Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-75973 — Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured

Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provide…

tomcat | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-73581 — Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate u…

Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apac…

tomcat | Cryptography
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-15358 — Path Traversal Vulnerability

ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-14913 — SQL Injection vulnerability

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.6 HIGH
CVE-2026-12370 — Remote Code Execution Vulnerability

ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet process…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.3 MEDIUM
CVE-2026-96456 — Reachy Mini Bluetooth PIN authentication can be bypassed by racing an authenticated device

The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride alon…

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-96455 — Reachy Mini daemon allows unauthenticated remote code execution through the app installat…

The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler'…

| Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-96442 — Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920

A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-90950 — Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form

The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users …

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-87978 — Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscript…

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to mark arbitrary WooCommerce …

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
3.7 LOW
CVE-2026-87848 — MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure

The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-87071 — Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthen…

forminator_forms | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-87070 — Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing

The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it…

forminator_forms | Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.6 MEDIUM
CVE-2026-86612 — Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Da…

The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have …

ninja_tables | Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.8 MEDIUM
CVE-2026-86604 — GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation

The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expanding them which, in a non-default configuration, allows unauthenticated users t…

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-86601 — WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Cont…

The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to h…

wp_recipe_maker | Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.9 MEDIUM
CVE-2026-5696 — Multiple vulnerabilities in the Microweber administration panel

Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attac…

administration_panel | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.4 HIGH
CVE-2026-5695 — Multiple vulnerabilities in the Microweber administration panel

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit t…

administration_panel | Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-96454 — Pake grants unrestricted IPC access to every HTTPS origin loaded in generated applications

Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrust…

pake | Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-96443 — Apache Doris: JDBC driver URL validation bypass leads to remote code execution

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

doris | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14290 Results