| CVE-2026-105844 |
Payload: Prototype pollution in Payload Import Export plugin |
06.10.2026 |
|
| CVE-2026-105845 |
Payload: SQL Injection in SQLite and Postgres |
06.10.2026 |
9.8 |
| CVE-2026-105806 |
Payload: Improper access control for MCP API keys |
06.10.2026 |
|
| CVE-2026-105950 |
getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site scripting |
06.10.2026 |
|
| CVE-2026-26287 |
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration |
06.10.2026 |
7.1 |
| CVE-2026-105804 |
Payload: Password hashes use insufficient PBKDF2 iterations |
06.10.2026 |
|
| CVE-2026-105805 |
Payload: Sort queries could expose protected field information |
06.10.2026 |
|
| CVE-2026-63689 |
|
06.10.2026 |
6.5 |
| CVE-2026-63690 |
|
06.10.2026 |
5.4 |
| CVE-2026-63691 |
|
06.10.2026 |
6.1 |
| CVE-2026-70411 |
|
06.10.2026 |
7.1 |
| CVE-2026-61411 |
|
06.10.2026 |
7.7 |
| CVE-2026-67270 |
|
06.10.2026 |
8.2 |
| CVE-2026-67273 |
|
06.10.2026 |
9.6 |
| CVE-2026-76105 |
|
06.10.2026 |
7.7 |
| CVE-2025-8352 |
Denial-of-service vulnerability in ESET PROTECT On-Prem |
06.10.2026 |
|
| CVE-2026-104069 |
HortusFox < 6.2 Remote Code Execution via Theme Import |
06.10.2026 |
|
| CVE-2026-105801 |
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation |
06.10.2026 |
|
| CVE-2026-54472 |
|
06.10.2026 |
9.8 |
| CVE-2026-61421 |
|
06.10.2026 |
9.8 |
| CVE-2026-105799 |
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values |
06.10.2026 |
|
| CVE-2026-105800 |
i18next-http-backend incomplete URL validation permits SSRF |
06.10.2026 |
3.7 |
| CVE-2026-105922 |
vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of service |
06.10.2026 |
|
| CVE-2026-67269 |
|
06.10.2026 |
9.9 |
| CVE-2026-63688 |
|
06.10.2026 |
10 |
| CVE-2026-63692 |
|
06.10.2026 |
10 |
| CVE-2026-105791 |
Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injection |
06.10.2026 |
7.5 |
| CVE-2026-105792 |
Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager |
06.10.2026 |
6.5 |
| CVE-2026-105793 |
Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` |
06.10.2026 |
9.1 |
| CVE-2026-105794 |
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL |
06.10.2026 |
|
| CVE-2026-105795 |
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests |
06.10.2026 |
3.1 |
| CVE-2026-105796 |
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators |
06.10.2026 |
8.8 |
| CVE-2026-105797 |
SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spawn through MCP stdio transport) |
06.10.2026 |
8.8 |
| CVE-2026-105798 |
SimpleChat: Stored XSS via group document filename in inline onclick handler |
06.10.2026 |
8.7 |
| CVE-2026-105921 |
Kusalkasilva Learning-Management-System search_class.php sql injection |
06.10.2026 |
|
| CVE-2026-105788 |
Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and launch_app |
06.10.2026 |
8.8 |
| CVE-2026-105789 |
Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool |
06.10.2026 |
5.4 |
| CVE-2026-105790 |
Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinning via redirects |
06.10.2026 |
6.4 |
| CVE-2026-106037 |
Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service |
06.10.2026 |
|
| CVE-2026-106038 |
Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remove RPCs |
06.10.2026 |
|
| CVE-2026-106039 |
Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task RPC |
06.10.2026 |
|
| CVE-2026-106040 |
Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC |
06.10.2026 |
|
| CVE-2026-106041 |
Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC |
06.10.2026 |
|
| CVE-2026-34498 |
L4L |
06.10.2026 |
|
| CVE-2026-85523 |
OS Command Injection in Felisify Informatics' SambaBox |
06.10.2026 |
8.8 |
| CVE-2026-77178 |
|
06.10.2026 |
|
| CVE-2026-91140 |
OS command injection in Progress Software Autonomous REST Connector GenAI Agents |
06.10.2026 |
9.6 |
| CVE-2025-15591 |
Cross-Site Scripting (XSS) vulnerability identified in OpenText™ Content Management |
06.10.2026 |
|
| CVE-2026-105837 |
libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow |
06.10.2026 |
|
| CVE-2026-105838 |
libmikmod before 3.3.14 Heap Out-of-Bounds Read via IT Module Loader |
06.10.2026 |
|
| CVE-2026-105839 |
libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD |
06.10.2026 |
|
| CVE-2026-105840 |
lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath() |
06.10.2026 |
|
| CVE-2026-105841 |
lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode |
06.10.2026 |
|
| CVE-2026-105842 |
lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname |
06.10.2026 |
|
| CVE-2026-105920 |
Kusalkasilva Learning-Management-System Student Registration Endpoint student_signup.php sql injection |
06.10.2026 |
|
| CVE-2026-106026 |
tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule |
06.10.2026 |
|
| CVE-2026-77050 |
Potential denial-of-service vulnerability in get_supported_language_variant() |
06.10.2026 |
|
| CVE-2026-82924 |
PII Enumeration via Missing Rate Limiting in Pusula Communication's Expert Mail |
06.10.2026 |
5.3 |
| CVE-2026-84429 |
Potential denial-of-service vulnerability in HTTP header parsing |
06.10.2026 |
|
| CVE-2026-87890 |
Potential request forgery via spatial lookup byte values |
06.10.2026 |
|
| CVE-2026-87975 |
Privilege abuse in model formsets with editable primary keys |
06.10.2026 |
|
| CVE-2026-12380 |
Reflected XSS in Akıllı Ticaret's E-Commerce Pack |
06.10.2026 |
6.1 |
| CVE-2026-105834 |
Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source |
06.10.2026 |
|
| CVE-2026-105835 |
PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint |
06.10.2026 |
|
| CVE-2026-105836 |
QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms |
06.10.2026 |
|
| CVE-2026-105919 |
Kusalkasilva Learning-Management-System Administrator Login Endpoint login.php mysql_query sql injection |
06.10.2026 |
|
| CVE-2026-106016 |
Mitigation bypass in the File Handling component |
06.10.2026 |
|
| CVE-2026-82531 |
Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache |
06.10.2026 |
|
| CVE-2026-56596 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
06.10.2026 |
3.5 |
| CVE-2026-105918 |
Kusalkasilva Learning-Management-System Login Endpoint login.php mysql_error sql injection |
06.10.2026 |
|
| CVE-2026-75818 |
Heap Buffer Overflow in GNU Aspell's prezip utility |
06.10.2026 |
|
| CVE-2026-75819 |
Out-of-bounds Read in GNU Aspell |
06.10.2026 |
|
| CVE-2026-75820 |
Integer Truncation Leading to Heap Corruption in GNU Aspell |
06.10.2026 |
|
| CVE-2026-103831 |
Insecure deserialization in the TrueLayer Magento 2 plugin |
06.10.2026 |
|
| CVE-2026-105985 |
Authenticated RCE via render-components Entry Type overrides |
06.10.2026 |
|
| CVE-2026-84854 |
Out of Bound Write on WibuKey for Windows |
06.10.2026 |
7 |
| CVE-2026-80327 |
Open Redirect in PingGateway Fragment Filter |
06.10.2026 |
|
| CVE-2026-100518 |
WordPress Advanced Google reCAPTCHA plugin <= 5.40 - Broken Authentication vulnerability |
06.10.2026 |
5.3 |
| CVE-2026-102387 |
WordPress Xserver Migrator plugin <= 1.6.6 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-102915 |
WordPress WPO365 plugin <= 44.1 - Broken Access Control vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-104385 |
WordPress Groundhogg plugin <= 4.8.3 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-104387 |
WordPress PowerPress Podcasting plugin <= 11.17.9 - Broken Access Control vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-104394 |
WordPress Charitable plugin <= 1.8.12.3 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-104395 |
WordPress picu plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-104399 |
WordPress Motors plugin <= 1.4.124 - Sensitive Data Exposure vulnerability |
06.10.2026 |
|
| CVE-2026-104405 |
WordPress GiveWP plugin <= 4.17.0 - Privilege Escalation vulnerability |
06.10.2026 |
8.1 |
| CVE-2026-104406 |
WordPress picu plugin <= 3.10.1 - Broken Access Control vulnerability |
06.10.2026 |
7.3 |
| CVE-2026-104670 |
WordPress LearnPress plugin <= 4.4.9 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-104672 |
WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-104747 |
WordPress Haaken theme <= 1.5 - PHP Object Injection vulnerability |
06.10.2026 |
8.1 |
| CVE-2026-104757 |
WordPress Import and export users and customers plugin <= 2.5.5 - Privilege Escalation vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-104814 |
WordPress Form Block plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-105057 |
WordPress Zero Spam plugin <= 5.7.11 - Bypass vulnerability vulnerability |
06.10.2026 |
5.3 |
| CVE-2026-105058 |
WordPress WP User Profiles plugin <= 2.7.3 - Privilege Escalation vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-105059 |
WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Control vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-105061 |
WordPress WP Mailster plugin <= 1.9.0.0 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-105070 |
WordPress Salon booking system plugin <= 10.31.7 - Privilege Escalation vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-105071 |
WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.17 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-105317 |
WordPress Paid Member Subscriptions plugin <= 3.1.1 - SQL Injection vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-25433 |
WordPress WP2LEADS plugin <= 3.5.7 - Broken Access Control vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-25434 |
WordPress WP2LEADS plugin <= 3.5.7 - SQL Injection vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-32557 |
WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-32568 |
WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-32569 |
WordPress WP Media folder plugin <= 6.2.2 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32570 |
WordPress Progressify - Progressive Web App (PWA) plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32571 |
WordPress Ohio Extra plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-32572 |
WordPress WP User Frontend Pro plugin <= 4.2.13 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32574 |
WordPress Smart Forms plugin <= 2.6.104 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32575 |
WordPress SUMO Affiliates Pro plugin <= 11.7.0 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32577 |
WordPress Frontend File Manager plugin <= 23.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32578 |
WordPress ECPay Ecommerce for WooCommerce plugin <= 1.1.2606090 - Broken Access Control vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-32579 |
WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability |
06.10.2026 |
10 |
| CVE-2026-32580 |
WordPress WooCommerce Lottery plugin <= 2.2.9 - SQL Injection vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-32581 |
WordPress Mooberry Book Manager plugin 4.16.2 - SQL Injection vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39719 |
WordPress PDF Smart Viewer for Elementor plugin <= 1.0.4 - Server Side Request Forgery (SSRF) vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-39720 |
WordPress Mapster WP Maps plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39722 |
WordPress WPLMS theme <= 4.972 - Reflected Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39724 |
WordPress HTTP Requests Manager plugin <= 1.3.11 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39725 |
WordPress Content Visibility for Divi Builder plugin <= 5.03 - Remote Code Execution (RCE) vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-39726 |
WordPress Lumise Product Designer plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39727 |
WordPress WC Fields Factory plugin <= 4.1.12 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39728 |
WordPress Instapage Plugin plugin <= 3.7.2 - Server Side Request Forgery (SSRF) vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-39729 |
WordPress Edwiser Bridge plugin <= 4.3.4 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-39730 |
WordPress Wise Chat plugin <= 3.4.2 - Broken Access Control vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39731 |
WordPress Database for CF7 plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39745 |
WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39746 |
WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39747 |
WordPress Woffice theme <= 5.4.35 - SQL Injection vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-39748 |
WordPress EduMall theme <= 4.5.3 - Reflected Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39749 |
WordPress App for Cloudflare® plugin <= 1.10.1 - Broken Access Control vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39750 |
WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39751 |
WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-39752 |
WordPress Jobs for WordPress plugin <= 2.8.2 - Arbitrary File Deletion vulnerability |
06.10.2026 |
7.7 |
| CVE-2026-39753 |
WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability |
06.10.2026 |
9.8 |
| CVE-2026-39754 |
WordPress Piotnet Addons For Elementor plugin <= 7.1.71 - Arbitrary File Download vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39755 |
WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-39756 |
WordPress Wappointment plugin <= 2.7.7 - Insecure Direct Object References (IDOR) vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39757 |
WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-39758 |
WordPress Midtrans-WooCommerce plugin <= 2.32.3 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39759 |
WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-39761 |
WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability |
06.10.2026 |
9.8 |
| CVE-2026-39762 |
WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.17.1 - Broken Access Control vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39764 |
WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39765 |
WordPress Challan plugin <= 3.7.88 - Privilege Escalation vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-39766 |
WordPress ARForms plugin <= 7.1.2 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39767 |
WordPress WPBase Cache plugin <= 5.5.6 - Denial of Service Attack vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39768 |
WordPress Security & Malware scan by CleanTalk plugin <= 2.189 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39769 |
WordPress Graphina plugin <= 3.1.12 - Broken Authentication vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-39770 |
WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability |
06.10.2026 |
10 |
| CVE-2026-39771 |
WordPress Buddyboss Platform plugin <= 3.1.0 - SQL Injection vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-39772 |
WordPress Captcha by BestWebSoft plugin <= 5.2.8 - Bypass Vulnerability vulnerability |
06.10.2026 |
5.3 |
| CVE-2026-39773 |
WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability |
06.10.2026 |
10 |
| CVE-2026-39774 |
WordPress Tourfic Pro plugin <= 1.17.3 - Privilege Escalation vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-39775 |
WordPress JobZilla - Job Board WordPress Theme theme <= 2.2 - Privilege Escalation vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-39776 |
WordPress Tabs plugin <= 2.5 - Remote Code Execution (RCE) vulnerability |
06.10.2026 |
8 |
| CVE-2026-39778 |
WordPress Ansar Import – One Click Starter Sites – for Elementor & Themes plugin <= 2.1.2 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39780 |
WordPress Youzify plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39781 |
WordPress Document Gallery plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39784 |
WordPress Hotel Booking plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39785 |
WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39787 |
WordPress 10Web Social Photo Feed plugin <= 1.4.35 - Broken Access Control vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39788 |
WordPress Front End PM plugin <= 11.4.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39790 |
WordPress VikRentCar plugin <= 1.4.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39791 |
WordPress Mailjet Email Marketing plugin <= 6.2.3 - Sensitive Data Exposure vulnerability |
06.10.2026 |
5.3 |
| CVE-2026-39792 |
WordPress Simple File List plugin <= 6.3.11 - Arbitrary File Deletion vulnerability |
06.10.2026 |
8.6 |
| CVE-2026-39793 |
WordPress Simple JWT Login plugin 4.0.0 - Broken Authentication vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-39794 |
WordPress WooCommerce Multivendor Marketplace – REST API plugin <= 1.6.3 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-39795 |
WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39796 |
WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-39797 |
WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability |
06.10.2026 |
9.8 |
| CVE-2026-39798 |
WordPress TrueBooker plugin <= 1.2.9 - Settings Change vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-40806 |
WordPress Blog, Posts and Category Filter for Elementor plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-40807 |
WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-41555 |
WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-41559 |
WordPress SafeSnap – Verified WordPress Backup & Restore plugin <= 2.1.2 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-41560 |
WordPress WXD Backup Lite plugin <= 1.0.2 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-41561 |
WordPress Museder RestoreOne plugin <= 2.7.276 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-41562 |
WordPress Norvis Backup plugin <= 1.1.0 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-42413 |
WordPress Snapshotify – All-in-One Backup & Restore & Migrate plugin <= 1.3.2 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-42414 |
WordPress ListingPro plugin <= 2.9.12 - SQL Injection vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-42415 |
WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-42416 |
WordPress UDesign Core plugin <= 4.15.0 - SQL Injection vulnerability |
06.10.2026 |
8.5 |
| CVE-2026-42417 |
WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-42418 |
WordPress Social Rocket plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-42634 |
WordPress Video Background Block – Use video as background in the section. plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-42635 |
WordPress WooCommerce Simple Auctions plugin <= 3.0.10 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-42636 |
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.6 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-42637 |
WordPress PayPlug for WooCommerce (Official) plugin <= 3.1.0 - Settings Change vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-42638 |
WordPress Easy Digital Downloads plugin <= 3.7.1 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-48197 |
WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability |
06.10.2026 |
7.2 |
| CVE-2026-48199 |
WordPress Sermon'e plugin <= 1.0.2 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-62072 |
WordPress Progress Planner plugin <= 1.10.0 - Broken Access Control vulnerability |
06.10.2026 |
8.8 |
| CVE-2026-66588 |
WordPress The7 theme <= 14.2.2 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-94206 |
Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds |
06.10.2026 |
|
| CVE-2026-94675 |
WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-95105 |
Cloak AES-CTR cipher lacks ciphertext authentication, allowing chosen-plaintext forgery by bit flipping |
06.10.2026 |
|
| CVE-2026-95526 |
WordPress BEAR plugin <= 1.2.2 - Broken Access Control vulnerability |
06.10.2026 |
7.3 |
| CVE-2026-95594 |
WordPress SMS Alert Order Notifications plugin <= 4.0.0 - Privilege Escalation vulnerability |
06.10.2026 |
8.1 |
| CVE-2026-97308 |
WordPress Login Lockdown plugin <= 2.17 - Bypass Vulnerability vulnerability |
06.10.2026 |
4.8 |
| CVE-2026-98165 |
drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only |
06.10.2026 |
|
| CVE-2026-98166 |
drm/ttm: fix swapped-out resources never leaving their bulk_move range |
06.10.2026 |
|
| CVE-2026-98167 |
smb: client: fix server->total_read for compound encrypted PDUs |
06.10.2026 |
|
| CVE-2026-98168 |
smb: client: fix reparse buffer bounds in cifs_query_reparse_point() |
06.10.2026 |
|
| CVE-2026-98169 |
smb: client: fix potential OOB read in smb3_enum_snapshots() |
06.10.2026 |
|
| CVE-2026-98170 |
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() |
06.10.2026 |
|
| CVE-2026-98171 |
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs |
06.10.2026 |
|
| CVE-2026-98172 |
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error |
06.10.2026 |
|
| CVE-2026-98173 |
smb: client: fix use-after-free of iface in cifs_try_adding_channels() |
06.10.2026 |
|
| CVE-2026-98174 |
smb: client: fix rlist race and missing initialization |
06.10.2026 |
|
| CVE-2026-98175 |
smb: client: cancel reconnect work in clean_demultiplex_info() |
06.10.2026 |
|
| CVE-2026-98176 |
drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc |
06.10.2026 |
|
| CVE-2026-98177 |
drm/amdkfd: Avoid integer underflow in EOP ring size calculation. |
06.10.2026 |
|
| CVE-2026-98178 |
drm/amdgpu: Skip KFD mapping clear before initialization |
06.10.2026 |
|
| CVE-2026-98179 |
drm/amdgpu: fix rmmio iounmap skipped on device removal |
06.10.2026 |
|
| CVE-2026-98180 |
drm/msm: RCU-free the scheduler-containing ring and VM objects |
06.10.2026 |
|
| CVE-2026-98181 |
drm/gud: fix out-of-bounds write in gud_plane_atomic_check() |
06.10.2026 |
|
| CVE-2026-98182 |
wifi: mac80211: refuse to make a monitor active when it has no queue |
06.10.2026 |
|
| CVE-2026-98183 |
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements |
06.10.2026 |
|
| CVE-2026-98184 |
wifi: mwifiex: prevent authentication frame length truncation |
06.10.2026 |
|
| CVE-2026-98185 |
wifi: mwifiex: validate scan response extents |
06.10.2026 |
|
| CVE-2026-98186 |
wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length |
06.10.2026 |
|
| CVE-2026-98187 |
wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST |
06.10.2026 |
|
| CVE-2026-98188 |
wifi: p54: validate curve data length in the calibration curve converters |
06.10.2026 |
|
| CVE-2026-98189 |
wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() |
06.10.2026 |
|
| CVE-2026-98190 |
wifi: wilc1000: fix out-of-bounds read in P2P public action frames |
06.10.2026 |
|
| CVE-2026-98191 |
wifi: wlcore: release runtime PM ref on regdomain config failure |
06.10.2026 |
|
| CVE-2026-98192 |
wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown |
06.10.2026 |
|
| CVE-2026-98193 |
wifi: libipw: reject TKIP frames without a full MIC |
06.10.2026 |
|
| CVE-2026-98194 |
wifi: libertas_tf: fix UAF in lbtf_free_adapter() |
06.10.2026 |
|
| CVE-2026-98195 |
wifi: iwlegacy: fix broadcast stations deallocation |
06.10.2026 |
|
| CVE-2026-98196 |
wifi: brcmsmac: fix UAF in brcms_free_timer() |
06.10.2026 |
|
| CVE-2026-98197 |
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove |
06.10.2026 |
|
| CVE-2026-98198 |
hwmon: (pwm-fan) Stop RPM timer before freeing tach data |
06.10.2026 |
|
| CVE-2026-98199 |
hwmon: (pmbus/core) increase number of phases and add new mask |
06.10.2026 |
|
| CVE-2026-98200 |
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() |
06.10.2026 |
|
| CVE-2026-98201 |
Input: zero ff_effect before compat copy in input_ff_effect_from_user |
06.10.2026 |
|
| CVE-2026-98202 |
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound |
06.10.2026 |
|
| CVE-2026-98203 |
Input: soc_button_array - check btns_desc->package.count |
06.10.2026 |
|
| CVE-2026-98204 |
Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() |
06.10.2026 |
|
| CVE-2026-98205 |
Input: evdev - zero absinfo before partial copy in EVIOCSABS |
06.10.2026 |
|
| CVE-2026-98206 |
Input: cyttsp5 - clamp the HID report size before memcpy |
06.10.2026 |
|
| CVE-2026-98207 |
mmc: spi: reset bytes_xfered before retrying CRC failures |
06.10.2026 |
|
| CVE-2026-98208 |
mmc: sdio_uart: fix xmit_fifo leak when the port table is full |
06.10.2026 |
|
| CVE-2026-98209 |
mmc: sdhci-of-aspeed: Remove children before releasing SDC resources |
06.10.2026 |
|
| CVE-2026-98210 |
mmc: mxcmmc: cancel data work and watchdog on remove |
06.10.2026 |
|
| CVE-2026-98211 |
mmc: mmci: Fix use-after-free in busy-timeout work |
06.10.2026 |
|
| CVE-2026-98212 |
mmc: hsq: Fix use-after-free in retry work |
06.10.2026 |
|
| CVE-2026-98213 |
mmc: core: Cancel SDIO IRQ work before freeing host |
06.10.2026 |
|
| CVE-2026-98214 |
selinux: recheck intermediate backing files on mprotect() |
06.10.2026 |
|
| CVE-2026-98215 |
selinux: preserve user SID across nested backing files |
06.10.2026 |
|
| CVE-2026-98216 |
IB/hfi1: Fix the PIO_CRED credit-return mmap |
06.10.2026 |
|
| CVE-2026-98217 |
IB/mlx4: Fix use-after-free on pkey sysfs registration failure |
06.10.2026 |
|
| CVE-2026-98218 |
i2c: atr: fix dangling adapter pointer on add failure |
06.10.2026 |
|
| CVE-2026-98219 |
sched_ext: Close the pre-enable ops error claim window |
06.10.2026 |
|
| CVE-2026-98220 |
sched_ext: Fix NULL sched deref in kfunc sub-sched error paths |
06.10.2026 |
|
| CVE-2026-98221 |
KEYS: trusted: Fix tpm2_load_cmd() boundary check |
06.10.2026 |
|
| CVE-2026-98222 |
KEYS: encrypted: fix integer overflow of datablob_len |
06.10.2026 |
|
| CVE-2026-98223 |
mm: filemap: retain mapped dropbehind folios |
06.10.2026 |
|
| CVE-2026-98224 |
mm/vma: correctly unaccount on mmap_prepare() failure |
06.10.2026 |
|
| CVE-2026-98225 |
mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem |
06.10.2026 |
|
| CVE-2026-98226 |
mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count |
06.10.2026 |
|
| CVE-2026-98227 |
memstick: ms_block: destroy io_queue workqueue on removal |
06.10.2026 |
|
| CVE-2026-98228 |
mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ |
06.10.2026 |
|
| CVE-2026-98229 |
xfrm: save input state data before secpath resets |
06.10.2026 |
|
| CVE-2026-98230 |
xfrm: use hlist_del_init_rcu for state_cache and state_cache_input |
06.10.2026 |
|
| CVE-2026-98231 |
xfrm: serialize state GC with device state flush |
06.10.2026 |
|
| CVE-2026-98232 |
scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() |
06.10.2026 |
|
| CVE-2026-98233 |
net/packet: clear RX owner on VNET header error |
06.10.2026 |
|
| CVE-2026-98234 |
net/sched: hhf: cap hh_flows_limit at change time |
06.10.2026 |
|
| CVE-2026-98235 |
net/sched: act_api: release tail references on DELACTION failure |
06.10.2026 |
|
| CVE-2026-98236 |
net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value |
06.10.2026 |
|
| CVE-2026-98237 |
net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain |
06.10.2026 |
|
| CVE-2026-98238 |
net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() |
06.10.2026 |
|
| CVE-2026-98239 |
net: lan743x: fix RX checksum use-after-free |
06.10.2026 |
|
| CVE-2026-98240 |
net: ip_tunnel: initialize `options_len` before referencing options |
06.10.2026 |
|
| CVE-2026-98241 |
ipv6: xfrm: use full sockets in local error paths |
06.10.2026 |
|
| CVE-2026-98242 |
dma-buf: Fix silent overflow for phys vec to sgt |
06.10.2026 |
|
| CVE-2026-98243 |
dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 |
06.10.2026 |
|
| CVE-2026-98244 |
btrfs: clear free space tree creation state on rebuild failure |
06.10.2026 |
|
| CVE-2026-98245 |
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() |
06.10.2026 |
|
| CVE-2026-98246 |
Bluetooth: hci_sync: Serialize local codec list cleanup |
06.10.2026 |
|
| CVE-2026-98247 |
Bluetooth: hci_codec: validate vendor codec count length |
06.10.2026 |
|
| CVE-2026-98248 |
arm64: percpu: Fix LSE operations on {8,16}-bit types |
06.10.2026 |
|
| CVE-2026-98249 |
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc |
06.10.2026 |
|
| CVE-2026-98250 |
nfsd: fix handling of NFSEXP_PNFS in the netlink codepath |
06.10.2026 |
|
| CVE-2026-98251 |
openvswitch: avoid reallocating confirmed conntrack labels |
06.10.2026 |
|
| CVE-2026-98252 |
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() |
06.10.2026 |
|
| CVE-2026-98253 |
RDMA/ucma: Serialize join and leave on copy_to_user failure |
06.10.2026 |
|
| CVE-2026-98254 |
swiotlb: use the adjusted address for the highmem page lookup |
06.10.2026 |
|
| CVE-2026-98255 |
tcp: exclude old ACKs from tcp fast path |
06.10.2026 |
|
| CVE-2026-98256 |
signal: Prevent exec() race |
06.10.2026 |
|
| CVE-2026-98257 |
rds: ib: use rds_conn_drop() on protocol version mismatch |
06.10.2026 |
|
| CVE-2026-98258 |
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list |
06.10.2026 |
|
| CVE-2026-98259 |
fs/dax: check zero or empty entry before converting xarray entry |
06.10.2026 |
|
| CVE-2026-98260 |
exec: Cleanup POSIX timers right after de_thread() |
06.10.2026 |
|
| CVE-2026-98261 |
cifs: Fix server use-after-free in cifs_chan_skip_or_disable() |
06.10.2026 |
|
| CVE-2026-98262 |
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY |
06.10.2026 |
|
| CVE-2026-98263 |
ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type |
06.10.2026 |
|
| CVE-2026-98264 |
ALSA: virtio: reset device before deleting virtqueues |
06.10.2026 |
|
| CVE-2026-98265 |
ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity |
06.10.2026 |
|
| CVE-2026-98266 |
ALSA: core: Fix potential UAF after asynchronous card release |
06.10.2026 |
|
| CVE-2026-98267 |
9p: Fix v9fs_issue_write() to update i_size and remote_i_size |
06.10.2026 |
|
| CVE-2026-98268 |
perf: Fix null pointer access in is_include_guest_event() |
06.10.2026 |
|
| CVE-2026-98269 |
btrfs: abort transaction on failure to update inode for hole punching and reflinking |
06.10.2026 |
|
| CVE-2026-98270 |
drm/amdgpu: check ras and obj before dereference |
06.10.2026 |
|
| CVE-2026-98271 |
net: skbuff: do not leave stale header offsets after pskb_carve() |
06.10.2026 |
|
| CVE-2026-98272 |
net: mvpp2: prevent buffer overflow in page_pool allocation |
06.10.2026 |
|
| CVE-2026-98273 |
x86/kprobes: Fix crash when probing CS CALL instructions |
06.10.2026 |
|
| CVE-2026-98274 |
net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() |
06.10.2026 |
|
| CVE-2026-98275 |
net: ethernet: cortina: Ack RX overrun interrupt correctly |
06.10.2026 |
|
| CVE-2026-98276 |
net: lock the socket in sock_gettstamp() |
06.10.2026 |
|
| CVE-2026-98277 |
eth: fbnic: ring the doorbell if a burst ends in a drop |
06.10.2026 |
|
| CVE-2026-98278 |
net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check |
06.10.2026 |
|
| CVE-2026-98279 |
btrfs: handle lack of space when cleaning up verity items |
06.10.2026 |
|
| CVE-2026-98280 |
drm/xe/i2c: Disable IRQ on unbind |
06.10.2026 |
|
| CVE-2026-98281 |
futex: Also allocate private hash on vfork() |
06.10.2026 |
|
| CVE-2026-98282 |
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba |
06.10.2026 |
|
| CVE-2026-98283 |
KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() |
06.10.2026 |
|
| CVE-2026-98284 |
netlink: do not free nlk->groups while lockless readers can use it |
06.10.2026 |
|
| CVE-2026-98285 |
net: bridge: vlan: fix bugs caused by switchdev deletion errors |
06.10.2026 |
|
| CVE-2026-98286 |
drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown |
06.10.2026 |
|
| CVE-2026-98287 |
pppoatm: ensure a writable skb header and linear data |
06.10.2026 |
|
| CVE-2026-98288 |
net: stmmac: fix TSO header length truncation |
06.10.2026 |
|
| CVE-2026-98289 |
af_unix: Unify scc_index when finalising SCC in __unix_walk_scc(). |
06.10.2026 |
|
| CVE-2026-98290 |
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup |
06.10.2026 |
|
| CVE-2026-98291 |
Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit |
06.10.2026 |
|
| CVE-2026-98292 |
Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access |
06.10.2026 |
|
| CVE-2026-98293 |
Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() |
06.10.2026 |
|
| CVE-2026-98294 |
Bluetooth: hci_qca: Do not write to the serial port after it is closed |
06.10.2026 |
|
| CVE-2026-98295 |
Bluetooth: coredump: Quiesce dump work on unregister |
06.10.2026 |
|
| CVE-2026-98296 |
Bluetooth: btintel_pcie: validate TX skb length in send_sync |
06.10.2026 |
|
| CVE-2026-98297 |
Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained |
06.10.2026 |
|
| CVE-2026-98298 |
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() |
06.10.2026 |
|
| CVE-2026-98299 |
tcp: do not let tcp_rmem be set below 4096 |
06.10.2026 |
|
| CVE-2026-98300 |
tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv(). |
06.10.2026 |
|
| CVE-2026-98301 |
net: bridge: mst: move switchdev call outside rcu |
06.10.2026 |
|
| CVE-2026-98302 |
net: fddi: skfp: fix NULL deref when setting the MAC address while down |
06.10.2026 |
|
| CVE-2026-98303 |
ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup |
06.10.2026 |
|
| CVE-2026-98304 |
net: bcmgenet: restore the hardware filters on open |
06.10.2026 |
|
| CVE-2026-98305 |
net: dsa: mxl862xx: disable the stats poll on teardown |
06.10.2026 |
|
| CVE-2026-98306 |
seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation |
06.10.2026 |
|
| CVE-2026-98307 |
wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() |
06.10.2026 |
|
| CVE-2026-98308 |
ALSA: hda: trace PCM open only after assigning a stream |
06.10.2026 |
|
| CVE-2026-98309 |
drm/vc4: Use managed KMS polling to fix UAF on unbind |
06.10.2026 |
|
| CVE-2026-98310 |
drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory |
06.10.2026 |
|
| CVE-2026-98311 |
wifi: virt_wifi: don't transfer operstate before register |
06.10.2026 |
|
| CVE-2026-98312 |
ALSA: 6fire: fix OOB write from device-reported iso length |
06.10.2026 |
|
| CVE-2026-98313 |
drm/msm/dp: skip PUSH_IDLE when the link was never enabled |
06.10.2026 |
|
| CVE-2026-98314 |
ALSA: pcm: set timer->private_data before registering the PCM timer |
06.10.2026 |
|
| CVE-2026-98315 |
ntfs: protect runlist updates with the runlist lock |
06.10.2026 |
|
| CVE-2026-98316 |
ALSA: bcd2000: Fix race between rawmidi and disconnect |
06.10.2026 |
|
| CVE-2026-98317 |
neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS. |
06.10.2026 |
|
| CVE-2026-98318 |
smb: client: validate absolute native symlink targets before NT fixups |
06.10.2026 |
|
| CVE-2026-98319 |
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr |
06.10.2026 |
|
| CVE-2026-98320 |
netfilter: flowtable: hold reference on ct until flow is released |
06.10.2026 |
|
| CVE-2026-98321 |
netfilter: nf_nat: unregister and release hooks on error |
06.10.2026 |
|
| CVE-2026-98322 |
netfilter: nft_nat: fully initialise new_addr in netmap setup |
06.10.2026 |
|
| CVE-2026-98323 |
RDMA/siw: Bound fragmented header copies by the remaining length |
06.10.2026 |
|
| CVE-2026-98324 |
dmaengine: pxa: fix double counting of the hw descriptors |
06.10.2026 |
|
| CVE-2026-98325 |
wifi: mac80211: set up the TX info early to fix failure paths |
06.10.2026 |
|
| CVE-2026-98326 |
wifi: mac80211: mesh: release the channel if start fails |
06.10.2026 |
|
| CVE-2026-98327 |
wifi: mac80211: mesh: reset the CSA state when leaving |
06.10.2026 |
|
| CVE-2026-98328 |
wifi: mac80211: add HE 6 GHz capability in the scan elems len |
06.10.2026 |
|
| CVE-2026-98329 |
wifi: mac80211: don't allow injecting frames wider than the chanctx |
06.10.2026 |
|
| CVE-2026-98330 |
wifi: cfg80211: get the wiphy out of a dying network namespace |
06.10.2026 |
|
| CVE-2026-98331 |
wifi: mac80211: unlist vifs when their netdev is unregistered |
06.10.2026 |
|
| CVE-2026-98332 |
wifi: mac80211: only operate on TDLS peers in the TDLS code |
06.10.2026 |
|
| CVE-2026-98333 |
wifi: mac80211: reset the LED state when ifup fails |
06.10.2026 |
|
| CVE-2026-98334 |
wifi: mac80211: reset state when starting AP fails |
06.10.2026 |
|
| CVE-2026-98335 |
wifi: mac80211: abort chanswitch when leaving a mesh |
06.10.2026 |
|
| CVE-2026-98336 |
wifi: mac80211: don't offload TC setup on AP_VLAN interfaces |
06.10.2026 |
|
| CVE-2026-98337 |
wifi: mac80211: don't start a ROC while scanning |
06.10.2026 |
|
| CVE-2026-98338 |
wifi: cfg80211: ibss: ref BSS entry for joined event |
06.10.2026 |
|
| CVE-2026-98339 |
wifi: cfg80211: don't filter by BSS type when removing stale entries |
06.10.2026 |
|
| CVE-2026-98340 |
wifi: cfg80211: only group hidden BSSes with beacon entries |
06.10.2026 |
|
| CVE-2026-98341 |
wifi: cfg80211: don't free driver-owned scan requests |
06.10.2026 |
|
| CVE-2026-98342 |
dmaengine: wait for RCU readers before releasing dma_device |
06.10.2026 |
|
| CVE-2026-98343 |
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() |
06.10.2026 |
|
| CVE-2026-98344 |
dmaengine: Fix device kref underflow in dma_chan_put() |
06.10.2026 |
|
| CVE-2026-98345 |
wifi: cfg80211: check IP header size in cfg80211_classify8021d() |
06.10.2026 |
|
| CVE-2026-98346 |
wifi: cfg80211: don't get the radio mask for netdev-less wdevs |
06.10.2026 |
|
| CVE-2026-98347 |
IB/IPoIB: Avoid restoring OPER_UP after multicast flush |
06.10.2026 |
|
| CVE-2026-98348 |
wifi: libipw: reject too-short association responses |
06.10.2026 |
|
| CVE-2026-98349 |
wifi: libipw: reject too-short beacon and probe responses |
06.10.2026 |
|
| CVE-2026-98350 |
wifi: brcmfmac: cyw: pass PMKID to firmware if present |
06.10.2026 |
|
| CVE-2026-98351 |
wifi: virt_wifi: free skb when disconnected |
06.10.2026 |
|
| CVE-2026-98352 |
RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted |
06.10.2026 |
|
| CVE-2026-98353 |
RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables |
06.10.2026 |
|
| CVE-2026-98354 |
RDMA/mad: Fix receive buffer leak when PKey enforcement fails |
06.10.2026 |
|
| CVE-2026-98355 |
RDMA/rtrs: guard against null kobj name |
06.10.2026 |
|
| CVE-2026-98356 |
RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup |
06.10.2026 |
|
| CVE-2026-98357 |
IB/isert: wait for deferred control PDU completions before releasing the connection |
06.10.2026 |
|
| CVE-2026-98358 |
IB/iser: reject a remote invalidation of an unregistered direction |
06.10.2026 |
|
| CVE-2026-98359 |
RDMA/core: Reject unregistering netdevs in ib_get_eth_speed |
06.10.2026 |
|
| CVE-2026-98360 |
RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds |
06.10.2026 |
|
| CVE-2026-98361 |
RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths |
06.10.2026 |
|
| CVE-2026-98362 |
clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate |
06.10.2026 |
|
| CVE-2026-98363 |
firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS |
06.10.2026 |
|
| CVE-2026-98364 |
xfrm: hold net_device reference under RCU in bundle creation |
06.10.2026 |
|
| CVE-2026-98365 |
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access |
06.10.2026 |
|
| CVE-2026-98366 |
RDMA/rxe: validate access flags before swapping the MR's PD |
06.10.2026 |
|
| CVE-2026-98367 |
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept |
06.10.2026 |
|
| CVE-2026-98368 |
esp: downgrade zerocopy managed frags before mutating skb frags |
06.10.2026 |
|
| CVE-2026-98369 |
xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() |
06.10.2026 |
|
| CVE-2026-98370 |
xfrm: fix compat ALLOCSPI request use-after-free |
06.10.2026 |
|
| CVE-2026-98371 |
xfrm: iptfs: fix runt reassembly panic from short inner tot_len |
06.10.2026 |
|
| CVE-2026-98372 |
xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() |
06.10.2026 |
|
| CVE-2026-103346 |
WordPress Payflex Payment Gateway plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-105808 |
SourceCodester Simple Student Information System searchresults.php clean cross site scripting |
06.10.2026 |
|
| CVE-2026-105809 |
SourceCodester Simple Student Information System Profile Field register.php cross site scripting |
06.10.2026 |
|
| CVE-2026-105879 |
WordPress JetElements For Elementor plugin <= 2.9.2.2 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-4889 |
SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies |
06.10.2026 |
|
| CVE-2026-105305 |
Keycloak-services: keycloak-services: device authorization grant bypasses per-client minimum.acr.value enforcement |
06.10.2026 |
|
| CVE-2026-105807 |
SourceCodester Simple Student Information System searchquery.php sql injection |
06.10.2026 |
|
| CVE-2026-85153 |
Information Disclosure Vulnerability in Schmooze dating mobile Application |
06.10.2026 |
|
| CVE-2026-59357 |
Self-UAA OIDC Configuration allows JWT injection to establish unauthorized sessions |
06.10.2026 |
|
| CVE-2026-59358 |
UAA OAuth Token Endpoint Vulnerability allows user access token reuse for client_credentials grant type |
06.10.2026 |
|
| CVE-2026-105701 |
ACPT (Premium) <= 2.0.66 - Authenticated (Subscriber+) Remote Code Execution via REST API Email Template |
06.10.2026 |
8.8 |
| CVE-2026-105778 |
Tenda AC5 Wifi setWifi stack-based overflow |
06.10.2026 |
|
| CVE-2026-25263 |
Out of Bounds write in Linux Camera |
06.10.2026 |
6.6 |
| CVE-2026-25267 |
Missing Authorization in Core |
06.10.2026 |
7.8 |
| CVE-2026-25269 |
Out-of-bounds Write in Camera Driver |
06.10.2026 |
6.7 |
| CVE-2026-25270 |
Out-of-bounds Write in Camera Driver |
06.10.2026 |
6.7 |
| CVE-2026-25272 |
Out-of-bounds Write in Camera Driver |
06.10.2026 |
6.7 |
| CVE-2026-25273 |
Out-of-bounds Write in Camera Driver |
06.10.2026 |
6.7 |
| CVE-2026-25274 |
Use After Free in Windows WLAN Host |
06.10.2026 |
6.7 |
| CVE-2026-25291 |
Use After Free in Graphics |
06.10.2026 |
7.8 |
| CVE-2026-25302 |
Improper Verification of Cryptographic Signature in Boot |
06.10.2026 |
7.1 |
| CVE-2026-57537 |
Use After Free in DSP Service |
06.10.2026 |
7.8 |
| CVE-2026-57545 |
Untrusted Pointer Dereference in Graphics |
06.10.2026 |
7.8 |
| CVE-2026-57546 |
Buffer Over-read in WLAN HAL |
06.10.2026 |
7.5 |
| CVE-2026-57554 |
Use After Free in DSP Service |
06.10.2026 |
7.8 |
| CVE-2026-57555 |
Use After Free in DSP Service |
06.10.2026 |
7.8 |
| CVE-2026-57559 |
Use After Free in DSP_Services |
06.10.2026 |
7.8 |
| CVE-2026-94293 |
Missing authentication for critical function in the aas-edge-client REST API |
06.10.2026 |
|
| CVE-2026-105776 |
bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL admin_transaction.php sql injection |
06.10.2026 |
|
| CVE-2026-86786 |
Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_images |
06.10.2026 |
|
| CVE-2026-89289 |
Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST Endpoint |
06.10.2026 |
|
| CVE-2026-94270 |
Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via Webhook |
06.10.2026 |
|
| CVE-2026-94271 |
Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverified Success Return |
06.10.2026 |
|
| CVE-2026-94278 |
File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat |
06.10.2026 |
|
| CVE-2026-94299 |
elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Callback |
06.10.2026 |
|
| CVE-2026-105775 |
vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds |
06.10.2026 |
|
| CVE-2026-75962 |
Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_email' Parameter (Multisite Registration → Failed Email Log) |
06.10.2026 |
7.2 |
| CVE-2026-105072 |
WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-105708 |
imgproxy SVG svg.go sanitizeElement cross site scripting |
06.10.2026 |
|
| CVE-2026-32576 |
WordPress Faktur Pro for WooCommerce plugin <= 3.2.2 - Insecure Direct Object References (IDOR) vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-32582 |
WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-39599 |
WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vulnerability |
06.10.2026 |
4.3 |
| CVE-2026-39723 |
WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-39760 |
WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability |
06.10.2026 |
7.1 |
| CVE-2026-39789 |
WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-41558 |
WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA Bypass vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-41563 |
WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability |
06.10.2026 |
7.5 |
| CVE-2026-97300 |
WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability |
06.10.2026 |
6.5 |
| CVE-2026-105707 |
uptrace user_handler.go Login information exposure |
06.10.2026 |
|
| CVE-2026-105706 |
SourceCodester Drug Recommendation System cross-site request forgery |
06.10.2026 |
|
| CVE-2026-105704 |
SourceCodester Drug Recommendation System Auth Guard improper authentication |
06.10.2026 |
|
| CVE-2026-105705 |
SourceCodester Drug Recommendation System add_drug.php cross site scripting |
06.10.2026 |
|
| CVE-2026-105703 |
PHPGurukul User Registration & Login and User Management System Change Password change-password.php authorization |
06.10.2026 |
|
| CVE-2026-105621 |
jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization |
06.10.2026 |
|
| CVE-2026-105611 |
chillzhuang SpringBlade User Detail Endpoint RoleController.java improper authorization |
06.10.2026 |
|
| CVE-2026-105610 |
chillzhuang SpringBlade Parameter Submit Management ParamController.java improper authorization |
06.10.2026 |
|
| CVE-2026-105573 |
newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logic error |
06.10.2026 |
|
| CVE-2026-105572 |
PickMall Lilishop Buyer Invoice List receipt authorization |
06.10.2026 |
|
| CVE-2026-105487 |
yogeshojha reNgine listTargets Endpoint tasks.py subdomain_discovery os command injection |
06.10.2026 |
|
| CVE-2026-105571 |
PickMall Lilishop Mobile Binding bindMobile improper authorization |
06.10.2026 |
|
| CVE-2026-105486 |
OSSRS srs System API api.go systemAPI.Run missing authentication |
06.10.2026 |
|
| CVE-2026-104039 |
Sssd: sssd: denial of service via stale connection state reuse in pam gssapi responder |
06.10.2026 |
|
| CVE-2026-104040 |
Sssd: sssd: information disclosure via odata injection in entra id lookups |
06.10.2026 |
|
| CVE-2026-104041 |
Sssd: sssd: denial of service via unbounded negative cache growth |
06.10.2026 |
|
| CVE-2026-104042 |
Sssd: sssd: denial of service via out-of-bounds read in pam responder |
06.10.2026 |
|
| CVE-2026-104043 |
Sssd: sssd: denial of service via undersized packet parsing in nss responder |
06.10.2026 |
|
| CVE-2026-104044 |
Sssd: sssd: denial of service via crafted passkey kerberos authentication request |
06.10.2026 |
|
| CVE-2026-104380 |
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one |
06.10.2026 |
|
| CVE-2026-105484 |
TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection |
06.10.2026 |
|
| CVE-2026-104031 |
Sssd: sssd: denial of service via memory exhaustion in autofs responder |
06.10.2026 |
|
| CVE-2026-104032 |
Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
06.10.2026 |
|
| CVE-2026-104033 |
Sssd: sssd: access control bypass via improper ldap shadow expiration check |
06.10.2026 |
|
| CVE-2026-104034 |
Sssd: sssd: denial of service via use-after-free in kcm ticket renewal |
06.10.2026 |
|
| CVE-2026-104035 |
Sssd: sssd: denial of service via memory exhaustion in kcm responder |
06.10.2026 |
|
| CVE-2026-104036 |
Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
06.10.2026 |
|
| CVE-2026-104037 |
Sssd: sssd: denial of service via packet length underflow in autofs responder |
06.10.2026 |
|
| CVE-2026-104038 |
Sssd: sssd: denial of service via missing sid extension in certificate mapping |
06.10.2026 |
|
| CVE-2026-105472 |
girishsaraf Online-Appointment-Booking-System Booking book.php sql injection |
06.10.2026 |
|
| CVE-2026-92821 |
Sssd: sssd: access control bypass via premature ldap access rule evaluation |
06.10.2026 |
|
| CVE-2026-105471 |
girishsaraf Online-Appointment-Booking-System Registration signup.php sql injection |
06.10.2026 |
|
| CVE-2026-105762 |
Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint |
06.10.2026 |
8.3 |
| CVE-2026-105763 |
Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL |
05.10.2026 |
9.6 |
| CVE-2026-105764 |
Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE |
05.10.2026 |
|
| CVE-2026-105782 |
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware |
06.10.2026 |
7.5 |
| CVE-2026-105783 |
Joplin Web Clipper pairing allows cross-origin theft of a permanent API token |
06.10.2026 |
8 |
| CVE-2026-105784 |
Joplin whiteboard card rendering allows CSS injection into application chrome |
06.10.2026 |
4.6 |
| CVE-2026-105785 |
Joplin Server password reset accepts tokens issued for unrelated purposes |
05.10.2026 |
4.8 |
| CVE-2026-105786 |
Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier |
05.10.2026 |
|
| CVE-2026-82988 |
CVE-2026-82988 |
06.10.2026 |
|
| CVE-2026-82989 |
CVE-2026-82989 |
06.10.2026 |
|
| CVE-2026-105759 |
vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP method tokens in the vLLM Rust frontend metrics middleware (unauthenticated denial of service) |
05.10.2026 |
5.9 |
| CVE-2026-105760 |
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion |
06.10.2026 |
5.3 |
| CVE-2026-105761 |
Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers |
06.10.2026 |
7.1 |
| CVE-2026-104852 |
GraphQL Tools has prototype pollution in well-established utility function `mergeDeep` |
06.10.2026 |
|
| CVE-2026-105757 |
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites) |
06.10.2026 |
6.5 |
| CVE-2026-105758 |
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach |
05.10.2026 |
5.3 |
| CVE-2026-105754 |
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features |
05.10.2026 |
6.5 |
| CVE-2026-105755 |
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank` |
05.10.2026 |
4.2 |
| CVE-2026-105756 |
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service |
06.10.2026 |
6.5 |
| CVE-2026-105753 |
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core |
06.10.2026 |
6.5 |
| CVE-2026-105470 |
girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus.php mysqli_query sql injection |
05.10.2026 |
|
| CVE-2026-105752 |
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle |
06.10.2026 |
3.1 |
| CVE-2026-105469 |
girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection |
05.10.2026 |
|
| CVE-2026-93321 |
Malformed LLB file operation can crash buildkitd |
06.10.2026 |
|
| CVE-2026-103433 |
Bake filesystem entitlement consent is skipped for certain secret and oci-layout definitions |
06.10.2026 |
|
| CVE-2026-93315 |
BuildKit proxy CA cleanup can be disrupted by build steps |
06.10.2026 |
|
| CVE-2026-103546 |
Improper validation of Ops Manager configuration in MongoDB Kubernetes Operator |
06.10.2026 |
|
| CVE-2026-105468 |
girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection |
05.10.2026 |
|
| CVE-2026-0461 |
|
06.10.2026 |
|
| CVE-2026-0482 |
|
06.10.2026 |
|
| CVE-2026-105746 |
Docling: KServe v2 OCR engine does not enforce enable_remote_services |
05.10.2026 |
2.2 |
| CVE-2026-105747 |
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection) |
06.10.2026 |
4.3 |
| CVE-2026-105748 |
Docling: Crafted DoclingDocument JSON embeds local image files into converted output |
06.10.2026 |
4.3 |
| CVE-2026-105749 |
Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backends causes CPU/memory exhaustion |
05.10.2026 |
6.5 |
| CVE-2026-105750 |
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
05.10.2026 |
5.9 |
| CVE-2026-105751 |
Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend |
05.10.2026 |
|
| CVE-2026-105745 |
Docling: Plugin entry points are imported before the allow_external_plugins check |
06.10.2026 |
6.7 |
| CVE-2026-21589 |
|
06.10.2026 |
|
| CVE-2026-91107 |
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) |
06.10.2026 |
|
| CVE-2026-105744 |
Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engine |
05.10.2026 |
7.5 |