Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-97291 HIGH 8.8 Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. Sep 30, 2026
CVE-2026-97290 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. Sep 30, 2026
CVE-2026-97265 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a … Sep 30, 2026
CVE-2026-97256 HIGH 7.2 Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. Sep 30, 2026
CVE-2026-94171 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. Sep 30, 2026
CVE-2026-87004 HIGH 8.1 Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token … Sep 30, 2026
CVE-2026-55224 UNKNOWN — MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and … Sep 30, 2026
CVE-2026-55107 CRITICAL 10.0 Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, … Sep 30, 2026
CVE-2026-55094 UNKNOWN — Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on … Sep 30, 2026
CVE-2026-53605 HIGH 7.8 Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. … Sep 30, 2026
CVE-2026-103500 UNKNOWN — An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in … Sep 30, 2026
CVE-2026-103476 MEDIUM 5.3 yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate … Sep 30, 2026
CVE-2026-103475 CRITICAL 9.1 yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated … Sep 30, 2026
CVE-2026-103474 HIGH 8.8 yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role … Sep 30, 2026
CVE-2026-103473 HIGH 8.1 Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers … Sep 30, 2026
CVE-2026-103472 HIGH 7.5 restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream … Sep 30, 2026
CVE-2026-103471 HIGH 7.5 restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP … Sep 30, 2026
CVE-2026-103446 UNKNOWN — Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46. Sep 30, 2026
CVE-2026-103445 UNKNOWN — Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue … Sep 30, 2026
CVE-2026-103440 UNKNOWN — Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, … Sep 30, 2026
CVE-2026-103439 UNKNOWN — Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This … Sep 30, 2026
CVE-2026-103438 UNKNOWN — Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This … Sep 30, 2026
CVE-2026-103437 UNKNOWN — Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue … Sep 30, 2026
CVE-2026-103399 MEDIUM 5.3 A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an … Sep 30, 2026
CVE-2026-102397 MEDIUM 6.5 Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. Sep 30, 2026