- CVE-2026-105105 CRITICAL CVSS 9.8 -
NVD: CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject... NVD: The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. NVD: An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic.
A remote attacker may be able to run unintended system commands through the affected component; CVSS 9.8 (CRITICAL); EPSS percentile 55; sources: NVD, OSV.
- CVE-2026-105115 HIGH CVSS 8.8 -
NVD: OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. NVD: Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains. OSV: OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 8.8 (HIGH); EPSS percentile 38; sources: NVD, OSV.
- CVE-2026-96451 HIGH CVSS 8.8 -
NVD: Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
An attacker may cross a privilege boundary and gain more access than intended; CVSS 8.8 (HIGH); EPSS percentile 21; sources: NVD.
- CVE-2026-105123 HIGH CVSS 8.7 -
NVD: W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. NVD: Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. OSV: W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API
An attacker may be able to run code or commands on affected systems; CVSS 8.7 (HIGH); EPSS percentile 42; sources: NVD, OSV.
- CVE-2026-105126 HIGH CVSS 8.6 -
NVD: LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. NVD: Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution. OSV: LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
An attacker may cross a privilege boundary and gain more access than intended; CVSS 8.6 (HIGH); EPSS percentile 40; sources: NVD, OSV.
- CVE-2026-103065 HIGH CVSS 8.2 -
NVD: Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.2 (HIGH); EPSS percentile 10; sources: NVD.
- CVE-2026-105119 HIGH CVSS 7.6 -
NVD: OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. NVD: An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier. OSV: OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.6 (HIGH); EPSS percentile 9; sources: NVD, OSV.
- CVE-2026-105113 HIGH CVSS 7.1 -
NVD: Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. NVD: Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests. OSV: Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock
The affected service may become unavailable or unreliable; CVSS 7.1 (HIGH); EPSS percentile 9; sources: NVD, OSV.
- CVE-2026-103342 HIGH CVSS 7.1 -
NVD: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 7.1 (HIGH); EPSS percentile 3; sources: NVD.
- CVE-2026-105120 MEDIUM CVSS 6.9 -
NVD: OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. NVD: Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries. OSV: OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.9 (MEDIUM); EPSS percentile 17; sources: NVD, OSV.
- CVE-2026-105121 MEDIUM CVSS 6.9 -
NVD: OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. NVD: Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm. OSV: OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 6.9 (MEDIUM); EPSS percentile 15; sources: NVD, OSV.
- CVE-2026-105125 MEDIUM CVSS 6.3 -
NVD: LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. NVD: On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files. OSV: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
A remote attacker may be able to reach files outside the intended application path; CVSS 6.3 (MEDIUM); EPSS percentile 22; sources: NVD, OSV.
- CVE-2026-105112 MEDIUM CVSS 6.0 -
NVD: Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. NVD: Attackers can concurrently call the notification-group and batch-delete endpoints with oversized id lists to widen the race and close an ABBA cycle, permanently killing alert delivery until restart. OSV: Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints
The affected service may become unavailable or unreliable; CVSS 6.0 (MEDIUM); EPSS percentile 7; sources: NVD, OSV.
- CVE-2026-105122 MEDIUM CVSS 5.3 -
NVD: OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. NVD: Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service. OSV: OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri
The affected service may become unavailable or unreliable; CVSS 5.3 (MEDIUM); EPSS percentile 13; sources: NVD, OSV.
- CVE-2026-105124 MEDIUM CVSS 5.3 -
NVD: W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. NVD: Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges. OSV: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 11; sources: NVD, OSV.
- CVE-2026-105114 MEDIUM CVSS 5.3 -
NVD: OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. NVD: Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages. OSV: OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · remote exposure · authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 6; sources: NVD, OSV.
- CVE-2026-105117 MEDIUM CVSS 5.3 -
NVD: OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. NVD: Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients. OSV: OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 5; sources: NVD, OSV.
- CVE-2026-105116 MEDIUM CVSS 5.1 -
NVD: OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. NVD: If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions. OSV: OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 5.1 (MEDIUM); EPSS percentile 4; sources: NVD, OSV.
- CVE-2026-105118 LOW CVSS 2.3 -
NVD: OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. NVD: Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust. OSV: OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 2.3 (LOW); EPSS percentile 1; sources: NVD, OSV.
- CVE-2026-104983 LOW CVSS 2.1 -
NVD: A vulnerability has been found in Linux Mint Xreader up to 4.6.9. NVD: Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. NVD: Such manipulation of the argument attachment leads to path traversal.
An attacker may be able to reach files outside the intended application path; CVSS 2.1 (LOW); EPSS percentile 35; sources: NVD, OSV.