Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-105775 — vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds

A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component …

vllm | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.2 HIGH
CVE-2026-75962 — Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_emai…

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email…

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.5 MEDIUM
CVE-2026-105707 — uptrace user_handler.go Login information exposure

A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to informati…

uptrace | Remote | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.0 MEDIUM
CVE-2026-105706 — SourceCodester Drug Recommendation System cross-site request forgery

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be pe…

drug_recommendation_system | Remote | Cross-Site Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.0 MEDIUM
CVE-2026-105705 — SourceCodester Drug Recommendation System add_drug.php cross site scripting

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site …

drug_recommendation_system | Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105704 — SourceCodester Drug Recommendation System Auth Guard improper authentication

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to impro…

drug_recommendation_system | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105708 — imgproxy SVG svg.go sanitizeElement cross site scripting

A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation…

imgproxy | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-97300 — WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-41563 — WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.

Remote | Information Disclosure
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-41558 — WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA Bypass vulne…

Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-39789 — WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.1 HIGH
CVE-2026-39760 — WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-39723 — WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-39599 — WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vulnerability

Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-32582 — WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability

Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-32576 — WordPress Faktur Pro for WooCommerce plugin <= 3.2.1 - Insecure Direct Object References …

Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105072 — WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.

Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.8 MEDIUM
CVE-2026-105703 — PHPGurukul User Registration & Login and User Management System Change Password change-pa…

A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.5 MEDIUM
CVE-2026-105621 — jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDe…

A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.ja…

jsherp | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.3 LOW
CVE-2026-105611 — chillzhuang SpringBlade User Detail Endpoint RoleController.java improper authorization

A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleCont…

springblade | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 14536 Results