Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-104390 — WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability

Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27.

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-103075 — WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in WPMU DEV Hustle wordpress-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hustle: from n/a through 7.8.14.2.

hustle | Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-97720 — Apache Impala: Impala Executor Webserver Auth Bypass

Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserv…

impala | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-93684 — Apache Impala: Stored XSS in Impala query plans

An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query pla…

impala | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.1 MEDIUM
CVE-2026-93026 — Veeam Backup & Replication Unauthorized Configuration Modification Vulnerability

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
0.0 NA
CVE-2026-90466 — Apache Impala: Path traversal executes JARs outside trusted paths

Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The star…

impala | Path Traversal
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.2 HIGH
CVE-2026-89417 — OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthenticated Store…

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, an…

omgf | Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-5703 — Path Traversal in Satel Iberia SenNet Datalogger Serie 200

Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any di…

Remote | Path Traversal
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.3 HIGH
CVE-2026-58069 — Veeam Backup & Replication Arbitrary File Read Vulnerability

This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.

veeam_backup_\&_replication backup_and_replication | Remote | Information Disclosure
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.8 MEDIUM
CVE-2026-58068 — Veeam Agent for Microsoft Windows Arbitrary Process Termination Vulnerability

This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.

veeam_agent_for_windows | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.1 HIGH
CVE-2026-19186 — Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write

ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame i…

zephyr zephyr | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
8.8 HIGH
CVE-2026-15894 — Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement

The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the sourc…

zephyr zephyr | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-107104 — Unsafe Deserialization Vulnerability in Manacle Technologies ERP System

This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-107103 — SQL Injection Vulnerability in Manacle Technologies ERP System

This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulner…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-107102 — Account Takeover Vulnerability in Manacle Technologies ERP System

This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API endpoint. An unauthenticated remote attacker could …

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-103416 — Eclipse ThreadX NetX Duo TLS 1.3 Handshake Out-of-Bounds Write

Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest o…

threadx_netx_duo | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-102782 — Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Member…

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access contr…

Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.9 MEDIUM
CVE-2026-102781 — Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slid…

Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.4 CRITICAL
CVE-2025-64393 — Veeam Backup & Replication Remote Code Execution Vulnerability

This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server.

Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.8 MEDIUM
CVE-2025-64392 — Veeam Backup Enterprise Manager Cross-Site Scripting Vulnerability

This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.

Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15424 Results