Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-103623 | UNKNOWN | — | Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Oct 02, 2026 |
| CVE-2026-103622 | HIGH | 8.8 | Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Oct 02, 2026 |
| CVE-2026-103621 | UNKNOWN | — | Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security … | Oct 02, 2026 |
| CVE-2026-101104 | HIGH | 7.7 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do … | Oct 02, 2026 |
| CVE-2026-90970 | CRITICAL | 9.9 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, … | Oct 02, 2026 |
| CVE-2026-5782 | MEDIUM | 5.2 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS. This issue affects TurkHotspot: through 2026-10-02. NOTE: The … | Oct 02, 2026 |
| CVE-2026-39717 | MEDIUM | 4.3 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1. | Oct 02, 2026 |
| CVE-2026-39601 | LOW | 3.7 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from … | Oct 02, 2026 |
| CVE-2026-39600 | MEDIUM | 4.7 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through … | Oct 02, 2026 |
| CVE-2026-39444 | MEDIUM | 5.4 | Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a … | Oct 02, 2026 |
| CVE-2026-39439 | MEDIUM | 6.5 | Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7. | Oct 02, 2026 |
| CVE-2026-32585 | MEDIUM | 6.5 | Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/a through … | Oct 02, 2026 |
| CVE-2026-32584 | MEDIUM | 5.3 | Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded … | Oct 02, 2026 |
| CVE-2026-104638 | MEDIUM | 5.3 | A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is an unknown function of the file php/sessions.php. The manipulation … | Oct 02, 2026 |
| CVE-2026-104637 | HIGH | 7.3 | A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation … | Oct 02, 2026 |
| CVE-2026-104625 | MEDIUM | 6.3 | A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation … | Oct 02, 2026 |
| CVE-2026-104026 | HIGH | 7.8 | In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a … | Oct 02, 2026 |
| CVE-2026-94422 | HIGH | 8.8 | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus … | Oct 02, 2026 |
| CVE-2026-93875 | HIGH | 7.2 | The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to … | Oct 02, 2026 |
| CVE-2026-85215 | HIGH | 7.1 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue … | Oct 02, 2026 |
| CVE-2026-19652 | CRITICAL | 9.8 | The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function … | Oct 02, 2026 |
| CVE-2026-104721 | UNKNOWN | — | Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender … | Oct 02, 2026 |
| CVE-2026-104614 | MEDIUM | 6.3 | A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the … | Oct 02, 2026 |
| CVE-2026-104613 | MEDIUM | 6.3 | A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument … | Oct 02, 2026 |
| CVE-2026-96289 | UNKNOWN | — | Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes … | Oct 02, 2026 |