Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-107820 — x64dbg-MCP Server vulnerable to pre-authentication denial of service through Content-Leng…

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Conten…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.9 MEDIUM
CVE-2026-107819 — MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verifi…

MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authen…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.4 HIGH
CVE-2026-107818 — MariaDB: environment injection via wsrep bootstrap in the mariadb.service file

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster dur…

Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.4 MEDIUM
CVE-2026-107817 — MariaDB: mysql_json plugin OOB reads

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contai…

| Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.4 MEDIUM
CVE-2026-107816 — MariaDB: `qc_info` plugin can do OOB reads if query contains \0

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the qc_info plugin could be confused by a query containing embe…

Remote | Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-75597 — pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensiti…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 tem…

pyload | Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-75347 — EIPStackGroup OpENer Expired Pointer Dereference

EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attac…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.8 HIGH
CVE-2026-55797 — Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it cl…

argo-cd | Remote | Injection
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-48484 — pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termin…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole c…

pyload | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.5 MEDIUM
CVE-2026-42695 — WordPress FV Flowplayer Video Player plugin <= 7.5.54.7212 - Cross Site Scripting (XSS) v…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Flowplayer Video Player fv-wordpress-flowplayer allows Stored XSS.This issue affec…

fv_flowplayer_video_player | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-108160 — AstronRPA through 1.1.6 Unsigned Update Installation via Plain-HTTP Feed

AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechan…

Remote | Supply Chain
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-108159 — AstronRPA through 1.1.6 RCE via Smart-Component Chat XSS and IPC Bridge

AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM outpu…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108158 — plugNmeet Server through 2.5.2 Path Traversal via /api/whiteboard/convert

plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Atta…

Remote | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.2 CRITICAL
CVE-2026-108157 — Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108156 — LobsterAI 2026.5.27 through 2026.9.23 Arbitrary Directory Deletion via Skill _meta.json

LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during…

lobsterai | Path Traversal
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.3 MEDIUM
CVE-2026-108119 — Busybox: busybox: tar extraction-root escape via deferred symlink/hardlink creation bypas…

A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains insi…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.5 MEDIUM
CVE-2026-108093 — Gimp: gimp: denial of service via null pointer dereference in xcf simulation parasite loa…

A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a speciall…

enterprise_linux enterprise_linux | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.5 HIGH
CVE-2026-107815 — MariaDB: one byte OOB write in DOS tables of the CONNECT engine

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary …

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2025-61560 — Argo CD SessionManager Race Condition Vulnerability

A race condition vulnerability in the SessionManager of CNCF: Cloud Native Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting and perform a brute force attack via repeated c…

argo-cd | Race Condition
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.4 MEDIUM
CVE-2016-20098 — Moderator Toolbox before 4.0.14 Stored XSS via Removal Reasons Configuration

Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HT…

Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14118 Results