Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-102382 MEDIUM 4.3 Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a … Oct 01, 2026
CVE-2026-102381 MEDIUM 5.3 Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. Oct 01, 2026
CVE-2026-102379 HIGH 8.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder … Oct 01, 2026
CVE-2026-94276 UNKNOWN — Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token … Oct 01, 2026
CVE-2026-94269 UNKNOWN — Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted … Oct 01, 2026
CVE-2026-94250 UNKNOWN — Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via … Oct 01, 2026
CVE-2026-94220 UNKNOWN — Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link … Oct 01, 2026
CVE-2026-94212 UNKNOWN — Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under … Oct 01, 2026
CVE-2026-103858 UNKNOWN — MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing … Oct 01, 2026
CVE-2026-103754 MEDIUM 5.9 A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker … Oct 01, 2026
CVE-2026-103680 LOW 3.1 A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When … Oct 01, 2026
CVE-2026-103679 MEDIUM 6.5 A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing … Oct 01, 2026
CVE-2026-103678 MEDIUM 5.4 A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. … Oct 01, 2026
CVE-2026-103336 MEDIUM 5.3 Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate … Oct 01, 2026
CVE-2026-88789 HIGH 8.6 Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before … Oct 01, 2026
CVE-2026-82806 UNKNOWN — Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, … Oct 01, 2026
CVE-2026-78242 UNKNOWN — Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log … Oct 01, 2026
CVE-2026-103758 HIGH 8.1 Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ … Oct 01, 2026
CVE-2026-103757 HIGH 7.7 Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. … Oct 01, 2026
CVE-2026-103353 MEDIUM 5.3 Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. Oct 01, 2026
CVE-2026-103292 HIGH 8.0 Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. … Oct 01, 2026
CVE-2026-103291 MEDIUM 6.4 Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP … Oct 01, 2026
CVE-2026-103290 LOW 3.8 Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may … Oct 01, 2026
CVE-2026-103289 MEDIUM 6.5 Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized … Oct 01, 2026
CVE-2026-103288 MEDIUM 6.5 Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can … Oct 01, 2026