| CVE-2026-103470 |
|
30.09.2026 |
|
| CVE-2026-47492 |
|
30.09.2026 |
5.5 |
| CVE-2026-47493 |
|
30.09.2026 |
7.8 |
| CVE-2026-47495 |
|
30.09.2026 |
7.8 |
| CVE-2026-47496 |
|
30.09.2026 |
7.3 |
| CVE-2026-47497 |
|
30.09.2026 |
7.8 |
| CVE-2026-47498 |
|
30.09.2026 |
7.8 |
| CVE-2026-47499 |
|
30.09.2026 |
7.8 |
| CVE-2026-47503 |
|
30.09.2026 |
7.8 |
| CVE-2026-47506 |
|
30.09.2026 |
5.5 |
| CVE-2026-47509 |
|
30.09.2026 |
6.7 |
| CVE-2026-47513 |
|
30.09.2026 |
7.8 |
| CVE-2026-47514 |
|
30.09.2026 |
7.8 |
| CVE-2026-47515 |
|
30.09.2026 |
6.7 |
| CVE-2026-47516 |
|
30.09.2026 |
7.8 |
| CVE-2026-47517 |
|
30.09.2026 |
5.5 |
| CVE-2026-47518 |
|
30.09.2026 |
6 |
| CVE-2026-47519 |
|
30.09.2026 |
7.8 |
| CVE-2026-47520 |
|
30.09.2026 |
7.8 |
| CVE-2026-47521 |
|
30.09.2026 |
7.8 |
| CVE-2026-47522 |
|
30.09.2026 |
6.7 |
| CVE-2026-47523 |
|
30.09.2026 |
7.8 |
| CVE-2026-47524 |
|
30.09.2026 |
6.7 |
| CVE-2026-47525 |
|
30.09.2026 |
6.7 |
| CVE-2026-47526 |
|
30.09.2026 |
4.4 |
| CVE-2026-47527 |
|
30.09.2026 |
6.7 |
| CVE-2026-47528 |
|
30.09.2026 |
7.8 |
| CVE-2026-47529 |
|
30.09.2026 |
6.7 |
| CVE-2026-47530 |
|
30.09.2026 |
7.8 |
| CVE-2026-47531 |
|
30.09.2026 |
4.4 |
| CVE-2026-47532 |
|
30.09.2026 |
6.7 |
| CVE-2026-47533 |
|
30.09.2026 |
6.7 |
| CVE-2026-47534 |
|
30.09.2026 |
5.5 |
| CVE-2026-47535 |
|
30.09.2026 |
7.8 |
| CVE-2026-47536 |
|
30.09.2026 |
7.8 |
| CVE-2026-47537 |
|
30.09.2026 |
6.7 |
| CVE-2026-47538 |
|
30.09.2026 |
6.7 |
| CVE-2026-47539 |
|
30.09.2026 |
6.7 |
| CVE-2026-47540 |
|
30.09.2026 |
7.8 |
| CVE-2026-47541 |
|
30.09.2026 |
7.8 |
| CVE-2026-47542 |
|
30.09.2026 |
6.7 |
| CVE-2026-47543 |
|
30.09.2026 |
6.7 |
| CVE-2026-47544 |
|
30.09.2026 |
7.8 |
| CVE-2026-47545 |
|
30.09.2026 |
7.8 |
| CVE-2026-47546 |
|
30.09.2026 |
6.7 |
| CVE-2026-47547 |
|
30.09.2026 |
6.7 |
| CVE-2026-47548 |
|
30.09.2026 |
7.8 |
| CVE-2026-47549 |
|
30.09.2026 |
5.5 |
| CVE-2026-47550 |
|
30.09.2026 |
7.8 |
| CVE-2026-47551 |
|
30.09.2026 |
7.8 |
| CVE-2026-47552 |
|
30.09.2026 |
7.8 |
| CVE-2026-47553 |
|
30.09.2026 |
7.8 |
| CVE-2026-47554 |
|
30.09.2026 |
7.1 |
| CVE-2026-47555 |
|
30.09.2026 |
5.5 |
| CVE-2026-47556 |
|
30.09.2026 |
7.8 |
| CVE-2026-47557 |
|
30.09.2026 |
5.5 |
| CVE-2026-47558 |
|
30.09.2026 |
7.8 |
| CVE-2026-47559 |
|
30.09.2026 |
7.8 |
| CVE-2026-47560 |
|
30.09.2026 |
7.8 |
| CVE-2026-47561 |
|
30.09.2026 |
7.8 |
| CVE-2026-47562 |
|
30.09.2026 |
4.4 |
| CVE-2026-47563 |
|
30.09.2026 |
7.8 |
| CVE-2026-47565 |
|
30.09.2026 |
6.4 |
| CVE-2026-47566 |
|
30.09.2026 |
5.5 |
| CVE-2026-47567 |
|
30.09.2026 |
5.5 |
| CVE-2026-47568 |
|
30.09.2026 |
5.5 |
| CVE-2026-47569 |
|
30.09.2026 |
7.8 |
| CVE-2026-47570 |
|
30.09.2026 |
7.8 |
| CVE-2026-47571 |
|
30.09.2026 |
7.8 |
| CVE-2026-47572 |
|
30.09.2026 |
7.8 |
| CVE-2026-47573 |
|
30.09.2026 |
7.8 |
| CVE-2026-47574 |
|
30.09.2026 |
7.8 |
| CVE-2026-47575 |
|
30.09.2026 |
7.8 |
| CVE-2026-47576 |
|
30.09.2026 |
7.7 |
| CVE-2026-47577 |
|
30.09.2026 |
7.8 |
| CVE-2026-47578 |
|
30.09.2026 |
7.8 |
| CVE-2026-47579 |
|
30.09.2026 |
7.8 |
| CVE-2026-47580 |
|
30.09.2026 |
7.3 |
| CVE-2026-47581 |
|
30.09.2026 |
5.5 |
| CVE-2026-47582 |
|
30.09.2026 |
7 |
| CVE-2026-47583 |
|
30.09.2026 |
7.8 |
| CVE-2026-47584 |
|
30.09.2026 |
5.5 |
| CVE-2026-47585 |
|
30.09.2026 |
7.8 |
| CVE-2026-47586 |
|
30.09.2026 |
6.4 |
| CVE-2026-47587 |
|
30.09.2026 |
7.8 |
| CVE-2026-47588 |
|
30.09.2026 |
7.8 |
| CVE-2026-47589 |
|
30.09.2026 |
7.8 |
| CVE-2026-47590 |
|
30.09.2026 |
7.8 |
| CVE-2026-47591 |
|
30.09.2026 |
7.8 |
| CVE-2026-47592 |
|
30.09.2026 |
7.8 |
| CVE-2026-47593 |
|
30.09.2026 |
7.8 |
| CVE-2026-47594 |
|
30.09.2026 |
7.8 |
| CVE-2026-47595 |
|
30.09.2026 |
7.8 |
| CVE-2026-47596 |
|
30.09.2026 |
7 |
| CVE-2026-47597 |
|
30.09.2026 |
7.8 |
| CVE-2026-47598 |
|
30.09.2026 |
7 |
| CVE-2026-47599 |
|
30.09.2026 |
7.8 |
| CVE-2026-47600 |
|
30.09.2026 |
7.8 |
| CVE-2026-47601 |
|
30.09.2026 |
7.8 |
| CVE-2026-47602 |
|
30.09.2026 |
7.1 |
| CVE-2026-47603 |
|
30.09.2026 |
5.5 |
| CVE-2026-47604 |
|
30.09.2026 |
5.5 |
| CVE-2026-103436 |
|
30.09.2026 |
3.7 |
| CVE-2026-47489 |
|
30.09.2026 |
7.8 |
| CVE-2026-47491 |
|
30.09.2026 |
7.8 |
| CVE-2026-47494 |
|
30.09.2026 |
7.8 |
| CVE-2026-47500 |
|
30.09.2026 |
7.8 |
| CVE-2026-47501 |
|
30.09.2026 |
7.8 |
| CVE-2026-47502 |
|
30.09.2026 |
7.8 |
| CVE-2026-47504 |
|
30.09.2026 |
7.8 |
| CVE-2026-47505 |
|
30.09.2026 |
7.8 |
| CVE-2026-47507 |
|
30.09.2026 |
7.8 |
| CVE-2026-47508 |
|
30.09.2026 |
7.8 |
| CVE-2026-47510 |
|
30.09.2026 |
7.8 |
| CVE-2026-47511 |
|
30.09.2026 |
7.8 |
| CVE-2026-47512 |
|
30.09.2026 |
7.8 |
| CVE-2026-55174 |
UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding |
30.09.2026 |
5.9 |
| CVE-2026-103230 |
AdithyaYelloju Restaurant-Management-System Order Placement ord.php mysqli_query sql injection |
30.09.2026 |
|
| CVE-2026-103432 |
|
30.09.2026 |
8.1 |
| CVE-2026-100253 |
|
30.09.2026 |
8.8 |
| CVE-2026-100254 |
|
30.09.2026 |
8.8 |
| CVE-2026-100255 |
|
30.09.2026 |
8.1 |
| CVE-2026-100256 |
|
30.09.2026 |
7.8 |
| CVE-2026-100257 |
|
30.09.2026 |
4.3 |
| CVE-2026-100258 |
|
30.09.2026 |
4.3 |
| CVE-2026-100259 |
|
30.09.2026 |
4.3 |
| CVE-2026-100260 |
|
30.09.2026 |
5.3 |
| CVE-2026-100261 |
|
30.09.2026 |
5.4 |
| CVE-2026-100262 |
|
30.09.2026 |
7.6 |
| CVE-2026-100263 |
|
30.09.2026 |
4.7 |
| CVE-2026-100264 |
|
30.09.2026 |
2.7 |
| CVE-2026-100265 |
|
30.09.2026 |
4.8 |
| CVE-2026-100266 |
|
30.09.2026 |
7.7 |
| CVE-2026-100267 |
|
30.09.2026 |
5.9 |
| CVE-2026-100268 |
|
30.09.2026 |
7.7 |
| CVE-2026-100269 |
|
30.09.2026 |
4.3 |
| CVE-2026-100270 |
|
30.09.2026 |
3.3 |
| CVE-2026-100271 |
|
30.09.2026 |
2.7 |
| CVE-2026-100272 |
|
30.09.2026 |
4.9 |
| CVE-2026-100273 |
|
30.09.2026 |
8.2 |
| CVE-2026-100274 |
|
30.09.2026 |
6.5 |
| CVE-2026-100275 |
|
30.09.2026 |
6.9 |
| CVE-2026-100276 |
|
30.09.2026 |
5.9 |
| CVE-2026-100277 |
|
30.09.2026 |
8.9 |
| CVE-2026-100278 |
|
30.09.2026 |
4.9 |
| CVE-2026-100279 |
|
30.09.2026 |
6.5 |
| CVE-2026-100280 |
|
30.09.2026 |
3.1 |
| CVE-2026-102427 |
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 |
30.09.2026 |
|
| CVE-2026-103229 |
AdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysqli_query sql injection |
30.09.2026 |
|
| CVE-2026-80490 |
Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified |
30.09.2026 |
|
| CVE-2026-94545 |
Satori-generated SVG has improper escaping |
30.09.2026 |
|
| CVE-2026-103243 |
LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints |
30.09.2026 |
|
| CVE-2026-103270 |
LightLLM through 1.2.0 Missing Authentication on RL Control Routes |
30.09.2026 |
|
| CVE-2026-103395 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service |
30.09.2026 |
|
| CVE-2026-103396 |
bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount |
30.09.2026 |
|
| CVE-2026-103397 |
OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender |
30.09.2026 |
|
| CVE-2026-103398 |
OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path |
30.09.2026 |
|
| CVE-2026-76570 |
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 |
30.09.2026 |
|
| CVE-2026-102717 |
MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash |
30.09.2026 |
|
| CVE-2026-102983 |
Astro: Netlify Image CDN allowlist bypass enables SSRF |
30.09.2026 |
|
| CVE-2026-102984 |
Astro: Malformed port in the Host header can crash the Node adapter |
30.09.2026 |
|
| CVE-2026-103227 |
GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow |
30.09.2026 |
|
| CVE-2026-103388 |
MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field |
30.09.2026 |
|
| CVE-2026-103389 |
MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph |
30.09.2026 |
|
| CVE-2026-47097 |
AJA HELO Plus < 2.1.7 Static AES Passphrase Information Disclosure via /diags |
30.09.2026 |
|
| CVE-2026-101295 |
Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction |
30.09.2026 |
|
| CVE-2026-103222 |
Blosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer overflow |
30.09.2026 |
|
| CVE-2026-103226 |
Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow |
30.09.2026 |
|
| CVE-2026-18782 |
SQL Injection in Trex Digital Manufacturing's Trex MES |
30.09.2026 |
9.8 |
| CVE-2026-18783 |
Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES |
30.09.2026 |
8.8 |
| CVE-2026-62084 |
WordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-62097 |
WordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-97259 |
WordPress Pay with Vipps for WooCommerce plugin <= 6.2.4 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
|
| CVE-2026-93903 |
|
30.09.2026 |
|
| CVE-2026-103118 |
GraphicsMagick WPG File wpg.c ExtractPostscript recursion |
30.09.2026 |
|
| CVE-2026-82307 |
Multiple Vulnerabilities in Dolusoft Software's SOPLOG |
30.09.2026 |
9.8 |
| CVE-2026-91860 |
Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge |
30.09.2026 |
|
| CVE-2026-93547 |
Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells |
30.09.2026 |
|
| CVE-2026-103117 |
OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection |
30.09.2026 |
|
| CVE-2026-76504 |
Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-86778 |
Username Enumeration in Maksisoft Technology's Maksisoft Gym |
30.09.2026 |
5.3 |
| CVE-2026-100507 |
WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-100508 |
WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-100513 |
WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-102384 |
WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
5.9 |
| CVE-2026-102385 |
WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-102386 |
WordPress WP Photo Album Plus plugin <= 9.3.02.003 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-102395 |
WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-102396 |
WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-102398 |
WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-102399 |
WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-103116 |
OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection |
30.09.2026 |
|
| CVE-2026-27085 |
WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability |
30.09.2026 |
2.7 |
| CVE-2026-27371 |
WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-62078 |
WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-62079 |
WordPress Qi Addons For Elementor plugin <= 1.11 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-62080 |
WordPress Happy Addons for Elementor plugin <= 3.23.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-62081 |
WordPress Flexible PDF Coupons plugin <= 1.14.11 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-62083 |
WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-62085 |
WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-93512 |
WordPress JW Player for WordPress plugin <= 2.3.11 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-93514 |
WordPress Notification for Telegram plugin <= 3.5.2 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-93621 |
WordPress WP Data Access plugin <= 5.5.84 - SQL Injection vulnerability |
30.09.2026 |
8.2 |
| CVE-2026-93624 |
WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-93651 |
WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.1.2 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-93770 |
WordPress WP Statistics plugin <= 14.16.13 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-93771 |
WordPress Cost of Goods for WooCommerce plugin <= 3.5.2 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-94074 |
WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-94076 |
WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-94077 |
WordPress Safe SVG plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-94078 |
WordPress Site Reviews plugin <= 8.3.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-94081 |
WordPress WordPress Persistent Login plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-94082 |
WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-94115 |
WordPress Easy Pricing Tables plugin <= 4.1.2 - SQL Injection vulnerability |
30.09.2026 |
8.5 |
| CVE-2026-94120 |
WordPress GravityExport Lite for Gravity Forms plugin <= 2.7.2 - Broken Access Control vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-94121 |
WordPress 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin <= 2.33.6 - PHP Object Injection vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-94122 |
WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-94123 |
WordPress NextGEN Gallery plugin <= 4.5.0 - Arbitrary File Download vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-94173 |
WordPress Business Directory plugin <= 6.4.27 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-94177 |
WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability |
30.09.2026 |
8.5 |
| CVE-2026-94178 |
WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-94389 |
WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability |
30.09.2026 |
9 |
| CVE-2026-94499 |
WordPress FormGent plugin <= 1.12.2 - Broken Access Control vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-94672 |
WordPress Safe SVG plugin <= 2.5.0 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
4.3 |
| CVE-2026-94673 |
WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-94674 |
WordPress Pixel Manager for WooCommerce plugin <= 1.69.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-94677 |
WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-94678 |
WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-94681 |
WordPress WP Store Locator plugin < 3.0.0 - Denial of Service Attack vulnerability |
30.09.2026 |
5.9 |
| CVE-2026-94683 |
WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-95531 |
WordPress Conversational Forms for ChatBot plugin <= 1.5.0 - PHP Object Injection vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-95587 |
WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-96338 |
WordPress Profile Builder plugin <= 4.0.2 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-96343 |
WordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-96344 |
WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-96345 |
WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-96346 |
WordPress WP ERP plugin <= 1.17.9 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-96347 |
WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-96348 |
WordPress Bookly plugin <= 28.2 - Broken Access Control vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-96349 |
WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability |
30.09.2026 |
10 |
| CVE-2026-96350 |
WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-96351 |
WordPress Classified Listing plugin <= 6.1.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96352 |
WordPress YITH WooCommerce Ajax Search plugin <= 2.28.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96450 |
WordPress pixfort Core plugin < 4.3.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-96814 |
WordPress WooCommerce Product Table Lite plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96815 |
WordPress Vitepos plugin <= 3.5.0 - Privilege Escalation vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-96816 |
WordPress Trusted Shops Easy Integration for WooCommerce plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96817 |
WordPress MakeCommerce for WooCommerce plugin <= 4.1.0 - Broken Access Control vulnerability |
30.09.2026 |
8.2 |
| CVE-2026-96818 |
WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Broken Access Control vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-96819 |
WordPress oik plugin <= 4.15.4 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96820 |
WordPress Awesome Support plugin <= 6.3.9 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96821 |
WordPress FluentBoards plugin <= 2.0.12 - Privilege Escalation vulnerability |
30.09.2026 |
6.3 |
| CVE-2026-96822 |
WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability |
30.09.2026 |
9.3 |
| CVE-2026-96823 |
WordPress Customer Reviews for WooCommerce plugin <= 5.120.0 - Arbitrary Content Deletion vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-96824 |
WordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vulnerability |
30.09.2026 |
6.8 |
| CVE-2026-96825 |
WordPress All In One WP Security & Firewall plugin <= 5.4.8 - Bypass Vulnerability vulnerability |
30.09.2026 |
4.2 |
| CVE-2026-96827 |
WordPress Admin Notices Manager plugin <= 1.6.0 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-96828 |
WordPress Category Discount Woocommerce plugin <= 5.18 - SQL Injection vulnerability |
30.09.2026 |
7.6 |
| CVE-2026-96829 |
WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 6.5.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-96830 |
WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96831 |
WordPress Themify Builder plugin <= 7.8.1 - PHP Object Injection vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-96832 |
WordPress Content Egg plugin <= 6.3.1 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-96833 |
WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.51 - PHP Object Injection vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-96834 |
WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-96835 |
WordPress King Addons for Elementor plugin <= 51.1.85 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-96836 |
WordPress Parsi Date plugin <= 6.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-96837 |
WordPress CartFlows plugin <= 3.2.0 - Remote Code Execution (RCE) vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-96838 |
WordPress Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability |
30.09.2026 |
8.8 |
| CVE-2026-97065 |
WordPress Happyforms plugin <= 1.26.15 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97066 |
WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-97067 |
WordPress EWWW Image Optimizer plugin <= 8.7.7 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97074 |
WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin <= 1.9.0 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
4.3 |
| CVE-2026-97077 |
WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97078 |
WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.17 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-97079 |
WordPress Webba Booking plugin <= 6.5.0 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
4.3 |
| CVE-2026-97197 |
WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Control vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-97235 |
WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97236 |
WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97237 |
WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97238 |
WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
5.5 |
| CVE-2026-97239 |
WordPress MCP Content Manager Lite plugin <= 1.1.0 - Broken Access Control vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97240 |
WordPress StifLi Backup Tools plugin <= 2.2.7 - Sensitive Data Exposure vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-97241 |
WordPress BackupEase plugin <= 2.2.2 - Sensitive Data Exposure vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-97242 |
WordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerability |
30.09.2026 |
6.8 |
| CVE-2026-97243 |
WordPress AllAble Connector plugin <= 0.13.4 - Broken Access Control vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-97244 |
WordPress Creator LMS plugin <= 1.2.19 - Path Traversal vulnerability |
30.09.2026 |
7.5 |
| CVE-2026-97245 |
WordPress SureCart plugin <= 4.7.2 - Privilege Escalation vulnerability |
30.09.2026 |
7.2 |
| CVE-2026-97246 |
WordPress ShortPixel Image Optimizer plugin <= 6.5.5 - PHP Object Injection vulnerability |
30.09.2026 |
4.9 |
| CVE-2026-97247 |
WordPress Blocksy Companion plugin <= 2.1.55 - Broken Access Control vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97248 |
WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-97249 |
WordPress Paid Member Subscriptions plugin <= 3.0.9 - Bypass Vulnerability vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-97250 |
WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97253 |
WordPress LayerSlider plugin <= 8.4.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97261 |
WordPress Notivo plugin <= 1.4.2 - Sensitive Data Exposure vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-97262 |
WordPress Visual Composer Website Builder plugin <= 45.16.2 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97266 |
WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97267 |
WordPress Prevent files / folders access plugin <= 2.6.7 - Broken Access Control vulnerability |
30.09.2026 |
4.3 |
| CVE-2026-97270 |
WordPress CMB2 plugin <= 2.13.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97271 |
WordPress WPFunnels plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97272 |
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.13 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97274 |
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-97279 |
WordPress Polylang plugin <= 3.8.9 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97282 |
WordPress Review Schema plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-97285 |
WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-97286 |
WordPress Strong Testimonials plugin <= 3.3.11 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97287 |
WordPress Event Tickets plugin <= 5.29.5 - SQL Injection vulnerability |
30.09.2026 |
8.5 |
| CVE-2026-97288 |
WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97289 |
WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
7.1 |
| CVE-2026-97292 |
WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97293 |
WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability |
30.09.2026 |
8.5 |
| CVE-2026-97298 |
WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97299 |
WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability |
30.09.2026 |
5.4 |
| CVE-2026-97301 |
WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability |
30.09.2026 |
6.5 |
| CVE-2026-97302 |
WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability |
30.09.2026 |
5.3 |
| CVE-2026-103115 |
OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection |
30.09.2026 |
|
| CVE-2026-103321 |
MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image |
30.09.2026 |
|
| CVE-2026-74864 |
Authentication Bypass in sogo_yhn |
30.09.2026 |
|
| CVE-2026-74865 |
Authentication Bypass in sogo_yhn |
30.09.2026 |
|
| CVE-2026-89238 |
Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection |
30.09.2026 |
|
| CVE-2026-92121 |
Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference |
30.09.2026 |
|
| CVE-2026-92899 |
Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce |
30.09.2026 |
|
| CVE-2026-95616 |
Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions |
30.09.2026 |
|
| CVE-2026-85532 |
Apache WSS4J: Insufficient Validation of Derived-Key Parameters |
30.09.2026 |
|
| CVE-2026-87830 |
Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. |
30.09.2026 |
|
| CVE-2026-88920 |
Apache WSS4J: SAML Sender-Vouches Authentication Bypass |
30.09.2026 |
|
| CVE-2026-103242 |
Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag |
30.09.2026 |
|
| CVE-2026-62146 |
Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket |
30.09.2026 |
|
| CVE-2026-10726 |
Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation |
30.09.2026 |
|
| CVE-2026-10739 |
Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation |
30.09.2026 |
|
| CVE-2026-103012 |
|
30.09.2026 |
|
| CVE-2026-103114 |
OS4ED openSIS-Classic Assignment Management Endpoint Assignments.php DBQuery_assignment sql injection |
30.09.2026 |
|
| CVE-2026-13719 |
Alert rules in restricted folders disclosed via the alert rules list API |
30.09.2026 |
4.3 |
| CVE-2026-13720 |
Editor can forge file-provisioning provenance on dashboards via the dashboard API |
30.09.2026 |
5.4 |
| CVE-2026-76992 |
Uncontrolled Memory Allocation in CODESYS Gateway Client |
30.09.2026 |
|
| CVE-2026-96342 |
WordPress WPMobile.App plugin <= 11.83 - Sensitive Data Exposure vulnerability |
30.09.2026 |
|
| CVE-2026-103113 |
OS4ED openSIS-Classic General Information Tab Student.php save action sql injection |
30.09.2026 |
|
| CVE-2026-103239 |
MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection |
30.09.2026 |
|
| CVE-2026-103237 |
MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows |
30.09.2026 |
|
| CVE-2026-10764 |
Information disclosure in BVMS 4.5 up to 12.3 |
30.09.2026 |
8.7 |
| CVE-2026-77185 |
Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
30.09.2026 |
9.1 |
| CVE-2026-93994 |
Apache MINA SSHD: Repeated-publickey policy bypass on server |
30.09.2026 |
8.1 |
| CVE-2026-93995 |
Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the server |
30.09.2026 |
6.5 |
| CVE-2026-93996 |
Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read |
30.09.2026 |
6.5 |
| CVE-2026-94002 |
Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies |
30.09.2026 |
7.5 |
| CVE-2026-94053 |
Apache MINA SSHD: LDAP injection in sshd-ldap |
30.09.2026 |
9.1 |
| CVE-2026-79625 |
Improper Synchronization in Monitoring in CODESYS Control Runtime |
30.09.2026 |
|
| CVE-2026-94029 |
Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension |
30.09.2026 |
6.5 |
| CVE-2026-94052 |
Apache MINA SSHD: LDAP password authentication ineffective |
30.09.2026 |
9.1 |
| CVE-2026-103235 |
MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events |
30.09.2026 |
|
| CVE-2026-102455 |
DigiWin|EasyFlow .NET - Insecure Deserialization |
30.09.2026 |
|
| CVE-2026-102456 |
DigiWin|EasyFlow .NET - SQL Injection |
30.09.2026 |
|
| CVE-2026-102457 |
DigiWin|EasyFlow .NET - Arbitrary File Read |
30.09.2026 |
|
| CVE-2026-102458 |
DigiWin|EasyFlow .NET - Missing Authentication |
30.09.2026 |
|
| CVE-2026-102459 |
DigiWin|EasyFlow .NET - Reflected Cross-site Scripting |
30.09.2026 |
|
| CVE-2026-102577 |
Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass |
30.09.2026 |
|
| CVE-2026-102578 |
Moodle: sql injection in question bank web service |
30.09.2026 |
|
| CVE-2026-102579 |
Moodle: user profile information disclosure via grade web service |
30.09.2026 |
|
| CVE-2026-102580 |
Moodle: arbitrary class instantiation via report builder audience classname |
30.09.2026 |
|
| CVE-2026-102581 |
Moodle: xss in forum post templates due to insufficient escaping |
30.09.2026 |
|
| CVE-2026-102582 |
Moodle: manual enrolment page accessible when plugin disabled |
30.09.2026 |
|
| CVE-2026-102583 |
Moodle: incorrect capability check in ai generate image web service |
30.09.2026 |
|
| CVE-2026-102584 |
Moodle: missing capability check allows unauthorised grade penalty recalculation |
30.09.2026 |
|
| CVE-2026-102585 |
Moodle: group validation missing when enrolling user to course |
30.09.2026 |
|
| CVE-2026-102586 |
Moodle: xss via password reset link due to insufficient username escaping |
30.09.2026 |
|
| CVE-2026-102587 |
Moodle: user list filters bypass profile field visibility |
30.09.2026 |
|
| CVE-2026-102588 |
Moodle: csrf in xml grade import |
30.09.2026 |
|
| CVE-2025-14564 |
Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
30.09.2026 |
6.4 |
| CVE-2026-102454 |
DigiWin|EasyFlow .NET - Arbitrary File Upload |
30.09.2026 |
|
| CVE-2026-102509 |
Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser |
30.09.2026 |
|
| CVE-2026-102510 |
Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths |
30.09.2026 |
|
| CVE-2026-102511 |
Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them |
30.09.2026 |
|
| CVE-2026-75098 |
Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design |
30.09.2026 |
7.5 |
| CVE-2026-92712 |
ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter |
30.09.2026 |
6.4 |
| CVE-2026-93908 |
Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'before_price_text' Parameter |
30.09.2026 |
6.4 |
| CVE-2026-97347 |
Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header |
30.09.2026 |
7.2 |
| CVE-2026-92873 |
|
30.09.2026 |
|
| CVE-2026-102508 |
Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade |
30.09.2026 |
|
| CVE-2026-11895 |
HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting |
30.09.2026 |
6.4 |
| CVE-2026-14876 |
Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block |
30.09.2026 |
6.4 |
| CVE-2026-16596 |
WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter |
30.09.2026 |
6.5 |
| CVE-2026-6170 |
Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute |
30.09.2026 |
6.4 |
| CVE-2026-6171 |
Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute |
30.09.2026 |
6.4 |
| CVE-2026-6172 |
Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'caption' Parameter |
30.09.2026 |
6.4 |
| CVE-2026-6173 |
Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter |
30.09.2026 |
6.4 |
| CVE-2026-6806 |
Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters |
30.09.2026 |
7.5 |
| CVE-2026-88037 |
Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title |
30.09.2026 |
6.4 |
| CVE-2026-92871 |
|
30.09.2026 |
|
| CVE-2026-92872 |
|
30.09.2026 |
|
| CVE-2026-93460 |
|
30.09.2026 |
|
| CVE-2026-93462 |
|
30.09.2026 |
|
| CVE-2026-93463 |
|
30.09.2026 |
|
| CVE-2026-93464 |
|
30.09.2026 |
|
| CVE-2026-92867 |
|
30.09.2026 |
|
| CVE-2026-92868 |
|
30.09.2026 |
|
| CVE-2026-92869 |
|
30.09.2026 |
|
| CVE-2026-92870 |
|
30.09.2026 |
|
| CVE-2026-97150 |
|
30.09.2026 |
|
| CVE-2026-97196 |
WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability |
30.09.2026 |
9.1 |
| CVE-2026-89294 |
Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter |
30.09.2026 |
7.5 |
| CVE-2026-100143 |
FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email |
30.09.2026 |
|
| CVE-2026-75823 |
WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption |
30.09.2026 |
|
| CVE-2026-75824 |
WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled |
30.09.2026 |
|
| CVE-2026-75873 |
Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload |
30.09.2026 |
|
| CVE-2026-80333 |
Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes |
30.09.2026 |
|
| CVE-2026-82127 |
Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields |
30.09.2026 |
|
| CVE-2026-83560 |
New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass |
30.09.2026 |
|
| CVE-2026-85001 |
EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute |
30.09.2026 |
|
| CVE-2026-85415 |
Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL |
30.09.2026 |
|
| CVE-2026-85573 |
All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload |
30.09.2026 |
|
| CVE-2026-85576 |
All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update |
30.09.2026 |
|
| CVE-2026-86789 |
Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes |
30.09.2026 |
|
| CVE-2026-87777 |
Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute |
30.09.2026 |
|
| CVE-2026-88791 |
Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules |
30.09.2026 |
|
| CVE-2026-88797 |
Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation |
30.09.2026 |
|
| CVE-2026-89190 |
Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax |
30.09.2026 |
|
| CVE-2026-89193 |
Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser |
30.09.2026 |
|
| CVE-2026-90953 |
Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks |
30.09.2026 |
|
| CVE-2026-91051 |
EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta |
30.09.2026 |
|
| CVE-2026-91072 |
EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler |
30.09.2026 |
|
| CVE-2026-91832 |
WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF |
30.09.2026 |
|
| CVE-2026-92424 |
Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue |
30.09.2026 |
|
| CVE-2026-92994 |
Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API |
30.09.2026 |
|
| CVE-2026-93580 |
InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook |
30.09.2026 |
|
| CVE-2026-94274 |
YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API |
30.09.2026 |
|
| CVE-2026-94297 |
Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation |
30.09.2026 |
|
| CVE-2026-96886 |
Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export |
30.09.2026 |
|
| CVE-2026-97316 |
Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass |
30.09.2026 |
|
| CVE-2026-102913 |
SourceCodester Car Driving School Management System Master.php save_enrollment sql injection |
30.09.2026 |
|
| CVE-2026-103111 |
|
30.09.2026 |
7.6 |
| CVE-2026-102912 |
SourceCodester Online Leave Management System page reports sql injection |
30.09.2026 |
|
| CVE-2026-102910 |
SourceCodester Online Reviewer Management System exam-delete.php sql injection |
30.09.2026 |
|
| CVE-2026-102911 |
zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection |
30.09.2026 |
|
| CVE-2026-86134 |
Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service |
30.09.2026 |
|
| CVE-2026-103110 |
|
30.09.2026 |
9.8 |
| CVE-2026-102909 |
SourceCodester Online Reviewer Management System btn_functions.php sql injection |
30.09.2026 |
|
| CVE-2026-103109 |
|
30.09.2026 |
7.7 |
| CVE-2026-102908 |
SourceCodester Online Reviewer Management System questions-view.php sql injection |
30.09.2026 |
|
| CVE-2026-103105 |
|
30.09.2026 |
8.8 |
| CVE-2026-103106 |
|
30.09.2026 |
7.8 |
| CVE-2026-103108 |
|
30.09.2026 |
7.5 |
| CVE-2026-102874 |
HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection |
30.09.2026 |
|
| CVE-2026-102906 |
0xshariq github-mcp-server Git Remove MCP Tool github.ts child_process.exec os command injection |
30.09.2026 |
|
| CVE-2026-103099 |
|
30.09.2026 |
7.5 |
| CVE-2026-103100 |
|
30.09.2026 |
7.5 |
| CVE-2026-103101 |
|
30.09.2026 |
8.6 |
| CVE-2026-103102 |
|
30.09.2026 |
8.6 |
| CVE-2026-103104 |
|
30.09.2026 |
7.5 |
| CVE-2026-86556 |
An information disclosure vulnerability in ZTE U30 Air product |
30.09.2026 |
5.3 |
| CVE-2026-96649 |
Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) |
30.09.2026 |
7.2 |
| CVE-2026-102847 |
gedelumbung HospitalManagement Guest Book buku_tamu.php kirim cross site scripting |
30.09.2026 |
|
| CVE-2026-78229 |
|
30.09.2026 |
6.7 |
| CVE-2026-81310 |
|
30.09.2026 |
6.6 |
| CVE-2026-102845 |
gedelumbung HospitalManagement HTTP Response index.php error_reporting information disclosure |
30.09.2026 |
|
| CVE-2026-102846 |
gedelumbung HospitalManagement Configuration sistem.php simpan improper authorization |
30.09.2026 |
|
| CVE-2026-102843 |
gedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversal |
30.09.2026 |
|
| CVE-2026-102844 |
gedelumbung HospitalManagement laporan_data_pasien.php detail authorization |
30.09.2026 |
|
| CVE-2026-103087 |
|
30.09.2026 |
|
| CVE-2026-103088 |
|
30.09.2026 |
7.5 |
| CVE-2026-102804 |
Nothings stb stb_hexwave.h hexwave_init integer overflow |
30.09.2026 |
|
| CVE-2026-102805 |
Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer overflow |
30.09.2026 |
|
| CVE-2026-102842 |
gedelumbung HospitalManagement KCFinder File Manager app_user_login_model.php cekUserLogin unrestricted upload |
30.09.2026 |
|
| CVE-2026-103053 |
AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API |
30.09.2026 |
|
| CVE-2026-103054 |
AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP |
30.09.2026 |
|
| CVE-2026-103055 |
AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret |
30.09.2026 |
|
| CVE-2026-103056 |
AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR |
30.09.2026 |
|
| CVE-2026-103057 |
AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints |
30.09.2026 |
|
| CVE-2026-51936 |
|
30.09.2026 |
|
| CVE-2026-102794 |
Ziroom ZHOME A0101 ping command injection |
30.09.2026 |
|
| CVE-2026-102793 |
Ziroom ZHOME A0101 set_time_zone command injection |
29.09.2026 |
|
| CVE-2026-103048 |
Open Redirect in Special:Book |
29.09.2026 |
|
| CVE-2026-103049 |
XSS in Cargo's Special:CargoQuery page due to unsanitized table headers |
29.09.2026 |
|
| CVE-2026-103050 |
Stored i18n XSS in MassMessage |
29.09.2026 |
|
| CVE-2026-103051 |
Stored i18n XSSs in CentralNotice |
29.09.2026 |
|
| CVE-2026-13046 |
Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution |
30.09.2026 |
|
| CVE-2026-13224 |
Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read |
30.09.2026 |
|
| CVE-2026-18105 |
Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service |
30.09.2026 |
|
| CVE-2026-18145 |
Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution |
30.09.2026 |
|
| CVE-2026-81433 |
Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution |
30.09.2026 |
|
| CVE-2026-86101 |
Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access |
30.09.2026 |
|
| CVE-2026-86104 |
Fireware OS Resource Exhaustion in Login Process Allows Denial of Service |
30.09.2026 |
|
| CVE-2026-86105 |
Fireware OS Improper Authorization in Access Portal Reverse Proxy |
30.09.2026 |
|
| CVE-2026-86128 |
Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service |
30.09.2026 |
|
| CVE-2026-86131 |
Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution |
30.09.2026 |
|
| CVE-2026-86132 |
Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service |
30.09.2026 |
|
| CVE-2026-86133 |
Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service |
30.09.2026 |
|
| CVE-2026-86136 |
Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A |
30.09.2026 |
|
| CVE-2026-90441 |
Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B |
30.09.2026 |
|
| CVE-2026-103047 |
XSS through i18n message in CentralAuth |
29.09.2026 |
|
| CVE-2026-103040 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service |
30.09.2026 |
|
| CVE-2026-103041 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service |
30.09.2026 |
|
| CVE-2026-103042 |
LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_value |
29.09.2026 |
|
| CVE-2026-103043 |
anchorme through 3.0.8 Regular Expression Denial of Service |
29.09.2026 |
|
| CVE-2026-103045 |
XSS in Refreshed skin |
29.09.2026 |
|
| CVE-2026-102792 |
Ziroom ZHOME A0101 set_syslog command injection |
29.09.2026 |
|
| CVE-2026-103044 |
EasyTimeline should not serve image maps as application/xml |
29.09.2026 |
|
| CVE-2026-103046 |
WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML |
29.09.2026 |
|
| CVE-2026-15278 |
|
29.09.2026 |
|
| CVE-2026-102771 |
Naichen ThinkCMF Email Template MailController.php templatePut special elements in template engine |
30.09.2026 |
|
| CVE-2026-69662 |
Toptech TMS7 and TopHAT Eval Injection |
30.09.2026 |
3.7 |
| CVE-2026-71189 |
Toptech TMS7 and TopHAT Cross-site Scripting |
30.09.2026 |
3.5 |
| CVE-2026-68068 |
Toptech TMS7 and TopHAT SQL Injection |
30.09.2026 |
9 |
| CVE-2026-71302 |
Toptech TMS7 and TopHAT Session Fixation |
30.09.2026 |
7.1 |
| CVE-2026-72507 |
Toptech TMS7 and TopHAT SQL Injection |
30.09.2026 |
9 |