CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-105105 Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration 03.10.2026 9.8
CVE-2026-71885 MLS X.509 credential not bound to the LeafNode signature key 03.10.2026 9.2
CVE-2026-92084 Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output 03.10.2026 9.1
CVE-2026-87115 VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter 03.10.2026 9.1
CVE-2026-105080 03.10.2026 9.4
CVE-2026-84411 MikroTik RouterOS Integer Underflow 02.10.2026 9.3
CVE-2026-95102 Monta monta.app Missing Authentication for Critical Function 02.10.2026 9.3
CVE-2026-75937 OS Command Injection in Digi Accelerated Linux (DAL OS) 02.10.2026 9.4
CVE-2026-82042 UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter 02.10.2026 9.3
CVE-2026-104019 OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio 02.10.2026 9.3
CVE-2026-103956 Missing authentication for critical function in Loom for AWS 02.10.2026 10
CVE-2023-54405 H3C CVM Unauthenticated File Upload via fileUpload/upload Token 02.10.2026 9.3
CVE-2026-104848 Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution 02.10.2026 9.5
CVE-2026-104849 Tinypool: Prototype Pollution Gadget to RCE in run() options 02.10.2026 9.5
CVE-2026-103648 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader 02.10.2026 9.1
CVE-2026-104846 Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940) 02.10.2026 9.8
CVE-2026-90970 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 02.10.2026 9.9
CVE-2026-19652 Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter 02.10.2026 9.8
CVE-2026-83632 Apache Thrift: C++ THttpTransport grows its line buffer without bound 02.10.2026 9.2
CVE-2026-104610 Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow 02.10.2026 10
CVE-2026-104611 Tenda AC9 POST Request fast_setting_internet_set stack-based overflow 02.10.2026 9.4
CVE-2026-104467 YesWiki before 4.6.7 Authorization Bypass via Public API Mode 02.10.2026 9.2
CVE-2026-91135 Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) 02.10.2026 9.2
CVE-2026-86325 02.10.2026 9.4
CVE-2026-94541 WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter 02.10.2026 9.8
CVE-2026-97637 JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response 02.10.2026 9.8
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value 02.10.2026 9.1
CVE-2026-93029 02.10.2026 9
CVE-2026-93697 02.10.2026 9
CVE-2026-93698 02.10.2026 9.9
CVE-2026-15896 Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter 02.10.2026 9.1
CVE-2026-19660 Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter 02.10.2026 9.8
CVE-2026-14378 DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow 02.10.2026 9.8
CVE-2026-104480 Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership 02.10.2026 9.4
CVE-2026-86345 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result 02.10.2026 9
CVE-2026-103764 Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport 02.10.2026 9.3
CVE-2026-18397 SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability 02.10.2026 9.4
CVE-2026-71449 02.10.2026 9.3
CVE-2026-55393 Local File Inclusion in Teledyne FLIR Robots running Aware2 01.10.2026 10
CVE-2026-55395 Hardcoded Passwords in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-14984 Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-102628 Cadmos LTI exposure of sensitive information via debug mode 01.10.2026 9.2
CVE-2026-102667 Joyland AI WebView command injection 02.10.2026 9
CVE-2026-53953 GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover 01.10.2026 9.1
CVE-2026-56660 GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction 01.10.2026 9.1
CVE-2026-56662 GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request 01.10.2026 9.6
CVE-2026-104286 02.10.2026 9.8
CVE-2026-55083 DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) 01.10.2026 9.1
CVE-2026-103922 Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path 01.10.2026 9.3
CVE-2026-13043 WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access 01.10.2026 9.3
CVE-2026-96658 Foreman: safemode bypass leading to rce 02.10.2026 9.9
CVE-2026-96659 Foreman: excessive permissions for viewer role on preview 02.10.2026 9.1
CVE-2026-94620 Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 01.10.2026 9.4
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability 01.10.2026 9.8
CVE-2026-79898 Fortra BoKS Manager crlserver command injection vulnerability 01.10.2026 9.1
CVE-2026-103752 WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability 01.10.2026 9.8
CVE-2026-62071 WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability 01.10.2026 9.3
CVE-2026-79901 Predictable Active Directory service-account passwords in BoKS Manager 01.10.2026 9.9
CVE-2026-103244 ground-station before 0.8.0 Authentication Bypass via setup.restore 01.10.2026 9.3
CVE-2026-103264 Fleet before 4.87.0 Authentication Bypass via Device Identifiers 01.10.2026 9.3
CVE-2026-103655 MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period 01.10.2026 9.3
CVE-2026-15989 Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter 01.10.2026 9.8
CVE-2026-75957 Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter 01.10.2026 9.8
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects 01.10.2026 9.3
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted 01.10.2026 9.3
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed 01.10.2026 9.3
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens 01.10.2026 9.3
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process 01.10.2026 9.3
CVE-2026-76142 Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface 01.10.2026 9.3
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field 01.10.2026 9.1
CVE-2026-14157 02.10.2026 9.4
CVE-2026-101283 01.10.2026 9.2
CVE-2026-101276 01.10.2026 9.2
CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication 01.10.2026 9.1
CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102115 Kiteworks Core Authentication Bypass in the Password Reset Workflow 01.10.2026 9.8
CVE-2026-102147 Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) 01.10.2026 9.3
CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control 01.10.2026 9.4
CVE-2026-102992 piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env 30.09.2026 9.2
CVE-2026-103547 30.09.2026 9.2
CVE-2026-100512 WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-103473 Deno 2.7.0 through 2.9.7 Command Injection via node:child_process 02.10.2026 9.2
CVE-2026-103475 yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure 30.09.2026 9.3
CVE-2026-55107 Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) 30.09.2026 10
CVE-2026-55181 Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false 30.09.2026 9.4
CVE-2026-55494 Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset 30.09.2026 9.8
CVE-2026-62308 Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint 30.09.2026 9.1
CVE-2026-55176 Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token 02.10.2026 9
CVE-2026-102489 Undisclosed RCE in Zammad v6.3 and higher 03.10.2026 9.4
CVE-2026-102490 Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha 03.10.2026 9.4
CVE-2026-19445 Use-after-free of a server-side SSLContext when sni_callback switches contexts 03.10.2026 9.2
CVE-2026-75969 PTZOptics Missing Authentication in Firmware Upload 30.09.2026 9.1
CVE-2026-103470 30.09.2026 9.3
CVE-2026-102427 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 30.09.2026 10
CVE-2026-103395 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service 30.09.2026 9.3
CVE-2026-76570 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 30.09.2026 10
CVE-2026-18782 SQL Injection in Trex Digital Manufacturing's Trex MES 30.09.2026 9.8
CVE-2026-93903 30.09.2026 9.4
CVE-2026-82307 Multiple Vulnerabilities in Dolusoft Software's SOPLOG 30.09.2026 9.8
CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 02.10.2026 9.8
CVE-2026-94389 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability 30.09.2026 9
CVE-2026-96349 WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability 30.09.2026 10
CVE-2026-96350 WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability 30.09.2026 9.8
CVE-2026-96822 WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability 30.09.2026 9.3
CVE-2026-97248 WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-97274 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability 30.09.2026 9.8
CVE-2026-74864 Authentication Bypass in sogo_yhn 30.09.2026 9.3
CVE-2026-74865 Authentication Bypass in sogo_yhn 30.09.2026 9.2
CVE-2026-77185 Apache MINA SSHD: Asynchronous authentication can bypass signature verification 30.09.2026 9.1
CVE-2026-94053 Apache MINA SSHD: LDAP injection in sshd-ldap 30.09.2026 9.1
CVE-2026-94052 Apache MINA SSHD: LDAP password authentication ineffective 30.09.2026 9.1
CVE-2026-102455 DigiWin|EasyFlow .NET - Insecure Deserialization 30.09.2026 9.3
CVE-2026-102458 DigiWin|EasyFlow .NET - Missing Authentication 30.09.2026 9.3
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade 30.09.2026 9.2
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability 30.09.2026 9.1
CVE-2026-102911 zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection 30.09.2026 9.4
CVE-2026-103110 02.10.2026 9.8
CVE-2026-103056 AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR 30.09.2026 9.4
CVE-2026-102794 Ziroom ZHOME A0101 ping command injection 30.09.2026 9.4
CVE-2026-102793 Ziroom ZHOME A0101 set_time_zone command injection 01.10.2026 9.4
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution 01.10.2026 9.2
CVE-2026-103040 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service 30.09.2026 9.3
CVE-2026-103041 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service 30.09.2026 9.3
CVE-2026-102792 Ziroom ZHOME A0101 set_syslog command injection 02.10.2026 9.4
CVE-2026-70356 Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type 30.09.2026 9.4
CVE-2026-71379 Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties 30.09.2026 10
CVE-2026-96587 Use of Hard-coded Credentials in Viidure Dashcam Android Application 29.09.2026 10
CVE-2026-53988 Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints 02.10.2026 9.2
CVE-2026-100291 Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 29.09.2026 9.3
CVE-2026-76721 Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs 30.09.2026 9.8
CVE-2026-76722 Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs 01.10.2026 9.8
CVE-2026-76723 Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS 01.10.2026 9.6
CVE-2026-76724 Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol 01.10.2026 9.6
CVE-2026-76725 Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs 01.10.2026 9.6
CVE-2026-102829 simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 30.09.2026 9.2
CVE-2026-102828 simple-git unsafe-operation guard does not block trailer command configuration 30.09.2026 9.2
CVE-2026-84436 IBM Guardium Data Protection is affected by multiple vulnerabilities. 30.09.2026 9.1
CVE-2026-102710 30.09.2026 9.3
CVE-2026-102761 30.09.2026 9.3
CVE-2026-102425 Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 01.10.2026 9.5
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 30.09.2026 9.3
CVE-2026-22094 Weak root password in EVbee DC 80 30.09.2026 9.3
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026 9.3
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026 9.3
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026 9
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026 9.3
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 30.09.2026 9.2
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026 10
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026 9.4
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 01.10.2026 9.3
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 01.10.2026 9.4
CVE-2026-101262 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101261 Ziroom ZHOME A0101 firstSetup_wifi command injection 01.10.2026 9.4
CVE-2026-101260 Ziroom ZHOME A0101 firstLogin command injection 29.09.2026 9.4
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection 29.09.2026 9.1
CVE-2026-101187 Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection 29.09.2026 9.4
CVE-2026-102268 PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard 29.09.2026 9.1
CVE-2026-100752 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 30.09.2026 9.3
CVE-2026-101108 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 30.09.2026 9.3
CVE-2026-101110 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 30.09.2026 9.3
CVE-2026-49994 Bluehood: Missing authentication on Bluehood API routes when web auth is enabled 28.09.2026 9.1
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access 28.09.2026 9.3
CVE-2026-101894 @xhmikosr/decompress: Path traversal via symlink chain 28.09.2026 9.1
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution 28.09.2026 9.3
CVE-2026-101081 D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow 28.09.2026 9.4
CVE-2026-88804 Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher 28.09.2026 9.6
CVE-2026-12342 SailPoint IdentityIQ Improper Form Validation Vulnerability 29.09.2026 9.6
CVE-2026-101076 Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection 01.10.2026 10
CVE-2026-101077 Netcore NR289-GE boa_temp process_request missing authentication 28.09.2026 10
CVE-2026-101075 Netcore NR289-GE Location Time location_time.cgi system os command injection 28.09.2026 10
CVE-2026-101074 Netcore NR289-GE Authentication boa password-check stack-based overflow 28.09.2026 9.3
CVE-2026-90924 Default Admin Credentials in Innotim Software's Logsign SIEM 28.09.2026 9.8
CVE-2026-101072 Netcore NR289-GE CGI ap_ip.cgi system os command injection 28.09.2026 10
CVE-2026-73640 Time-based SQL Injection in Dayforce Payroll 28.09.2026 9.3
CVE-2026-73642 Path Traversal in Dayforce Payroll 28.09.2026 9.2
CVE-2026-85185 Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root 28.09.2026 9.6
CVE-2026-85526 Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD 29.09.2026 9.9
CVE-2026-87799 Arbitrary file write on LXD host via symlink in migration stream 29.09.2026 9.9
CVE-2026-81867 Deserialization of Untrusted Data in Application Integration allows Remote Code Execution 30.09.2026 9.4
CVE-2026-101039 FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow 28.09.2026 10
CVE-2026-101038 FAST FAC1200R MmtAtePrase stack-based overflow 28.09.2026 9.4
CVE-2026-19759 Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution 28.09.2026 9.4
CVE-2026-101037 FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow 01.10.2026 9.4
CVE-2026-82384 Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint 29.09.2026 9.8
CVE-2026-82377 Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers 29.09.2026 9.9
CVE-2026-82378 Apache Roller: OAuth authorization endpoint trusts request-supplied identity 29.09.2026 9
CVE-2026-101008 aaPanel BaoTa File Merge files.py merge_split_file command injection 28.09.2026 9.4
CVE-2026-101009 aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection 01.10.2026 9.3
CVE-2026-101007 aaPanel BaoTa Database Backup database.py InputSql os command injection 28.09.2026 9.3
CVE-2026-101002 Netcore NBR200V2 Tools Ping network_tools system os command injection 28.09.2026 9.4
CVE-2026-101001 Netcore NBR200V2 Web Management network_tools eval os command injection 28.09.2026 10
CVE-2026-101000 Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization 01.10.2026 10
CVE-2026-100896 TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection 28.09.2026 9.4
CVE-2026-100886 Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication 28.09.2026 10
CVE-2026-101065 Obot Quickstart Docker Deployment Unauthenticated Admin Access 30.09.2026 9.3
CVE-2026-101084 obot before v0.21.1 Authorization Bypass via /mcp-connect 30.09.2026 9.3
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri 28.09.2026 9.3
CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands 29.09.2026 9.5
CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 28.09.2026 9.5
CVE-2026-88773 HTTP Request Smuggling 29.09.2026 9.3
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 28.09.2026 9.8
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 28.09.2026 9.5
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 30.09.2026 9.1
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 28.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-103065 WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability 03.10.2026 8.2
CVE-2026-103342 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability 03.10.2026 7.1
CVE-2026-105112 Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints 03.10.2026
CVE-2026-105113 Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock 03.10.2026
CVE-2026-105114 OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page 03.10.2026
CVE-2026-105115 OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface 03.10.2026
CVE-2026-105116 OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page 03.10.2026
CVE-2026-105117 OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions 03.10.2026
CVE-2026-105118 OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession 03.10.2026
CVE-2026-105119 OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows 03.10.2026
CVE-2026-105120 OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint 03.10.2026
CVE-2026-105121 OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping 03.10.2026
CVE-2026-105122 OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri 03.10.2026
CVE-2026-105105 Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration 03.10.2026 9.8
CVE-2026-104983 Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversal 03.10.2026
CVE-2026-18040 HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler 03.10.2026
CVE-2026-71890 MLS external commit can remove an arbitrary group member 03.10.2026
CVE-2026-71891 BLS12-381 key validation accepts a public key built on a foreign curve 03.10.2026
CVE-2026-71885 MLS X.509 credential not bound to the LeafNode signature key 03.10.2026
CVE-2026-71886 OpenPGP certification accepted from a subkey without certification authority 03.10.2026
CVE-2026-71883 Native AES packet cipher returns the raw AES key on an alias 03.10.2026
CVE-2026-71887 OpenPGP data signature accepted from a signing subkey without cross-certification 03.10.2026
CVE-2026-71888 CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent 03.10.2026
CVE-2026-71889 PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate 03.10.2026
CVE-2026-71892 CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys 03.10.2026
CVE-2026-85515 OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check 03.10.2026
CVE-2026-97873 Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider 03.10.2026
CVE-2026-104982 Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal 03.10.2026
CVE-2026-92084 Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output 03.10.2026 9.1
CVE-2026-92767 Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'offset' Shortcode Attribute 03.10.2026 6.4
CVE-2026-100157 WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode) 03.10.2026 6.5
CVE-2026-103421 WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/search/<value>/0' Path Segment 03.10.2026 5.4
CVE-2026-103519 WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter 03.10.2026 5.4
CVE-2026-104313 WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via 'rule_data' Parameter 03.10.2026 6.1
CVE-2026-11601 WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete 03.10.2026 5.3
CVE-2026-15795 Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 03.10.2026 6.4
CVE-2026-18443 Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter 03.10.2026 8.8
CVE-2026-75028 WPCafe <= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting 03.10.2026 7.5
CVE-2026-87115 VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter 03.10.2026 9.1
CVE-2026-92974 Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_url' Parameter 03.10.2026 6.1
CVE-2026-93889 Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message 03.10.2026 7.2
CVE-2026-93896 WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUEST_URI 03.10.2026 6.1
CVE-2026-94505 Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter 03.10.2026 8.1
CVE-2026-96267 WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter 03.10.2026 7.5
CVE-2026-97343 Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link Authentication Bypass via 'burst_share_token' 03.10.2026 4.3
CVE-2026-97660 WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name 03.10.2026 7.2
CVE-2026-101159 WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission 03.10.2026
CVE-2026-101160 WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating 03.10.2026
CVE-2026-101161 WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode 03.10.2026
CVE-2026-101162 WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings 03.10.2026
CVE-2026-103293 MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import 03.10.2026
CVE-2026-103514 WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay 03.10.2026
CVE-2026-80517 WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload 03.10.2026
CVE-2026-80518 WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path 03.10.2026
CVE-2026-85015 Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Traversal 03.10.2026
CVE-2026-85568 Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parameter 03.10.2026
CVE-2026-86832 MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API 03.10.2026
CVE-2026-86834 MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integration 03.10.2026
CVE-2026-88782 Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attribute 03.10.2026
CVE-2026-88783 Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content 03.10.2026
CVE-2026-89236 SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'sort_order' Parameters 03.10.2026
CVE-2026-91078 TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN 03.10.2026
CVE-2026-92437 Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion 03.10.2026
CVE-2026-92923 Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_data 03.10.2026
CVE-2026-94238 Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter 03.10.2026
CVE-2026-94239 Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration 03.10.2026
CVE-2026-96962 Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code 03.10.2026
CVE-2025-12828 Ultra Addons Lite for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget 03.10.2026 6.4
CVE-2026-100148 Rich Showcase for Google Reviews <= 7.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API) 03.10.2026 6.4
CVE-2026-100149 WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`… 03.10.2026 5.3
CVE-2026-100152 All in One SEO <= 5.0.2 - Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter 03.10.2026 6.5
CVE-2026-101357 SEOPress <= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'seopress_google_analytics_matomo_id' Parameter 03.10.2026 4.9
CVE-2026-101923 Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter 03.10.2026 8.1
CVE-2026-101928 Magic Tooltips For Contact Form 7 <= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author 03.10.2026 7.2
CVE-2026-103888 WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter 03.10.2026 6.1
CVE-2026-103909 Calculated Fields Form <= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation 03.10.2026 6.1
CVE-2026-103913 GeoDirectory <= 2.8.186 - Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing 03.10.2026 7.5
CVE-2026-11399 Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter 03.10.2026 4.3
CVE-2026-87091 Welcart e-Commerce <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters 03.10.2026 7.2
CVE-2026-91108 Alt Text AI <= 1.10.41 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Content Modification via atai_enrich_post_content AJAX Action 03.10.2026 4.3
CVE-2026-93430 GD Rating System <= 3.7.1 - Unauthenticated Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX 03.10.2026 7.2
CVE-2026-96564 SEOPress <= 10.2 - Unauthenticated Stored Cross-Site Scripting via Author Display Name 03.10.2026 7.2
CVE-2026-96575 Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder 03.10.2026 7.2
CVE-2026-96650 Strong Testimonials <= 3.3.11 - Unauthenticated Stored Cross-Site Scripting via 'platform_user_photo' Custom Field 03.10.2026 7.2
CVE-2026-97337 Simple Membership <= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints 03.10.2026 7.5
CVE-2026-97341 Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header 03.10.2026 7.2
CVE-2026-97344 Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write 03.10.2026 6.4
CVE-2026-92536 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields 03.10.2026 8.8
CVE-2026-92538 LearnPress <= 4.4.7 - Reflected DOM-Based Cross-Site Scripting via 'orderby' Parameter 03.10.2026 6.1
CVE-2026-92551 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter 03.10.2026 6.1
CVE-2026-92727 EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute 03.10.2026 6.4
CVE-2026-92826 EWWW Image Optimizer <= 8.7.7 - Reflected Cross-Site Scripting via REQUEST_URI Parameter Key 03.10.2026 6.1
CVE-2026-92977 Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via Comment 03.10.2026 7.2
CVE-2026-97644 Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test 03.10.2026 8.8
CVE-2026-100180 Jeg Kit for Elementor <= 3.2.19 - Unauthenticated Stored Cross-Site Scripting via Comment 03.10.2026 5.4
CVE-2026-92243 Ivory Search <= 5.5.18 - Reflected DOM-Based Cross-Site Scripting via 's' Parameter 03.10.2026 6.1
CVE-2026-93428 Ultimate Member <= 2.13.1 - Missing Authorization to Unauthenticated Sensitive Profile Field Disclosure via Member Directory Field Privacy Bypass 03.10.2026 7.5
CVE-2026-94378 SupportCandy <= 3.5.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'name' Parameter 03.10.2026 6.4
CVE-2026-94539 SupportCandy <= 3.5.3 - Authenticated (Custom+) SQL Injection via 'sort_by' Parameter 03.10.2026 6.5
CVE-2026-95865 Beaver Builder Page Builder <= 2.11.0.5 - Authenticated (Contributor+) SQL Injection via 'fields[][value]' Parameter 03.10.2026 6.5
CVE-2026-96270 Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'form_id' Parameter 03.10.2026 7.2
CVE-2026-105090 03.10.2026
CVE-2026-105083 ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE 03.10.2026
CVE-2026-105080 03.10.2026
CVE-2026-79113 03.10.2026
CVE-2026-104433 Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString 02.10.2026
CVE-2026-104474 OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update 02.10.2026
CVE-2026-104475 IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload 02.10.2026
CVE-2026-104476 Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive 02.10.2026
CVE-2026-104477 Showdown through 2.1.0 XSS via unescaped quote in href and src attributes 02.10.2026
CVE-2026-104478 Formwork before 2.3.13 Path Traversal via BackupController Download and Delete 02.10.2026
CVE-2026-104479 Shopclass before 6.2.0 Stored XSS via Listing Description Field 02.10.2026
CVE-2026-105029 UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint 02.10.2026
CVE-2026-105030 Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API 02.10.2026
CVE-2026-105051 02.10.2026 1.9
CVE-2026-105050 02.10.2026
CVE-2026-105048 02.10.2026 4
CVE-2026-105049 02.10.2026 5.8
CVE-2026-84411 MikroTik RouterOS Integer Underflow 02.10.2026 9.8
CVE-2026-105046 02.10.2026 4.3
CVE-2026-94591 Armatura LLC Armatura One Use of Hard-coded Cryptographic Key 02.10.2026 8.4
CVE-2026-94592 Armatura LLC Armatura One Use of Hard-coded Credentials 02.10.2026 8.4
CVE-2026-94593 Armatura LLC Armatura One Insertion of Sensitive Information into Log File 02.10.2026 7.8
CVE-2026-94594 Armatura LLC Armatura One Insertion of Sensitive Information into Log File 02.10.2026 4