Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-102392 HIGH 7.2 Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. Sep 30, 2026
CVE-2026-102391 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. Sep 30, 2026
CVE-2026-102377 HIGH 8.8 Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. Sep 30, 2026
CVE-2026-102376 HIGH 7.1 Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. Sep 30, 2026
CVE-2026-102375 MEDIUM 6.5 Subscriber Broken Access Control in Optimole <= 4.2.14 versions. Sep 30, 2026
CVE-2026-100512 CRITICAL 9.8 Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. Sep 30, 2026
CVE-2026-100510 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. Sep 30, 2026
CVE-2026-75969 UNKNOWN — Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the … Sep 30, 2026
CVE-2026-62308 CRITICAL 9.1 Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server … Sep 30, 2026
CVE-2026-55494 CRITICAL 9.8 Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when … Sep 30, 2026
CVE-2026-55181 CRITICAL 9.4 Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. … Sep 30, 2026
CVE-2026-55177 UNKNOWN — CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family … Sep 30, 2026
CVE-2026-55176 CRITICAL 9.0 Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and … Sep 30, 2026
CVE-2026-46711 HIGH 8.3 Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 … Sep 30, 2026
CVE-2026-19553 UNKNOWN — ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname … Sep 30, 2026
CVE-2026-19445 UNKNOWN — A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context … Sep 30, 2026
CVE-2026-103444 UNKNOWN — Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue … Sep 30, 2026
CVE-2026-103443 UNKNOWN — Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script … Sep 30, 2026
CVE-2026-103241 MEDIUM 5.3 A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing … Sep 30, 2026
CVE-2026-103233 MEDIUM 6.3 A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin … Sep 30, 2026
CVE-2026-103232 HIGH 7.3 A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument … Sep 30, 2026
CVE-2026-102490 UNKNOWN — All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. Sep 30, 2026
CVE-2026-102489 UNKNOWN — Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also … Sep 30, 2026
CVE-2026-80490 UNKNOWN — Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING … Sep 30, 2026
CVE-2026-55174 MEDIUM 5.9 UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature … Sep 30, 2026