🔐 CVE Alert

Real-Time CVE Alerts & Vulnerability Tracker

Search enriched vulnerability intelligence — EPSS exploitability scores, CVSS severity, CISA KEV status — and get instant alerts to Slack, Telegram, Discord or Google Chat.

⚡ Immediate or digest alerts 🎯 Filter by ecosystem, severity, EPSS 🔑 CISA KEV tracking 🆓 Free forever

288,515 results

CVE-2020-37278HIGH 7.5

Weaver e-Bridge Unauthenticated Arbitrary File Read via saveYZJFile

Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and the same endpoint's support for http(s) URLs also enables server-side request forgery against internal network resources. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.

EPSS
0.0%
weaver / e-bridgeOct 2, 2026
CVE-2014-125130HIGH 7.5

CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_download.php

CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19.

EPSS
0.0%
damjan / codeart google mp3 audio playerOct 2, 2026
CVE-2023-54405CRITICAL 9.8

H3C CVM Unauthenticated File Upload via fileUpload/upload Token

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

EPSS
0.0%
h3c / cvmOct 2, 2026
CVE-2026-19856MEDIUM 6.5

All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query

The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.

EPSS
0.0%
unknown / all in one seoOct 2, 2026
CVE-2026-104861HIGH 7.5

probe-image-size: Quadratic-time Denial of Service in the SVG Parser

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the full supplied buffer without an input cap, while the streaming parser reparses the complete accumulated SVG prefix for every received chunk. The probe.sync(), probe(stream), and probe(url) entry points can therefore block the Node.js event loop at full CPU, and attacker-controlled chunking can amplify the streaming cost. This issue is fixed in version 7.4.0.

EPSS
0.0%
nodeca / probe-image-sizeOct 2, 2026
CVE-2026-104859UNKNOWN 0.0

Nx: OS command injection in the @nx/docker release pipeline

Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.

EPSS
0.0%
nrwl / nxOct 2, 2026
CVE-2026-102795CRITICAL 9.3

Apache Traffic Server: SNI to Host header matching policy is not properly enforced

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected.

EPSS
0.0%
apache software foundation / apache traffic serverOct 2, 2026
CVE-2026-104855UNKNOWN 0.0

Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state

Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an embedder mutates a Store in Store::epoch_deadline_callback or continues using a Store after cancellation or a trap. A cancelled non-nullable table growth can leave null elements, linear-memory growth during memory.copy can invalidate retained raw pointers, and callback-triggered garbage collection during array.copy can invalidate GC pointers, resulting in a crash, invalid memory access, or GC heap corruption. Embeddings whose callbacks only access the host data in Store<T>, and embeddings that discard a Store after timeout or epoch deadline, are not affected. This issue is fixed in versions 46.0.2 and 47.0.3.

EPSS
0.0%
bytecodealliance / wasmtimeOct 2, 2026
CVE-2026-59265UNKNOWN 0.0

Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.

EPSS
0.0%
apache software foundation / apache openofficeOct 2, 2026
CVE-2026-102626UNKNOWN 0.0

LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.

EPSS
0.0%
limesurvey / limesurveyOct 2, 2026
CVE-2026-104854UNKNOWN 0.0

Nx daemon and plugin worker sockets are accessible to other local users

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.

EPSS
0.0%
nrwl / nxOct 2, 2026
CVE-2026-104853UNKNOWN 0.0

Nx: Path traversal in nx migrate package-migrations extraction

Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.

EPSS
0.0%
nrwl / nxOct 2, 2026
CVE-2026-104851HIGH 8.8

fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in _process_references1._render_jinja, _process_templates, and _process_gen in fsspec/implementations/reference.py. A document supplied inline or fetched from an attacker-controlled URL can provide template expressions that execute Python code when the reference filesystem is opened, including through consumers such as xarray, before referenced data is read. The _process_gen path is reached whenever a document includes a gen array, while the other paths depend on template-related options and values. This issue is fixed in version 2026.6.0.

EPSS
0.0%
fsspec / filesystem_specOct 2, 2026
CVE-2026-104849UNKNOWN 0.0

Tinypool: Prototype Pollution Gadget to RCE in run() options

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.

EPSS
0.0%
tinylibs / tinypoolOct 2, 2026
CVE-2026-104848UNKNOWN 0.0

Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.

EPSS
0.0%
tinylibs / tinypoolOct 2, 2026
CVE-2026-104914UNKNOWN 0.0

MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View

MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48.

EPSS
0.0%
misp / mispOct 2, 2026
CVE-2026-103627UNKNOWN 0.0

No title available

Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

EPSS
0.0%
google / chrome
BrowserAndroidCloud
Oct 2, 2026
CVE-2026-103631UNKNOWN 0.0

No title available

Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS
0.0%
google / chrome
BrowserAndroidCloud
Oct 2, 2026
CVE-2026-103623UNKNOWN 0.0

No title available

Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS
0.0%
google / chrome
BrowserAndroidCloud
Oct 2, 2026
CVE-2026-103622UNKNOWN 0.0

No title available

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS
0.0%
google / chrome
BrowserAndroidCloud
Oct 2, 2026

Never miss a critical vulnerability

Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS — get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.

Set Up Free Alerts → Create Free Account

Slack · Telegram · Discord · Google Chat