Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102382 | MEDIUM | 4.3 | Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a … | Oct 01, 2026 |
| CVE-2026-102381 | MEDIUM | 5.3 | Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | Oct 01, 2026 |
| CVE-2026-102379 | HIGH | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder … | Oct 01, 2026 |
| CVE-2026-94276 | UNKNOWN | — | Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token … | Oct 01, 2026 |
| CVE-2026-94269 | UNKNOWN | — | Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted … | Oct 01, 2026 |
| CVE-2026-94250 | UNKNOWN | — | Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via … | Oct 01, 2026 |
| CVE-2026-94220 | UNKNOWN | — | Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link … | Oct 01, 2026 |
| CVE-2026-94212 | UNKNOWN | — | Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under … | Oct 01, 2026 |
| CVE-2026-103858 | UNKNOWN | — | MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing … | Oct 01, 2026 |
| CVE-2026-103754 | MEDIUM | 5.9 | A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker … | Oct 01, 2026 |
| CVE-2026-103680 | LOW | 3.1 | A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When … | Oct 01, 2026 |
| CVE-2026-103679 | MEDIUM | 6.5 | A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing … | Oct 01, 2026 |
| CVE-2026-103678 | MEDIUM | 5.4 | A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. … | Oct 01, 2026 |
| CVE-2026-103336 | MEDIUM | 5.3 | Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate … | Oct 01, 2026 |
| CVE-2026-88789 | HIGH | 8.6 | Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before … | Oct 01, 2026 |
| CVE-2026-82806 | UNKNOWN | — | Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, … | Oct 01, 2026 |
| CVE-2026-78242 | UNKNOWN | — | Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log … | Oct 01, 2026 |
| CVE-2026-103758 | HIGH | 8.1 | Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ … | Oct 01, 2026 |
| CVE-2026-103757 | HIGH | 7.7 | Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. … | Oct 01, 2026 |
| CVE-2026-103353 | MEDIUM | 5.3 | Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14. | Oct 01, 2026 |
| CVE-2026-103292 | HIGH | 8.0 | Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. … | Oct 01, 2026 |
| CVE-2026-103291 | MEDIUM | 6.4 | Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP … | Oct 01, 2026 |
| CVE-2026-103290 | LOW | 3.8 | Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may … | Oct 01, 2026 |
| CVE-2026-103289 | MEDIUM | 6.5 | Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized … | Oct 01, 2026 |
| CVE-2026-103288 | MEDIUM | 6.5 | Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can … | Oct 01, 2026 |