Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97291 | HIGH | 8.8 | Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | Sep 30, 2026 |
| CVE-2026-97290 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | Sep 30, 2026 |
| CVE-2026-97265 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a … | Sep 30, 2026 |
| CVE-2026-97256 | HIGH | 7.2 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | Sep 30, 2026 |
| CVE-2026-94171 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. | Sep 30, 2026 |
| CVE-2026-87004 | HIGH | 8.1 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token … | Sep 30, 2026 |
| CVE-2026-55224 | UNKNOWN | — | MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and … | Sep 30, 2026 |
| CVE-2026-55107 | CRITICAL | 10.0 | Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, … | Sep 30, 2026 |
| CVE-2026-55094 | UNKNOWN | — | Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on … | Sep 30, 2026 |
| CVE-2026-53605 | HIGH | 7.8 | Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. … | Sep 30, 2026 |
| CVE-2026-103500 | UNKNOWN | — | An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in … | Sep 30, 2026 |
| CVE-2026-103476 | MEDIUM | 5.3 | yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate … | Sep 30, 2026 |
| CVE-2026-103475 | CRITICAL | 9.1 | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated … | Sep 30, 2026 |
| CVE-2026-103474 | HIGH | 8.8 | yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role … | Sep 30, 2026 |
| CVE-2026-103473 | HIGH | 8.1 | Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers … | Sep 30, 2026 |
| CVE-2026-103472 | HIGH | 7.5 | restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream … | Sep 30, 2026 |
| CVE-2026-103471 | HIGH | 7.5 | restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP … | Sep 30, 2026 |
| CVE-2026-103446 | UNKNOWN | — | Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46. | Sep 30, 2026 |
| CVE-2026-103445 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue … | Sep 30, 2026 |
| CVE-2026-103440 | UNKNOWN | — | Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, … | Sep 30, 2026 |
| CVE-2026-103439 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This … | Sep 30, 2026 |
| CVE-2026-103438 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This … | Sep 30, 2026 |
| CVE-2026-103437 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue … | Sep 30, 2026 |
| CVE-2026-103399 | MEDIUM | 5.3 | A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an … | Sep 30, 2026 |
| CVE-2026-102397 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | Sep 30, 2026 |