Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97260 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | Oct 01, 2026 |
| CVE-2026-97258 | MEDIUM | 6.5 | Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. | Oct 01, 2026 |
| CVE-2026-97251 | MEDIUM | 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | Oct 01, 2026 |
| CVE-2026-95588 | HIGH | 8.6 | Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. | Oct 01, 2026 |
| CVE-2026-95137 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not … | Oct 01, 2026 |
| CVE-2026-94390 | HIGH | 7.2 | Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | Oct 01, 2026 |
| CVE-2026-79900 | MEDIUM | 6.5 | boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name … | Oct 01, 2026 |
| CVE-2026-79899 | HIGH | 7.9 | Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local … | Oct 01, 2026 |
| CVE-2026-79898 | CRITICAL | 9.1 | Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP … | Oct 01, 2026 |
| CVE-2026-67106 | MEDIUM | 5.3 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker … | Oct 01, 2026 |
| CVE-2026-67105 | HIGH | 7.4 | HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic … | Oct 01, 2026 |
| CVE-2026-67104 | MEDIUM | 5.3 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the … | Oct 01, 2026 |
| CVE-2026-62073 | HIGH | 7.5 | Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | Oct 01, 2026 |
| CVE-2026-62071 | CRITICAL | 9.3 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | Oct 01, 2026 |
| CVE-2026-56599 | LOW | 2.2 | HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as … | Oct 01, 2026 |
| CVE-2026-56589 | HIGH | 7.2 | HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within … | Oct 01, 2026 |
| CVE-2026-103752 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | Oct 01, 2026 |
| CVE-2026-103687 | HIGH | 7.3 | A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component … | Oct 01, 2026 |
| CVE-2026-103347 | MEDIUM | 5.3 | Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | Oct 01, 2026 |
| CVE-2026-103068 | HIGH | 8.8 | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | Oct 01, 2026 |
| CVE-2026-103004 | UNKNOWN | — | Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With … | Oct 01, 2026 |
| CVE-2026-102378 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | Oct 01, 2026 |
| CVE-2026-100517 | HIGH | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | Oct 01, 2026 |
| CVE-2026-100514 | HIGH | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | Oct 01, 2026 |
| CVE-2024-58388 | HIGH | 7.5 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the … | Oct 01, 2026 |