Sign in

CVE Alerts

@cve.skyfleet.blue
1.2K followers 6 following 38K posts

Unofficial account to notify You about new CVE id's CVE is a program that identifies, defines, and catalogs publicly disclosed cybersecurity vulnerabilities. check out @infosec.skyfleet.blue 🆘 @skyfleet.blue

PostsRepliesMedia
CVE Alerts @cve.skyfleet.blue · 2h
CVE-2026-104478 - Formwork before 2.3.13 Path Traversal via BackupController Download and Delete CVE ID : CVE-2026-104478 Published : Oct. 3, 2026, 12:16 a.m. | 46 minutes ago Description : Formwork before 2.3.13 contains a path traversal vulnerability in BackupControlle...
cvefeed.io
CVE-2026-104478 - Formwork before 2.3.13 Path Traversal via BackupController Download and Delete
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
000
CVE Alerts @cve.skyfleet.blue · 2h
CVE-2026-104479 - Shopclass before 6.2.0 Stored XSS via Listing Description Field CVE ID : CVE-2026-104479 Published : Oct. 3, 2026, 12:16 a.m. | 46 minutes ago Description : Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-reg...
cvefeed.io
CVE-2026-104479 - Shopclass before 6.2.0 Stored XSS via Listing Description Field
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the …
000
CVE Alerts @cve.skyfleet.blue · 2h
CVE-2026-105029 - UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint CVE ID : CVE-2026-105029 Published : Oct. 3, 2026, 12:16 a.m. | 46 minutes ago Description : UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct o...
cvefeed.io
CVE-2026-105029 - UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other …
000
CVE Alerts @cve.skyfleet.blue · 2h
CVE-2026-105030 - Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API CVE ID : CVE-2026-105030 Published : Oct. 3, 2026, 12:16 a.m. | 45 minutes ago Description : Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows ...
cvefeed.io
CVE-2026-105030 - Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime …
000
CVE Alerts @cve.skyfleet.blue · 2h
CVE-2026-104477 - Showdown through 2.1.0 XSS via unescaped quote in href and src attributes CVE ID : CVE-2026-104477 Published : Oct. 3, 2026, 12:16 a.m. | 46 minutes ago Description : Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml l...
cvefeed.io
CVE-2026-104477 - Showdown through 2.1.0 XSS via unescaped quote in href and src attributes
Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script …
000
CVE Alerts @cve.skyfleet.blue · 4h
CVE-2026-94591 - Armatura LLC Armatura One Use of Hard-coded Cryptographic Key CVE ID : CVE-2026-94591 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description : Armatura One stores database and message-broker credentials in an install configuration file,...
cvefeed.io
CVE-2026-94591 - Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package …
000
CVE Alerts @cve.skyfleet.blue · 4h
CVE-2026-94592 - Armatura LLC Armatura One Use of Hard-coded Credentials CVE ID : CVE-2026-94592 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description : Armatura One's database initialization routine assigns a fixed, vendor-defined password to the data...
cvefeed.io
CVE-2026-94592 - Armatura LLC Armatura One Use of Hard-coded Credentials
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where …
000
CVE Alerts @cve.skyfleet.blue · 4h
CVE-2026-94593 - Armatura LLC Armatura One Insertion of Sensitive Information into Log File CVE ID : CVE-2026-94593 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description : Armatura One's backup and restore routine records the full database connection c...
cvefeed.io
CVE-2026-94593 - Armatura LLC Armatura One Insertion of Sensitive Information into Log File
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
000
CVE Alerts @cve.skyfleet.blue · 4h
CVE-2026-95102 - Monta monta.app Missing Authentication for Critical Function CVE ID : CVE-2026-95102 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description : WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate c...
cvefeed.io
CVE-2026-95102 - Monta monta.app Missing Authentication for Critical Function
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the …
000
CVE Alerts @cve.skyfleet.blue · 4h
CVE-2026-97363 - Monta monta.app Improper Restriction of Excessive Authentication Attempts CVE ID : CVE-2026-97363 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description : The WebSocket Application Programming Interface lacks restrictions on the number ...
cvefeed.io
CVE-2026-97363 - Monta monta.app Improper Restriction of Excessive Authentication Attempts
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
000
CVE Alerts @cve.skyfleet.blue · 6h
CVE-2026-104055 - Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm CVE ID : CVE-2026-104055 Published : Oct. 2, 2026, 8:35 p.m. | 26 minutes ago Description : The postgresql-operator charm runs a Prometheus postgres_exporter to col...
cvefeed.io
CVE-2026-104055 - Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm
The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to …
000
CVE Alerts @cve.skyfleet.blue · 6h
CVE-2026-75937 - OS Command Injection in Digi Accelerated Linux (DAL OS) CVE ID : CVE-2026-75937 Published : Oct. 2, 2026, 8:33 p.m. | 28 minutes ago Description : A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacke...
cvefeed.io
CVE-2026-75937 - OS Command Injection in Digi Accelerated Linux (DAL OS)
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
000
CVE Alerts @cve.skyfleet.blue · 6h
CVE-2026-82045 - UTMStack CVE ID : CVE-2026-82045 Published : Oct. 2, 2026, 8:21 p.m. | 40 minutes ago Description : UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetwork...
cvefeed.io
CVE-2026-82045 - UTMStack < 11.2.16 JPQL Injection via searchPropertyValues
UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can inject malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint to …
000
CVE Alerts @cve.skyfleet.blue · 6h
CVE-2026-104874 - Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction CVE ID : CVE-2026-104874 Published : Oct. 2, 2026, 8:21 p.m. | 40 minutes ago Description : Multidict is an implementation of a multidict data structure. From 6.7.0 unti...
cvefeed.io
CVE-2026-104874 - Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction
Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these …
000
CVE Alerts @cve.skyfleet.blue · 6h
CVE-2026-82044 - UTMStack CVE ID : CVE-2026-82044 Published : Oct. 2, 2026, 8:20 p.m. | 41 minutes ago Description : UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary inte...
cvefeed.io
CVE-2026-82044 - UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf
UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the …
000
CVE Alerts @cve.skyfleet.blue · 8h
CVE-2026-103958 - Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS CVE ID : CVE-2026-103958 Published : Oct. 2, 2026, 7:07 p.m. | 14 minutes ago Description : Server-side request forgery in the tool server and remote age...
cvefeed.io
CVE-2026-103958 - Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS
Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when …
000
CVE Alerts @cve.skyfleet.blue · 8h
CVE-2026-103957 - Server-side request forgery in the OAuth2 discovery handling in Loom for AWS CVE ID : CVE-2026-103957 Published : Oct. 2, 2026, 7:06 p.m. | 14 minutes ago Description : Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before ...
cvefeed.io
CVE-2026-103957 - Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address …
000
CVE Alerts @cve.skyfleet.blue · 8h
CVE-2026-96940 - Microsoft Exchange Server Elevation of Privilege Vulnerability CVE ID : CVE-2026-96940 Published : Oct. 2, 2026, 7:06 p.m. | 15 minutes ago Description : None Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected prod...
cvefeed.io
CVE-2026-96940 - Microsoft Exchange Server Elevation of Privilege Vulnerability
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
000
CVE Alerts @cve.skyfleet.blue · 8h
CVE-2026-103956 - Missing authentication for critical function in Loom for AWS CVE ID : CVE-2026-103956 Published : Oct. 2, 2026, 7:06 p.m. | 15 minutes ago Description : Missing authentication for critical function in the authentication dependency in Loom for AWS before...
cvefeed.io
CVE-2026-103956 - Missing authentication for critical function in Loom for AWS
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to …
000
CVE Alerts @cve.skyfleet.blue · 8h
CVE-2023-54405 - H3C CVM Unauthenticated File Upload via fileUpload/upload Token CVE ID : CVE-2023-54405 Published : Oct. 2, 2026, 6:36 p.m. | 45 minutes ago Description : H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an u...
cvefeed.io
CVE-2023-54405 - H3C CVM Unauthenticated File Upload via fileUpload/upload Token
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path …
000
CVE Alerts @cve.skyfleet.blue · 10h
CVE-2026-104853 - Nx: Path traversal in nx migrate package-migrations extraction CVE ID : CVE-2026-104853 Published : Oct. 2, 2026, 4:52 p.m. | 9 minutes ago Description : Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23....
cvefeed.io
CVE-2026-104853 - Nx: Path traversal in nx migrate package-migrations extraction
Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup …
010
CVE Alerts @cve.skyfleet.blue · 10h
CVE-2026-104851 - fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution CVE ID : CVE-2026-104851 Published : Oct. 2, 2026, 4:36 p.m. | 25 minutes ago Description : fsspec is a specification and Python implementation framework for fi...
cvefeed.io
CVE-2026-104851 - fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution
fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in _process_references1._render_jinja, _process_templates, and _process_gen in fsspec/implementations/reference.py. A document supplied inline or fetched from an attacker-controlled URL can provide template expressions that execute …
000
CVE Alerts @cve.skyfleet.blue · 10h
CVE-2026-104849 - Tinypool: Prototype Pollution Gadget to RCE in run() options CVE ID : CVE-2026-104849 Published : Oct. 2, 2026, 4:17 p.m. | 44 minutes ago Description : Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads file...
cvefeed.io
CVE-2026-104849 - Tinypool: Prototype Pollution Gadget to RCE in run() options
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object …
000
CVE Alerts @cve.skyfleet.blue · 10h
CVE-2026-94544 - Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages CVE ID : CVE-2026-94544 Published : Oct. 2, 2026, 4:16 p.m. | 45 minutes ago Description : Next.js is a React framework for building full-stack web a...
cvefeed.io
CVE-2026-94544 - Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping …
000
CVE Alerts @cve.skyfleet.blue · 10h
CVE-2026-96613 - Missing Authorization in Meari IoT Cloud Platform OpenAPI Service CVE ID : CVE-2026-96613 Published : Oct. 2, 2026, 4:16 p.m. | 45 minutes ago Description : The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows a...
cvefeed.io
CVE-2026-96613 - Missing Authorization in Meari IoT Cloud Platform OpenAPI Service
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship …
000
CVE Alerts @cve.skyfleet.blue · 12h
CVE-2026-90970 - Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway CVE ID : CVE-2026-90970 Published : Oct. 2, 2026, 2:34 p.m. | 46 minutes ago Description : GitLab has remediated a vulnerability in the GitLab AI Gateway component...
cvefeed.io
CVE-2026-90970 - Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox …
001
CVE Alerts @cve.skyfleet.blue · 12h
CVE-2026-94422 - xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape CVE ID : CVE-2026-94422 Published : Oct. 2, 2026, 2:17 p.m. | 1 hour, 3 minutes ago Description : An incorrect implementation of message filtering in xdg-dbus-proxy versions ...
cvefeed.io
CVE-2026-94422 - xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its …
000
CVE Alerts @cve.skyfleet.blue · 12h
CVE-2026-19652 - Divi Membership CVE ID : CVE-2026-19652 Published : Oct. 2, 2026, 2:17 p.m. | 1 hour, 3 minutes ago Description : The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `...
cvefeed.io
CVE-2026-19652 - Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with …
000
CVE Alerts @cve.skyfleet.blue · 14h
CVE-2026-11795 - User Enumeration in Softtr's E-Commerce Pack CVE ID : CVE-2026-11795 Published : Oct. 2, 2026, 12:42 p.m. | 18 minutes ago Description : Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Foo...
cvefeed.io
CVE-2026-11795 - User Enumeration in Softtr's E-Commerce Pack
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
000
CVE Alerts @cve.skyfleet.blue · 14h
CVE-2026-102797 - WordPress ThemeREX Addons plugin CVE ID : CVE-2026-102797 Published : Oct. 2, 2026, 12:39 p.m. | 21 minutes ago Description : Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forger...
cvefeed.io
CVE-2026-102797 - WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0.
000
CVE Alerts @cve.skyfleet.blue · 14h
CVE-2026-102798 - WordPress ThemeREX Addons plugin CVE ID : CVE-2026-102798 Published : Oct. 2, 2026, 12:38 p.m. | 22 minutes ago Description : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX A...
cvefeed.io
CVE-2026-102798 - WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from n/a through 2.46.0.
000
CVE Alerts @cve.skyfleet.blue · 14h
CVE-2026-66081 - Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages CVE ID : CVE-2026-66081 Published : Oct. 2, 2026, 12:33 p.m. | 27 minutes ago Description : Access of Uninitialized Pointer vulnerability in Apache Thrift ...
cvefeed.io
CVE-2026-66081 - Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages
Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
000
CVE Alerts @cve.skyfleet.blue · 14h
CVE-2026-66331 - Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize CVE ID : CVE-2026-66331 Published : Oct. 2, 2026, 12:32 p.m. | 28 minutes ago Description : Allocation of Resources Without Limits or Throttling vulnerability in Apache Thri...
cvefeed.io
CVE-2026-66331 - Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
000
CVE Alerts @cve.skyfleet.blue · 16h
CVE-2026-96990 - Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound CVE ID : CVE-2026-96990 Published : Oct. 2, 2026, 11 a.m. | 20 minutes ago Description : Allocation of Resources Without Limits or Throttling vulnerability in Apache Thri...
cvefeed.io
CVE-2026-96990 - Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
010
CVE Alerts @cve.skyfleet.blue · 16h
CVE-2026-94642 - Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception CVE ID : CVE-2026-94642 Published : Oct. 2, 2026, 10:57 a.m. | 23 minutes ago Description : Uncaught exception vulnerability in Apache Thrift PHP bindings. This ...
cvefeed.io
CVE-2026-94642 - Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception
Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
000
CVE Alerts @cve.skyfleet.blue · 16h
CVE-2026-94644 - Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound CVE ID : CVE-2026-94644 Published : Oct. 2, 2026, 10:53 a.m. | 26 minutes ago Description : Allocation of resources without limits or throttling vulnerability in Apache Thrift PH...
cvefeed.io
CVE-2026-94644 - Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
001
CVE Alerts @cve.skyfleet.blue · 16h
CVE-2026-94645 - Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound CVE ID : CVE-2026-94645 Published : Oct. 2, 2026, 10:51 a.m. | 28 minutes ago Description : Improper validation of specified quantity in input, Allocati...
cvefeed.io
CVE-2026-94645 - Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
000
CVE Alerts @cve.skyfleet.blue · 16h
CVE-2026-94650 - Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion) CVE ID : CVE-2026-94650 Published : Oct. 2, 2026, 10:49 a.m. | 30 minutes ago Description : Uncontrolled Recursion vulnerability in Apache Thrift c_gli...
cvefeed.io
CVE-2026-94650 - Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion)
Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
000
CVE Alerts @cve.skyfleet.blue · 18h
CVE-2026-59669 - Multiple vulnerabilities in the Repasat application CVE ID : CVE-2026-59669 Published : Oct. 2, 2026, 8:40 a.m. | 20 minutes ago Description : Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability co...
cvefeed.io
CVE-2026-59669 - Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “name” parameter is affected – endpoint “/es/attachmenttypes/update/203336”
000
CVE Alerts @cve.skyfleet.blue · 18h
CVE-2026-91784 - Argument Injection leading to arbitrary process termination in gotop CVE ID : CVE-2026-91784 Published : Oct. 2, 2026, 8:38 a.m. | 22 minutes ago Description : cjbassi/gotop is vulnerable to local argument injection via process termination functionality....
cvefeed.io
CVE-2026-91784 - Argument Injection leading to arbitrary process termination in gotop
cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature …
000
CVE Alerts @cve.skyfleet.blue · 18h
CVE-2026-97663 - Customer Reviews for WooCommerce CVE ID : CVE-2026-97663 Published : Oct. 2, 2026, 8:17 a.m. | 43 minutes ago Description : The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in ...
cvefeed.io
CVE-2026-97663 - Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …
010
CVE Alerts @cve.skyfleet.blue · 18h
CVE-2026-97637 - JSON API Auth CVE ID : CVE-2026-97637 Published : Oct. 2, 2026, 8:17 a.m. | 43 minutes ago Description : The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and includi...
cvefeed.io
CVE-2026-97637 - JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method …
000
CVE Alerts @cve.skyfleet.blue · 19h
CVE-2026-97641 - Relevanssi CVE ID : CVE-2026-97641 Published : Oct. 2, 2026, 8:17 a.m. | 43 minutes ago Description : The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and includ...
cvefeed.io
CVE-2026-97641 - Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …
000
CVE Alerts @cve.skyfleet.blue · 20h
CVE-2026-63569 - MTI/A0 DHAgreement does not validate the peer's ephemeral value CVE ID : CVE-2026-63569 Published : 2. Oktober 2026 07:00 | 19 Minuten ago Description : Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legio...
cvefeed.io
CVE-2026-63569 - MTI/A0 DHAgreement does not validate the peer's ephemeral value
Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer …
000
CVE Alerts @cve.skyfleet.blue · 20h
CVE-2026-63568 - Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion CVE ID : CVE-2026-63568 Published : 2. Oktober 2026 06:59 | 20 Minuten ago Description : Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC v...
cvefeed.io
CVE-2026-63568 - Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion
Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a CMP message or CRMF certificate request whose PBMParameter declares a …
000
CVE Alerts @cve.skyfleet.blue · 20h
CVE-2026-63567 - IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) CVE ID : CVE-2026-63567 Published : 2. Oktober 2026 06:58 | 21 Minuten ago Description : Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-cs...
cvefeed.io
CVE-2026-63567 - IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in …
000
CVE Alerts @cve.skyfleet.blue · 20h
CVE-2026-63566 - DTLS handshake reassembler allocates buffer from unchecked 24-bit length CVE ID : CVE-2026-63566 Published : 2. Oktober 2026 06:57 | 22 Minuten ago Description : Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHa...
cvefeed.io
CVE-2026-63566 - DTLS handshake reassembler allocates buffer from unchecked 24-bit length
Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial of service through memory exhaustion via crafted handshake message fragments, because the reassembly buffer for each incoming …
000
CVE Alerts @cve.skyfleet.blue · 20h
CVE-2026-16001 - IesEngine stream-mode MAC forgery via length-dependent KDF split CVE ID : CVE-2026-16001 Published : 2. Oktober 2026 06:55 | 24 Minuten ago Description : Exposure of the message authentication key through the encryption keystream in the stream mode of Ie...
cvefeed.io
CVE-2026-16001 - IesEngine stream-mode MAC forgery via length-dependent KDF split
Exposure of the message authentication key through the encryption keystream in the stream mode of IesEngine (an IesEngine constructed without a block cipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has observed one encrypted message with known plaintext to forge shorter messages …
000
CVE Alerts @cve.skyfleet.blue · 22h
CVE-2026-19660 - Divi Membership CVE ID : CVE-2026-19660 Published : Oct. 2, 2026, 4:27 a.m. | 33 minutes ago Description : The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_ca...
cvefeed.io
CVE-2026-19660 - Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to …
020
CVE Alerts @cve.skyfleet.blue · 22h
CVE-2026-10026 - CTX Feed Pro CVE ID : CVE-2026-10026 Published : Oct. 2, 2026, 4:27 a.m. | 33 minutes ago Description : The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input ...
cvefeed.io
CVE-2026-10026 - CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is passed directly to the eval() function. This makes it possible for authenticated attackers, with Administrator-level access …
000