Latest CVEs

Every organization faces unique cybersecurity challenges, and staying ahead of emerging vulnerabilities is a critical part of maintaining a resilient security program. Gilliam Security helps organizations identify, assess, and prioritize cybersecurity risks so security leaders and stakeholders can make informed decisions and take timely action to protect critical systems and business operations.

The latest Common Vulnerabilities and Exposures (CVEs) provide visibility into newly disclosed security vulnerabilities across a broad range of vendors, products, and technologies. Monitoring these vulnerabilities can help organizations identify potential exposure, prioritize remediation efforts, and strengthen their overall vulnerability management practices.

Provided below are the latest CVEs published within the last 30 days:

CVE-2026-96577 - Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled
Published: October 01, 2026
CVE ID :CVE-2026-96577
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Severity: 7.1 | HIGH

CVE-2026-96256 - Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute
Published: October 01, 2026
CVE ID :CVE-2026-96256
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker title/content values, which are stored as JSON and then decoded and concatenated directly into raw HTML by the frontend script's InfoWindow content builder. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Severity: 6.4 | MEDIUM

CVE-2026-92144 - Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
Published: October 01, 2026
CVE ID :CVE-2026-92144
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form submission nonce is freely obtainable by unauthenticated users via the publicly accessible wp_ajax_nopriv_forminator_get_nonce endpoint, making the full attack chain exploitable without any authentication or prior account.
Severity: 7.2 | HIGH

CVE-2026-83589 - Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
Published: October 01, 2026
CVE ID :CVE-2026-83589
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.
Severity: 6.1 | MEDIUM

CVE-2026-7176 - Multiple vulnerabilities in Entradium by Crocantickets
Published: October 01, 2026
CVE ID :CVE-2026-7176
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :CVE-2026-7176: the Help text and Title parameters in the endpoint /events/-/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaScript that will execute on the public ticket purchase page for the event.
Severity: 4.8 | MEDIUM

CVE-2026-7175 - Multiple vulnerabilities in Entradium by Crocantickets
Published: October 01, 2026
CVE ID :CVE-2026-7175
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
Severity: 4.8 | MEDIUM

CVE-2026-7174 - Multiple vulnerabilities in Entradium by Crocantickets
Published: October 01, 2026
CVE ID :CVE-2026-7174
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the affected parameters, which executes when an event’s discount list page is displayed. Successful exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.
Severity: 4.8 | MEDIUM

CVE-2026-7173 - Multiple vulnerabilities in Entradium by Crocantickets
Published: October 01, 2026
CVE ID :CVE-2026-7173
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored XSS) The City parameter in the endpoint /events//edit_general during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page. * (Reflected XSS) The Description parameter in the endpoint /events//edit-general when attempting to create or modify an event without filling in all required fields.
Severity: 4.8 | MEDIUM

CVE-2026-75786 - SQL Injection in Grafana Integration Endpoint (query.php)
Published: October 01, 2026
CVE ID :CVE-2026-75786
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :Unsanitized concatenation of the module parameter in the Grafana datasource endpoint allows authenticated blind SQL injection. Affects Pandora FMS from 777 onwards.
Severity: 7.2 | HIGH

CVE-2026-64950 - Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
Published: October 01, 2026
CVE ID :CVE-2026-64950
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :Missing input validation and output encoding on the directory name parameter in File Manager's Create Directory allows stored XSS, executing without user interaction. Affects Pandora FMS from 777 onwards.
Severity: 8.4 | HIGH

CVE-2026-64949 - Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager
Published: October 01, 2026
CVE ID :CVE-2026-64949
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :Incomplete extension blacklist in the File Manager module allows authenticated upload and execution of arbitrary .phar files. Affects Pandora FMS from 777 onwards.
Severity: 8.6 | HIGH

CVE-2026-64948 - Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure
Published: October 01, 2026
CVE ID :CVE-2026-64948
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :Missing authorization in module data retrieval allows unauthorized cross-group access to module history. Affects Pandora FMS from 777 onwards.
Severity: 7.1 | HIGH

CVE-2026-64947 - CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager
Published: October 01, 2026
CVE ID :CVE-2026-64947
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker to upload and execute arbitrary PHP code, resulting in Remote Code Execution. This issue affects Pandora FMS: from 777 onwards.
Severity: 7.5 | HIGH

CVE-2026-64946 - CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager
Published: October 01, 2026
CVE ID :CVE-2026-64946
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
Severity: 7.4 | HIGH

CVE-2026-34190 - CSRF in Alert Command Deletion
Published: October 01, 2026
CVE ID :CVE-2026-34190
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Severity: 5.9 | MEDIUM

CVE-2026-34189 - CSRF in Event Response Deletion
Published: October 01, 2026
CVE ID :CVE-2026-34189
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
Severity: 5.9 | MEDIUM

CVE-2026-103497 - JetBrains YouTrack Server-Side Request Forgery
Published: October 01, 2026
CVE ID :CVE-2026-103497
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
Severity: 5.5 | MEDIUM

CVE-2026-103496 - JetBrains YouTrack Insecure Direct Object Reference Vulnerability
Published: October 01, 2026
CVE ID :CVE-2026-103496
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
Severity: 5.4 | MEDIUM

CVE-2026-103495 - JetBrains YouTrack Missing Authorization Vulnerability
Published: October 01, 2026
CVE ID :CVE-2026-103495
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
Severity: 4.3 | MEDIUM

CVE-2026-103494 - JetBrains YouTrack Privilege Escalation
Published: October 01, 2026
CVE ID :CVE-2026-103494
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
Severity: 6.6 | MEDIUM

CVE-2026-103493 - JetBrains YouTrack Stored Cross-Site Scripting
Published: October 01, 2026
CVE ID :CVE-2026-103493
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
Severity: 8.1 | HIGH

CVE-2026-103492 - JetBrains YouTrack Denial of Service Vulnerability
Published: October 01, 2026
CVE ID :CVE-2026-103492
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
Severity: 6.5 | MEDIUM

CVE-2026-103491 - JetBrains YouTrack Insecure Direct Object Reference Vulnerability
Published: October 01, 2026
CVE ID :CVE-2026-103491
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
Severity: 6.5 | MEDIUM

CVE-2026-103490 - JetBrains YouTrack User Group Privilege Escalation
Published: October 01, 2026
CVE ID :CVE-2026-103490
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
Severity: 7.2 | HIGH

CVE-2026-103489 - JetBrains YouTrack HTML Injection in VCS Command Failure Notifications
Published: October 01, 2026
CVE ID :CVE-2026-103489
Published : Oct. 1, 2026, 10:17 a.m. | 16 minutes ago
Description :In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
Severity: 2.0 | LOW