Common Vulnerabilities and Exposures (CVE)

CVE-2026-17538

Oct 7, 2026 23:27:12 UTC

The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process_step_customer() function using is_user_logged_in() ...

CVE-2026-94154

Oct 7, 2026 23:27:11 UTC

The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for ...

CVE-2026-107363

Oct 7, 2026 23:06:46 UTC

In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitut...

CVE-2026-107315

Oct 7, 2026 23:03:18 UTC

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value. The bytes...

CVE-2026-107314

Oct 7, 2026 23:03:01 UTC

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi...

CVE-2024-1102

Oct 7, 2026 22:44:34 UTC

A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

CVE-2026-33818

Oct 7, 2026 22:22:17 UTC

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

CVE-2026-42504

Oct 7, 2026 22:22:16 UTC

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

CVE-2026-103877

Oct 7, 2026 22:07:09 UTC

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java clas...

CVE-2026-103885

Oct 7, 2026 22:07:01 UTC

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue...

CVE-2026-85494

Oct 7, 2026 22:06:51 UTC

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift P...

CVE-2026-94651

Oct 7, 2026 22:06:45 UTC

improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to versi...

CVE-2026-106016

Oct 7, 2026 22:06:36 UTC

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.

CVE-2026-106552

Oct 7, 2026 22:06:29 UTC

In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.

CVE-2026-107271

Oct 7, 2026 22:06:20 UTC

Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can send a different forwarded address per reques...