Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-96882 — TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authori…

A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/…

lin-cms-spring-boot | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-97149 — OpenStack Swift TempURL Middleware Unauthorized Object Access Vulnerability

In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of dis…

swift | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.6 HIGH
CVE-2026-97056 — SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass

SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.2 CRITICAL
CVE-2026-97055 — SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret

SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and …

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.5 MEDIUM
CVE-2026-96880 — TaleLin lin-cms-spring-boot book Endpoint BookController.java getBook improper authorizat…

A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the co…

lin-cms-spring-boot | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.0 MEDIUM
CVE-2026-96810 — huanzi-qch base-admin Add User CommonController.java save cross site scripting

A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-96803 — java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMOImpl.fallBac…

A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such man…

microcommunity | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-96777 — Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection

A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.adm_server.php?r=adm/userselector/getData of the c…

lms | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.8 CRITICAL
CVE-2026-18467 — Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation…

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equal…

paytium | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-96881 — TaleLin lin-cms-spring-boot book Endpoint BookController.java getBooks improper authoriza…

A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of t…

lin-cms-spring-boot | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-96774 — SPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.t…

A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of the component Configuratio…

Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-96773 — Intelliants Subrion CMS Login Page login.php authorize redirect

A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::authorize of the file front/login.php of the component Login Page. This manipul…

subrion_cms | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.5 MEDIUM
CVE-2026-96772 — Intelliants Subrion CMS actions.json assign-owner information disclosure

A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of the argument q results in i…

subrion_cms | Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-96764 — kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources

A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a m…

mooncake | Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.4 MEDIUM
CVE-2026-96763 — kvcache-ai mooncake MountSegment Request Processing segment.cpp access control

A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the compo…

mooncake | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-96762 — kvcache-ai mooncake RPC Path UnmountSegment authorization

A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_i…

mooncake | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-96751 — pmTicket Project-Management-Software add_project.php setSync sql injection

A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipu…

project-management-software | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-96739 — SEMCMS KindEditor Upload upload_json.php cross site scripting

A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation o…

semcms | Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.9 CRITICAL
CVE-2026-93577 — Integer Overflow or Wraparound in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authentic…

gitlab | Remote | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.4 MEDIUM
CVE-2026-92874 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authentic…

gitlab | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14346 Results