Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-63572 — Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files

Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a PKCS#12 (PFX) file…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-63571 — Attribute certificate path validation does not verify the attribute certificate's signatu…

Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-c…

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.1 HIGH
CVE-2026-63570 — Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links

Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted PKCS#12 file to an appli…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-18036 — NTRU leaks private key information by reducing secret values with a non-constant-time int…

In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried ou…

bc-java | Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-17508 — Password-based KDF cost parameters honoured unbounded from untrusted input across the rem…

In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a …

bc-java | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-17507 — MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range se…

In Bouncy Castle for Java before 1.86, the MLS implementation (org.bouncycastle.mls) holds RFC 9420's uint32 leaf_index in a signed int, so a wire value with the top bit set decodes to a negative num…

bc-java | Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-12951 — MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Para…

The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and in…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-103604 — Quadratic-time escaping when converting X.509 distinguished names to strings

Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows …

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-103603 — Unbounded HSS public key level count allows huge array allocation during signature verifi…

Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthentic…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-103602 — Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts

Improper certificate validation in PkixNameConstraintValidator in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or can obtain certificates from, a name-cons…

Remote | Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.2 HIGH
CVE-2026-103601 — CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after …

Release of unverified plaintext in the CCM (CcmBlockCipher) and DSTU 7624 CCM (KCcmBlockCipher) AEAD modes in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to obtai…

Remote | Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-103600 — Unbounded ASN.1 nesting depth causes process-terminating stack overflow

Uncontrolled recursion in the ASN.1 parser (Asn1InputStream, Asn1StreamParser) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of…

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-103426 — Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Para…

The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and including, 2.31.4 due to insufficient input sanitization an…

relevanssi | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-102772 — CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field

The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due t…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
3.1 LOW
CVE-2026-102002 — Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in For…

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the '…

otter_blocks | Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-100182 — Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin…

The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient in…

download_monitor | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-100107 — Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comm…

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitizat…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.3 MEDIUM
CVE-2026-97219 — MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter

The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status o…

mstore_api | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.9 CRITICAL
CVE-2026-93698 — Multilang Adminbin Command Injection

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.0 CRITICAL
CVE-2026-93697 — WHM Stored Cross-Site Scripting Vulnerability

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14915 Results