN Software's AKINSOFT WOLVOX Control Panel

Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resource…

Remote | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.8 HIGH
CVE-2026-19083 — IDOR in AKIN Software's OctoCloud

Authorization bypass through User-Controlled key vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. OctoCloud allows Accessing Functionality Not Properly Constrained by…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107587 — Improper Certificate Validation in hMailServer

Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to have S/MIME-encrypted mail that the account later sends…

Remote | Cryptography
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.4 HIGH
CVE-2026-107584 — Not Failing Securely ('Failing Open') in hMailServer

Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open when applying DANE (RFC 7672) to outbound SMTP delivery. The server's validating DNSSEC resolver treated a TLSA or MX lookup that did not …

Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107583 — Inefficient Algorithmic Complexity in hMailServer

Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15585 Results