Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-101105 — code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_…

A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation Endpoint…

matrimonial_system | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-100753 — Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (…

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly …

Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.3 CRITICAL
CVE-2026-100752 — Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (F…

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listi…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-96740 — Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka …

A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without…

Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.6 HIGH
CVE-2026-75600 — FreePBX: Authenticated API generatedocs Host Command Injection

FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. A…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.6 HIGH
CVE-2026-55160 — Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer

Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server…

Remote | Server-Side Request Forgery
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.4 HIGH
CVE-2026-55157 — Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulner…

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-55156 — Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in …

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.6 HIGH
CVE-2026-54710 — FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclu…

FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP f…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.6 HIGH
CVE-2026-54708 — Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module

FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on t…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.7 HIGH
CVE-2026-54675 — FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Mod…

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.6 HIGH
CVE-2026-54674 — Authenticated Command Injection in FreePBX UCP Interface

FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typic…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.1 CRITICAL
CVE-2026-49994 — Bluehood: Missing authentication on Bluehood API routes when web auth is enabled

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devic…

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.7 HIGH
CVE-2026-45562 — FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrar…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-101913 — ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing S…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the co…

ip-address | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-101912 — ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as …

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings w…

ip-address | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-101911 — ip-address: Address6 builds a parse diagnostic proportional to the input with no length b…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded…

ip-address | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101910 — ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing S…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 loc…

ip-address | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.3 HIGH
CVE-2026-101909 — Axios: Prototype Pollution Gadget in axios toFormData Options

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplie…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101908 — Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original…

Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14257 Results