Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-92705 — Aegisub executes arbitrary code through automatically loaded Automation scripts

Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects withou…

| Supply Chain
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-62376 — Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables acc…

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. …

vikunja | Remote | Cryptography
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-62367 — Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-accou…

Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, V…

vikunja | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.1 HIGH
CVE-2026-57458 — Vikunja: Scoped API token can mint unrestricted OAuth session credentials

Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAu…

vikunja | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108266 — Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS …

Privasys rustls is a maintained fork of the rustls TLS library that adds RA-TLS challenge and channel-binding support. Prior to privasys-v0.8.1, the fork emitted RA-TLS challenge certificates whose q…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108265 — enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session

Enclave OS Mini is a Rust-based runtime for confidential applications inside Intel SGX enclaves. Prior to wasm-v0.40.0, the SGX runtime's RA-TLS challenge certificate path placed the certificate publ…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-108264 — Wizarr: Authenticated Server-Side Template Injection (SSTI) in wizard step rendering lead…

Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles …

Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.9 CRITICAL
CVE-2026-108263 — Astron Agent: Unsandboxed code-node leads to cross-tenant RCE

Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run select…

astron-agent | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-108261 — TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment

Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled has…

tinacms\/graphql | Remote | Server-Side Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.6 HIGH
CVE-2026-108260 — @tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without s…

Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anch…

tinacms\/graphql | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.2 HIGH
CVE-2026-108259 — Tina: Code injection via unescaped Git branch name in generated client source

Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and…

tinacms\/graphql tinacms\/cli | Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.9 MEDIUM
CVE-2026-108258 — Shiny for Python - Path traversal in bookmark restore

Shiny for Python is a framework for building interactive web applications in Python. From 1.4.0 until 1.6.4, bookmark restore accepts a client-supplied state_id and joins it into the server-side shin…

Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.4 MEDIUM
CVE-2026-107857 — Mindwtr: Cloud token and WebDAV password stored in plaintext on mobile

Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncS…

| Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.5 MEDIUM
CVE-2026-107856 — CiviForm: Trusted-Intermediary IDOR discloses any citizen's name and email

CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies…

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2026-107854 — Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (miss…

Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the ser…

jexactyl | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-107852 — Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as ful…

Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when paymen…

jexactyl | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.3 MEDIUM
CVE-2026-107851 — Contao: Improper access control in the table access voter

Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decision…

contao | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.3 MEDIUM
CVE-2026-107850 — Contao: Improper access control in the preview links module

Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\CoreBundle\Security\Voter\DataContainer\PreviewAccessVoter…

contao | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.5 LOW
CVE-2026-107848 — Contao: Cross-site request forgery in custom backend actions

Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act pa…

contao | Remote | Cross-Site Request Forgery
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-108269 — ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session

Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was …

| Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14134 Results