Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102392 | HIGH | 7.2 | Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | Sep 30, 2026 |
| CVE-2026-102391 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | Sep 30, 2026 |
| CVE-2026-102377 | HIGH | 8.8 | Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | Sep 30, 2026 |
| CVE-2026-102376 | HIGH | 7.1 | Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | Sep 30, 2026 |
| CVE-2026-102375 | MEDIUM | 6.5 | Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | Sep 30, 2026 |
| CVE-2026-100512 | CRITICAL | 9.8 | Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | Sep 30, 2026 |
| CVE-2026-100510 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | Sep 30, 2026 |
| CVE-2026-75969 | UNKNOWN | — | Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the … | Sep 30, 2026 |
| CVE-2026-62308 | CRITICAL | 9.1 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server … | Sep 30, 2026 |
| CVE-2026-55494 | CRITICAL | 9.8 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when … | Sep 30, 2026 |
| CVE-2026-55181 | CRITICAL | 9.4 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. … | Sep 30, 2026 |
| CVE-2026-55177 | UNKNOWN | — | CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family … | Sep 30, 2026 |
| CVE-2026-55176 | CRITICAL | 9.0 | Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and … | Sep 30, 2026 |
| CVE-2026-46711 | HIGH | 8.3 | Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 … | Sep 30, 2026 |
| CVE-2026-19553 | UNKNOWN | — | ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname … | Sep 30, 2026 |
| CVE-2026-19445 | UNKNOWN | — | A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context … | Sep 30, 2026 |
| CVE-2026-103444 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue … | Sep 30, 2026 |
| CVE-2026-103443 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script … | Sep 30, 2026 |
| CVE-2026-103241 | MEDIUM | 5.3 | A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing … | Sep 30, 2026 |
| CVE-2026-103233 | MEDIUM | 6.3 | A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin … | Sep 30, 2026 |
| CVE-2026-103232 | HIGH | 7.3 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument … | Sep 30, 2026 |
| CVE-2026-102490 | UNKNOWN | — | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | Sep 30, 2026 |
| CVE-2026-102489 | UNKNOWN | — | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also … | Sep 30, 2026 |
| CVE-2026-80490 | UNKNOWN | — | Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING … | Sep 30, 2026 |
| CVE-2026-55174 | MEDIUM | 5.9 | UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature … | Sep 30, 2026 |