CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-103470 30.09.2026 9.3
CVE-2026-102427 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 30.09.2026 10
CVE-2026-103395 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service 30.09.2026 9.3
CVE-2026-76570 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 30.09.2026 10
CVE-2026-18782 SQL Injection in Trex Digital Manufacturing's Trex MES 30.09.2026 9.8
CVE-2026-93903 30.09.2026 9.4
CVE-2026-82307 Multiple Vulnerabilities in Dolusoft Software's SOPLOG 30.09.2026 9.8
CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 30.09.2026 9.8
CVE-2026-94389 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability 30.09.2026 9
CVE-2026-96349 WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability 30.09.2026 10
CVE-2026-96350 WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability 30.09.2026 9.8
CVE-2026-96822 WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability 30.09.2026 9.3
CVE-2026-97248 WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-97274 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability 30.09.2026 9.8
CVE-2026-74864 Authentication Bypass in sogo_yhn 30.09.2026 9.3
CVE-2026-74865 Authentication Bypass in sogo_yhn 30.09.2026 9.2
CVE-2026-77185 Apache MINA SSHD: Asynchronous authentication can bypass signature verification 30.09.2026 9.1
CVE-2026-94053 Apache MINA SSHD: LDAP injection in sshd-ldap 30.09.2026 9.1
CVE-2026-94052 Apache MINA SSHD: LDAP password authentication ineffective 30.09.2026 9.1
CVE-2026-102455 DigiWin|EasyFlow .NET - Insecure Deserialization 30.09.2026 9.3
CVE-2026-102458 DigiWin|EasyFlow .NET - Missing Authentication 30.09.2026 9.3
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade 30.09.2026 9.2
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability 30.09.2026 9.1
CVE-2026-102911 zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection 30.09.2026 9.4
CVE-2026-103110 30.09.2026 9.8
CVE-2026-103056 AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR 30.09.2026 9.4
CVE-2026-102794 Ziroom ZHOME A0101 ping command injection 30.09.2026 9.4
CVE-2026-102793 Ziroom ZHOME A0101 set_time_zone command injection 29.09.2026 9.4
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution 30.09.2026 9.2
CVE-2026-103040 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service 30.09.2026 9.3
CVE-2026-103041 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service 30.09.2026 9.3
CVE-2026-102792 Ziroom ZHOME A0101 set_syslog command injection 29.09.2026 9.4
CVE-2026-70356 Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type 30.09.2026 9.4
CVE-2026-71379 Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties 30.09.2026 10
CVE-2026-96587 Use of Hard-coded Credentials in Viidure Dashcam Android Application 29.09.2026 10
CVE-2026-53988 Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints 29.09.2026 9.2
CVE-2026-100291 Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 29.09.2026 9.3
CVE-2026-76721 Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs 29.09.2026 9.8
CVE-2026-76722 Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs 29.09.2026 9.8
CVE-2026-76723 Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS 29.09.2026 9.6
CVE-2026-76724 Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol 29.09.2026 9.6
CVE-2026-76725 Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs 29.09.2026 9.6
CVE-2026-102829 simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 29.09.2026 9.2
CVE-2026-102828 simple-git unsafe-operation guard does not block trailer command configuration 29.09.2026 9.2
CVE-2026-84436 IBM Guardium Data Protection is affected by multiple vulnerabilities. 30.09.2026 9.1
CVE-2026-102710 29.09.2026 9.3
CVE-2026-102761 29.09.2026 9.3
CVE-2026-102425 Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 29.09.2026 9.5
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 30.09.2026 9.3
CVE-2026-22094 Weak root password in EVbee DC 80 30.09.2026 9.3
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026 9.3
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026 9.3
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026 9
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026 9.3
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 30.09.2026 9.2
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026 10
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026 9.4
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 28.09.2026 9.3
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 28.09.2026 9.4
CVE-2026-101262 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101261 Ziroom ZHOME A0101 firstSetup_wifi command injection 28.09.2026 9.4
CVE-2026-101260 Ziroom ZHOME A0101 firstLogin command injection 29.09.2026 9.4
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection 29.09.2026 9.1
CVE-2026-101187 Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection 29.09.2026 9.4
CVE-2026-102268 PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard 29.09.2026 9.1
CVE-2026-100752 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 30.09.2026 9.3
CVE-2026-101108 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 30.09.2026 9.3
CVE-2026-101110 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 30.09.2026 9.3
CVE-2026-49994 Bluehood: Missing authentication on Bluehood API routes when web auth is enabled 28.09.2026 9.1
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access 28.09.2026 9.3
CVE-2026-101894 @xhmikosr/decompress: Path traversal via symlink chain 28.09.2026 9.1
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution 28.09.2026 9.3
CVE-2026-101081 D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow 28.09.2026 9.4
CVE-2026-88804 Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher 28.09.2026 9.6
CVE-2026-12342 SailPoint IdentityIQ Improper Form Validation Vulnerability 29.09.2026 9.6
CVE-2026-101076 Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection 28.09.2026 10
CVE-2026-101077 Netcore NR289-GE boa_temp process_request missing authentication 28.09.2026 10
CVE-2026-101075 Netcore NR289-GE Location Time location_time.cgi system os command injection 28.09.2026 10
CVE-2026-101074 Netcore NR289-GE Authentication boa password-check stack-based overflow 28.09.2026 9.3
CVE-2026-90924 Default Admin Credentials in Innotim Software's Logsign SIEM 28.09.2026 9.8
CVE-2026-101072 Netcore NR289-GE CGI ap_ip.cgi system os command injection 28.09.2026 10
CVE-2026-73640 Time-based SQL Injection in Dayforce Payroll 28.09.2026 9.3
CVE-2026-73642 Path Traversal in Dayforce Payroll 28.09.2026 9.2
CVE-2026-85185 Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root 28.09.2026 9.6
CVE-2026-85526 Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD 29.09.2026 9.9
CVE-2026-87799 Arbitrary file write on LXD host via symlink in migration stream 29.09.2026 9.9
CVE-2026-81867 Deserialization of Untrusted Data in Application Integration allows Remote Code Execution 30.09.2026 9.4
CVE-2026-101039 FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow 28.09.2026 10
CVE-2026-101038 FAST FAC1200R MmtAtePrase stack-based overflow 28.09.2026 9.4
CVE-2026-19759 Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution 28.09.2026 9.4
CVE-2026-101037 FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow 28.09.2026 9.4
CVE-2026-82384 Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint 29.09.2026 9.8
CVE-2026-82377 Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers 29.09.2026 9.9
CVE-2026-82378 Apache Roller: OAuth authorization endpoint trusts request-supplied identity 29.09.2026 9
CVE-2026-101008 aaPanel BaoTa File Merge files.py merge_split_file command injection 28.09.2026 9.4
CVE-2026-101009 aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection 28.09.2026 9.3
CVE-2026-101007 aaPanel BaoTa Database Backup database.py InputSql os command injection 28.09.2026 9.3
CVE-2026-101002 Netcore NBR200V2 Tools Ping network_tools system os command injection 28.09.2026 9.4
CVE-2026-101001 Netcore NBR200V2 Web Management network_tools eval os command injection 28.09.2026 10
CVE-2026-101000 Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization 28.09.2026 10
CVE-2026-100896 TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection 28.09.2026 9.4
CVE-2026-100886 Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication 28.09.2026 10
CVE-2026-101065 Obot Quickstart Docker Deployment Unauthenticated Admin Access 30.09.2026 9.3
CVE-2026-101084 obot before v0.21.1 Authorization Bypass via /mcp-connect 27.09.2026 9.3
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri 28.09.2026 9.3
CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands 29.09.2026 9.5
CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 28.09.2026 9.5
CVE-2026-88773 HTTP Request Smuggling 29.09.2026 9.3
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 28.09.2026 9.8
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 28.09.2026 9.5
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 30.09.2026 9.1
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 28.09.2026 9.4
CVE-2026-82901 Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field 26.09.2026 9.8
CVE-2026-85984 miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter 26.09.2026 9.8
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.4
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.2
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 10
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 29.09.2026 9.5
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 27.09.2026 9.3
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 28.09.2026 9.2
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 28.09.2026 9.2
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 28.09.2026 9.2
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026 9.4
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026 9.4
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 28.09.2026 9.4
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026 9.3
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026 9
CVE-2026-100382 Unauthenticated remote code execution through wikitext in ExternalData 26.09.2026 10
CVE-2026-100389 GestSup before 3.2.62 Remote Code Execution via IMAP Attachment 30.09.2026 9.2
CVE-2026-100390 Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 25.09.2026 9.1
CVE-2026-48482 GLPI: RCE via Form import 30.09.2026 9.4
CVE-2026-84458 Zammad: Account takeover via unverified email matching during SSO auto-link 25.09.2026 9.1
CVE-2026-97063 X-SpringBoot through 6.0 Authentication Bypass via Login Code 25.09.2026 9.3
CVE-2026-97064 X-SpringBoot through 6.0 Authentication Bypass via Static Master Code 25.09.2026 9.3
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 28.09.2026 9.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 29.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 29.09.2026 9.1
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 26.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 28.09.2026 9.3
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026 9.3
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 26.09.2026 9.1
CVE-2026-81630 Botslab G980H Dashcams Insufficient Verification of Data Authenticity 25.09.2026 9.2
CVE-2026-93289 OS command injection in Eufy Omni C20, Omni X10 Pro 24.09.2026 9
CVE-2026-93291 Improper certificate validation in Eufy Omni C20 24.09.2026 9.3
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13249 Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040 24.09.2026 9.8
CVE-2026-61741 http4s-scala-xml has an XML External Entity (XXE) processing issue 29.09.2026 9.3
CVE-2026-61604 ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass 24.09.2026 9.3
CVE-2026-61732 Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context 24.09.2026 10
CVE-2026-61742 DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution 24.09.2026 9.3
CVE-2026-79766 Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email 29.09.2026 9.1
CVE-2026-97413 RDMA/rtrs-srv: Fix integer underflow in process_read and process_write 25.09.2026 9.8
CVE-2026-93425 Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root 24.09.2026 9.9
CVE-2026-93228 svcrdma: Reject Write/Reply chunks with segcount 0 25.09.2026 9.1
CVE-2026-93207 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry 25.09.2026 9.8
CVE-2026-81549 DataStage on Cloud Pak for Data has several vulnerabilities 24.09.2026 9.6
CVE-2026-90481 24.09.2026 9.2
CVE-2026-97404 26.09.2026 9.2
CVE-2026-97359 HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection 29.09.2026 10
CVE-2026-97360 HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine 24.09.2026 10
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy 24.09.2026 9.3
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal 25.09.2026 9.9
CVE-2026-12227 Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter 24.09.2026 9.8
CVE-2026-78312 Path Traversal in DIAEnergie 24.09.2026 9.1
CVE-2026-78308 Authentication Bypass in DIAEnergie 24.09.2026 9.8
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write 24.09.2026 9.3
CVE-2026-97055 SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret 24.09.2026 9.2
CVE-2026-18467 Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter 24.09.2026 9.8
CVE-2026-89078 Double Free in GitLab 25.09.2026 9.9
CVE-2026-93577 Integer Overflow or Wraparound in GitLab 25.09.2026 9.9
CVE-2026-93352 Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload 26.09.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-103470 30.09.2026
CVE-2026-47492 30.09.2026 5.5
CVE-2026-47493 30.09.2026 7.8
CVE-2026-47495 30.09.2026 7.8
CVE-2026-47496 30.09.2026 7.3
CVE-2026-47497 30.09.2026 7.8
CVE-2026-47498 30.09.2026 7.8
CVE-2026-47499 30.09.2026 7.8
CVE-2026-47503 30.09.2026 7.8
CVE-2026-47506 30.09.2026 5.5
CVE-2026-47509 30.09.2026 6.7
CVE-2026-47513 30.09.2026 7.8
CVE-2026-47514 30.09.2026 7.8
CVE-2026-47515 30.09.2026 6.7
CVE-2026-47516 30.09.2026 7.8
CVE-2026-47517 30.09.2026 5.5
CVE-2026-47518 30.09.2026 6
CVE-2026-47519 30.09.2026 7.8
CVE-2026-47520 30.09.2026 7.8
CVE-2026-47521 30.09.2026 7.8
CVE-2026-47522 30.09.2026 6.7
CVE-2026-47523 30.09.2026 7.8
CVE-2026-47524 30.09.2026 6.7
CVE-2026-47525 30.09.2026 6.7
CVE-2026-47526 30.09.2026 4.4
CVE-2026-47527 30.09.2026 6.7
CVE-2026-47528 30.09.2026 7.8
CVE-2026-47529 30.09.2026 6.7
CVE-2026-47530 30.09.2026 7.8
CVE-2026-47531 30.09.2026 4.4
CVE-2026-47532 30.09.2026 6.7
CVE-2026-47533 30.09.2026 6.7
CVE-2026-47534 30.09.2026 5.5
CVE-2026-47535 30.09.2026 7.8
CVE-2026-47536 30.09.2026 7.8
CVE-2026-47537 30.09.2026 6.7
CVE-2026-47538 30.09.2026 6.7
CVE-2026-47539 30.09.2026 6.7
CVE-2026-47540 30.09.2026 7.8
CVE-2026-47541 30.09.2026 7.8
CVE-2026-47542 30.09.2026 6.7
CVE-2026-47543 30.09.2026 6.7
CVE-2026-47544 30.09.2026 7.8
CVE-2026-47545 30.09.2026 7.8
CVE-2026-47546 30.09.2026 6.7
CVE-2026-47547 30.09.2026 6.7
CVE-2026-47548 30.09.2026 7.8
CVE-2026-47549 30.09.2026 5.5
CVE-2026-47550 30.09.2026 7.8
CVE-2026-47551 30.09.2026 7.8
CVE-2026-47552 30.09.2026 7.8
CVE-2026-47553 30.09.2026 7.8
CVE-2026-47554 30.09.2026 7.1
CVE-2026-47555 30.09.2026 5.5
CVE-2026-47556 30.09.2026 7.8
CVE-2026-47557 30.09.2026 5.5
CVE-2026-47558 30.09.2026 7.8
CVE-2026-47559 30.09.2026 7.8
CVE-2026-47560 30.09.2026 7.8
CVE-2026-47561 30.09.2026 7.8
CVE-2026-47562 30.09.2026 4.4
CVE-2026-47563 30.09.2026 7.8
CVE-2026-47565 30.09.2026 6.4
CVE-2026-47566 30.09.2026 5.5
CVE-2026-47567 30.09.2026 5.5
CVE-2026-47568 30.09.2026 5.5
CVE-2026-47569 30.09.2026 7.8
CVE-2026-47570 30.09.2026 7.8
CVE-2026-47571 30.09.2026 7.8
CVE-2026-47572 30.09.2026 7.8
CVE-2026-47573 30.09.2026 7.8
CVE-2026-47574 30.09.2026 7.8
CVE-2026-47575 30.09.2026 7.8
CVE-2026-47576 30.09.2026 7.7
CVE-2026-47577 30.09.2026 7.8
CVE-2026-47578 30.09.2026 7.8
CVE-2026-47579 30.09.2026 7.8
CVE-2026-47580 30.09.2026 7.3
CVE-2026-47581 30.09.2026 5.5
CVE-2026-47582 30.09.2026 7
CVE-2026-47583 30.09.2026 7.8
CVE-2026-47584 30.09.2026 5.5
CVE-2026-47585 30.09.2026 7.8
CVE-2026-47586 30.09.2026 6.4
CVE-2026-47587 30.09.2026 7.8
CVE-2026-47588 30.09.2026 7.8
CVE-2026-47589 30.09.2026 7.8
CVE-2026-47590 30.09.2026 7.8
CVE-2026-47591 30.09.2026 7.8
CVE-2026-47592 30.09.2026 7.8
CVE-2026-47593 30.09.2026 7.8
CVE-2026-47594 30.09.2026 7.8
CVE-2026-47595 30.09.2026 7.8
CVE-2026-47596 30.09.2026 7
CVE-2026-47597 30.09.2026 7.8
CVE-2026-47598 30.09.2026 7
CVE-2026-47599 30.09.2026 7.8
CVE-2026-47600 30.09.2026 7.8
CVE-2026-47601 30.09.2026 7.8
CVE-2026-47602 30.09.2026 7.1
CVE-2026-47603 30.09.2026 5.5
CVE-2026-47604 30.09.2026 5.5
CVE-2026-103436 30.09.2026 3.7
CVE-2026-47489 30.09.2026 7.8
CVE-2026-47491 30.09.2026 7.8
CVE-2026-47494 30.09.2026 7.8
CVE-2026-47500 30.09.2026 7.8
CVE-2026-47501 30.09.2026 7.8
CVE-2026-47502 30.09.2026 7.8
CVE-2026-47504 30.09.2026 7.8
CVE-2026-47505 30.09.2026 7.8
CVE-2026-47507 30.09.2026 7.8
CVE-2026-47508 30.09.2026 7.8
CVE-2026-47510 30.09.2026 7.8
CVE-2026-47511 30.09.2026 7.8
CVE-2026-47512 30.09.2026 7.8
CVE-2026-55174 UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding 30.09.2026 5.9
CVE-2026-103230 AdithyaYelloju Restaurant-Management-System Order Placement ord.php mysqli_query sql injection 30.09.2026
CVE-2026-103432 30.09.2026 8.1
CVE-2026-100253 30.09.2026 8.8
CVE-2026-100254 30.09.2026 8.8
CVE-2026-100255 30.09.2026 8.1
CVE-2026-100256 30.09.2026 7.8
CVE-2026-100257 30.09.2026 4.3
CVE-2026-100258 30.09.2026 4.3
CVE-2026-100259 30.09.2026 4.3
CVE-2026-100260 30.09.2026 5.3
CVE-2026-100261 30.09.2026 5.4
CVE-2026-100262 30.09.2026 7.6
CVE-2026-100263 30.09.2026 4.7
CVE-2026-100264 30.09.2026 2.7
CVE-2026-100265 30.09.2026 4.8
CVE-2026-100266 30.09.2026 7.7
CVE-2026-100267 30.09.2026 5.9
CVE-2026-100268 30.09.2026 7.7
CVE-2026-100269 30.09.2026 4.3
CVE-2026-100270 30.09.2026 3.3
CVE-2026-100271 30.09.2026 2.7
CVE-2026-100272 30.09.2026 4.9
CVE-2026-100273 30.09.2026 8.2
CVE-2026-100274 30.09.2026 6.5
CVE-2026-100275 30.09.2026 6.9
CVE-2026-100276 30.09.2026 5.9
CVE-2026-100277 30.09.2026 8.9
CVE-2026-100278 30.09.2026 4.9
CVE-2026-100279 30.09.2026 6.5
CVE-2026-100280 30.09.2026 3.1
CVE-2026-102427 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 30.09.2026
CVE-2026-103229 AdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysqli_query sql injection 30.09.2026
CVE-2026-80490 Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified 30.09.2026
CVE-2026-94545 Satori-generated SVG has improper escaping 30.09.2026
CVE-2026-103243 LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints 30.09.2026
CVE-2026-103270 LightLLM through 1.2.0 Missing Authentication on RL Control Routes 30.09.2026
CVE-2026-103395 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service 30.09.2026
CVE-2026-103396 bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount 30.09.2026
CVE-2026-103397 OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender 30.09.2026
CVE-2026-103398 OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path 30.09.2026
CVE-2026-76570 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 30.09.2026
CVE-2026-102717 MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash 30.09.2026
CVE-2026-102983 Astro: Netlify Image CDN allowlist bypass enables SSRF 30.09.2026
CVE-2026-102984 Astro: Malformed port in the Host header can crash the Node adapter 30.09.2026
CVE-2026-103227 GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow 30.09.2026
CVE-2026-103388 MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field 30.09.2026
CVE-2026-103389 MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph 30.09.2026
CVE-2026-47097 AJA HELO Plus < 2.1.7 Static AES Passphrase Information Disclosure via /diags 30.09.2026
CVE-2026-101295 Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction 30.09.2026
CVE-2026-103222 Blosc C-Blosc2 blosclz Decompression blosclz.c blosclz_decompress integer overflow 30.09.2026
CVE-2026-103226 Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow 30.09.2026
CVE-2026-18782 SQL Injection in Trex Digital Manufacturing's Trex MES 30.09.2026 9.8
CVE-2026-18783 Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES 30.09.2026 8.8
CVE-2026-62084 WordPress User Submitted Posts plugin <= 20260810 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-62097 WordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-97259 WordPress Pay with Vipps for WooCommerce plugin <= 6.2.4 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026
CVE-2026-93903 30.09.2026
CVE-2026-103118 GraphicsMagick WPG File wpg.c ExtractPostscript recursion 30.09.2026
CVE-2026-82307 Multiple Vulnerabilities in Dolusoft Software's SOPLOG 30.09.2026 9.8
CVE-2026-91860 Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge 30.09.2026
CVE-2026-93547 Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells 30.09.2026
CVE-2026-103117 OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection 30.09.2026
CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 30.09.2026 9.8
CVE-2026-86778 Username Enumeration in Maksisoft Technology's Maksisoft Gym 30.09.2026 5.3
CVE-2026-100507 WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-100508 WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability 30.09.2026 5.3
CVE-2026-100513 WordPress CF7 Views &#8211; Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-102384 WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) vulnerability 30.09.2026 5.9
CVE-2026-102385 WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-102386 WordPress WP Photo Album Plus plugin <= 9.3.02.003 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-102395 WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-102396 WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-102398 WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-102399 WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability 30.09.2026 5.4
CVE-2026-103116 OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection 30.09.2026
CVE-2026-27085 WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability 30.09.2026 2.7
CVE-2026-27371 WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-62078 WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-62079 WordPress Qi Addons For Elementor plugin <= 1.11 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-62080 WordPress Happy Addons for Elementor plugin <= 3.23.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-62081 WordPress Flexible PDF Coupons plugin <= 1.14.11 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 5.4
CVE-2026-62083 WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability 30.09.2026 5.4
CVE-2026-62085 WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-93512 WordPress JW Player for WordPress plugin <= 2.3.11 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-93514 WordPress Notification for Telegram plugin <= 3.5.2 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-93621 WordPress WP Data Access plugin <= 5.5.84 - SQL Injection vulnerability 30.09.2026 8.2
CVE-2026-93624 WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-93651 WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.1.2 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-93770 WordPress WP Statistics plugin <= 14.16.13 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-93771 WordPress Cost of Goods for WooCommerce plugin <= 3.5.2 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-94074 WordPress Simply Schedule Appointments plugin <= 1.6.12.29 - Broken Access Control vulnerability 30.09.2026 6.5
CVE-2026-94076 WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection vulnerability 30.09.2026 8.8
CVE-2026-94077 WordPress Safe SVG plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-94078 WordPress Site Reviews plugin <= 8.3.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-94081 WordPress WordPress Persistent Login plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-94082 WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-94115 WordPress Easy Pricing Tables plugin <= 4.1.2 - SQL Injection vulnerability 30.09.2026 8.5
CVE-2026-94120 WordPress GravityExport Lite for Gravity Forms plugin <= 2.7.2 - Broken Access Control vulnerability 30.09.2026 7.5
CVE-2026-94121 WordPress 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin <= 2.33.6 - PHP Object Injection vulnerability 30.09.2026 8.8
CVE-2026-94122 WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-94123 WordPress NextGEN Gallery plugin <= 4.5.0 - Arbitrary File Download vulnerability 30.09.2026 7.5
CVE-2026-94173 WordPress Business Directory plugin <= 6.4.27 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 5.4
CVE-2026-94177 WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability 30.09.2026 8.5
CVE-2026-94178 WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability 30.09.2026 7.5
CVE-2026-94389 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability 30.09.2026 9
CVE-2026-94499 WordPress FormGent plugin <= 1.12.2 - Broken Access Control vulnerability 30.09.2026 7.1
CVE-2026-94672 WordPress Safe SVG plugin <= 2.5.0 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 4.3
CVE-2026-94673 WordPress Simply Schedule Appointments plugin <= 1.6.12.31 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 5.3
CVE-2026-94674 WordPress Pixel Manager for WooCommerce plugin <= 1.69.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-94677 WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-94678 WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerability 30.09.2026 8.8
CVE-2026-94681 WordPress WP Store Locator plugin < 3.0.0 - Denial of Service Attack vulnerability 30.09.2026 5.9
CVE-2026-94683 WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability 30.09.2026 8.8
CVE-2026-95531 WordPress Conversational Forms for ChatBot plugin <= 1.5.0 - PHP Object Injection vulnerability 30.09.2026 8.8
CVE-2026-95587 WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability 30.09.2026 7.5
CVE-2026-96338 WordPress Profile Builder plugin <= 4.0.2 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-96343 WordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-96344 WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-96345 WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-96346 WordPress WP ERP plugin <= 1.17.9 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-96347 WordPress Bookly plugin <= 28.2 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 6.5
CVE-2026-96348 WordPress Bookly plugin <= 28.2 - Broken Access Control vulnerability 30.09.2026 7.5
CVE-2026-96349 WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability 30.09.2026 10
CVE-2026-96350 WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability 30.09.2026 9.8
CVE-2026-96351 WordPress Classified Listing plugin <= 6.1.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96352 WordPress YITH WooCommerce Ajax Search plugin <= 2.28.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96450 WordPress pixfort Core plugin < 4.3.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 5.4
CVE-2026-96814 WordPress WooCommerce Product Table Lite plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96815 WordPress Vitepos plugin <= 3.5.0 - Privilege Escalation vulnerability 30.09.2026 7.2
CVE-2026-96816 WordPress Trusted Shops Easy Integration for WooCommerce plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96817 WordPress MakeCommerce for WooCommerce plugin <= 4.1.0 - Broken Access Control vulnerability 30.09.2026 8.2
CVE-2026-96818 WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Broken Access Control vulnerability 30.09.2026 7.5
CVE-2026-96819 WordPress oik plugin <= 4.15.4 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96820 WordPress Awesome Support plugin <= 6.3.9 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96821 WordPress FluentBoards plugin <= 2.0.12 - Privilege Escalation vulnerability 30.09.2026 6.3
CVE-2026-96822 WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability 30.09.2026 9.3
CVE-2026-96823 WordPress Customer Reviews for WooCommerce plugin <= 5.120.0 - Arbitrary Content Deletion vulnerability 30.09.2026 7.5
CVE-2026-96824 WordPress Template Kit – Import plugin <= 1.0.16 - Arbitrary File Deletion vulnerability 30.09.2026 6.8
CVE-2026-96825 WordPress All In One WP Security & Firewall plugin <= 5.4.8 - Bypass Vulnerability vulnerability 30.09.2026 4.2
CVE-2026-96827 WordPress Admin Notices Manager plugin <= 1.6.0 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-96828 WordPress Category Discount Woocommerce plugin <= 5.18 - SQL Injection vulnerability 30.09.2026 7.6
CVE-2026-96829 WordPress The Plus Addons for Elementor Page Builder Lite plugin <= 6.5.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-96830 WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96831 WordPress Themify Builder plugin <= 7.8.1 - PHP Object Injection vulnerability 30.09.2026 8.8
CVE-2026-96832 WordPress Content Egg plugin <= 6.3.1 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-96833 WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.51 - PHP Object Injection vulnerability 30.09.2026 7.2
CVE-2026-96834 WordPress GiveWP plugin <= 4.16.9 - Sensitive Data Exposure vulnerability 30.09.2026 6.5
CVE-2026-96835 WordPress King Addons for Elementor plugin <= 51.1.85 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-96836 WordPress Parsi Date plugin <= 6.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-96837 WordPress CartFlows plugin <= 3.2.0 - Remote Code Execution (RCE) vulnerability 30.09.2026 8.8
CVE-2026-96838 WordPress Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerability 30.09.2026 8.8
CVE-2026-97065 WordPress Happyforms plugin <= 1.26.15 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97066 WordPress GiveWP plugin <= 4.16.9 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 5.3
CVE-2026-97067 WordPress EWWW Image Optimizer plugin <= 8.7.7 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97074 WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin <= 1.9.0 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 4.3
CVE-2026-97077 WordPress Ad Inserter plugin <= 2.8.18 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97078 WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.17 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 5.3
CVE-2026-97079 WordPress Webba Booking plugin <= 6.5.0 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 4.3
CVE-2026-97197 WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Control vulnerability 30.09.2026 7.5
CVE-2026-97235 WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97236 WordPress ThemeREX Addons plugin < 2.45.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97237 WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97238 WordPress JetEngine plugin <= 3.8.14.3 - Cross Site Scripting (XSS) vulnerability 30.09.2026 5.5
CVE-2026-97239 WordPress MCP Content Manager Lite plugin <= 1.1.0 - Broken Access Control vulnerability 30.09.2026 6.5
CVE-2026-97240 WordPress StifLi Backup Tools plugin <= 2.2.7 - Sensitive Data Exposure vulnerability 30.09.2026 7.5
CVE-2026-97241 WordPress BackupEase plugin <= 2.2.2 - Sensitive Data Exposure vulnerability 30.09.2026 7.5
CVE-2026-97242 WordPress WEBO MCP plugin <= 3.0.18 - Arbitrary File Deletion vulnerability 30.09.2026 6.8
CVE-2026-97243 WordPress AllAble Connector plugin <= 0.13.4 - Broken Access Control vulnerability 30.09.2026 5.4
CVE-2026-97244 WordPress Creator LMS plugin <= 1.2.19 - Path Traversal vulnerability 30.09.2026 7.5
CVE-2026-97245 WordPress SureCart plugin <= 4.7.2 - Privilege Escalation vulnerability 30.09.2026 7.2
CVE-2026-97246 WordPress ShortPixel Image Optimizer plugin <= 6.5.5 - PHP Object Injection vulnerability 30.09.2026 4.9
CVE-2026-97247 WordPress Blocksy Companion plugin <= 2.1.55 - Broken Access Control vulnerability 30.09.2026 6.5
CVE-2026-97248 WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-97249 WordPress Paid Member Subscriptions plugin <= 3.0.9 - Bypass Vulnerability vulnerability 30.09.2026 5.3
CVE-2026-97250 WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97253 WordPress LayerSlider plugin <= 8.4.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97261 WordPress Notivo plugin <= 1.4.2 - Sensitive Data Exposure vulnerability 30.09.2026 5.3
CVE-2026-97262 WordPress Visual Composer Website Builder plugin <= 45.16.2 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97266 WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97267 WordPress Prevent files / folders access plugin <= 2.6.7 - Broken Access Control vulnerability 30.09.2026 4.3
CVE-2026-97270 WordPress CMB2 plugin <= 2.13.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97271 WordPress WPFunnels plugin <= 3.13.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97272 WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.13 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97274 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability 30.09.2026 9.8
CVE-2026-97279 WordPress Polylang plugin <= 3.8.9 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97282 WordPress Review Schema plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability 30.09.2026 5.3
CVE-2026-97285 WordPress The Events Calendar plugin <= 6.17.5 - Broken Access Control vulnerability 30.09.2026 5.4
CVE-2026-97286 WordPress Strong Testimonials plugin <= 3.3.11 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97287 WordPress Event Tickets plugin <= 5.29.5 - SQL Injection vulnerability 30.09.2026 8.5
CVE-2026-97288 WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97289 WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability 30.09.2026 7.1
CVE-2026-97292 WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97293 WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability 30.09.2026 8.5
CVE-2026-97298 WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97299 WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability 30.09.2026 5.4
CVE-2026-97301 WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability 30.09.2026 6.5
CVE-2026-97302 WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability 30.09.2026 5.3
CVE-2026-103115 OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection 30.09.2026
CVE-2026-103321 MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image 30.09.2026
CVE-2026-74864 Authentication Bypass in sogo_yhn 30.09.2026
CVE-2026-74865 Authentication Bypass in sogo_yhn 30.09.2026
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection 30.09.2026
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference 30.09.2026
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce 30.09.2026
CVE-2026-95616 Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions 30.09.2026
CVE-2026-85532 Apache WSS4J: Insufficient Validation of Derived-Key Parameters 30.09.2026
CVE-2026-87830 Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. 30.09.2026
CVE-2026-88920 Apache WSS4J: SAML Sender-Vouches Authentication Bypass 30.09.2026
CVE-2026-103242 Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag 30.09.2026
CVE-2026-62146 Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket 30.09.2026
CVE-2026-10726 Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation 30.09.2026
CVE-2026-10739 Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation 30.09.2026
CVE-2026-103012 30.09.2026
CVE-2026-103114 OS4ED openSIS-Classic Assignment Management Endpoint Assignments.php DBQuery_assignment sql injection 30.09.2026
CVE-2026-13719 Alert rules in restricted folders disclosed via the alert rules list API 30.09.2026 4.3
CVE-2026-13720 Editor can forge file-provisioning provenance on dashboards via the dashboard API 30.09.2026 5.4
CVE-2026-76992 Uncontrolled Memory Allocation in CODESYS Gateway Client 30.09.2026
CVE-2026-96342 WordPress WPMobile.App plugin <= 11.83 - Sensitive Data Exposure vulnerability 30.09.2026
CVE-2026-103113 OS4ED openSIS-Classic General Information Tab Student.php save action sql injection 30.09.2026
CVE-2026-103239 MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection 30.09.2026
CVE-2026-103237 MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows 30.09.2026
CVE-2026-10764 Information disclosure in BVMS 4.5 up to 12.3 30.09.2026 8.7
CVE-2026-77185 Apache MINA SSHD: Asynchronous authentication can bypass signature verification 30.09.2026 9.1
CVE-2026-93994 Apache MINA SSHD: Repeated-publickey policy bypass on server 30.09.2026 8.1
CVE-2026-93995 Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the server 30.09.2026 6.5
CVE-2026-93996 Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read 30.09.2026 6.5
CVE-2026-94002 Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies 30.09.2026 7.5
CVE-2026-94053 Apache MINA SSHD: LDAP injection in sshd-ldap 30.09.2026 9.1
CVE-2026-79625 Improper Synchronization in Monitoring in CODESYS Control Runtime 30.09.2026
CVE-2026-94029 Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension 30.09.2026 6.5
CVE-2026-94052 Apache MINA SSHD: LDAP password authentication ineffective 30.09.2026 9.1
CVE-2026-103235 MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events 30.09.2026
CVE-2026-102455 DigiWin|EasyFlow .NET - Insecure Deserialization 30.09.2026
CVE-2026-102456 DigiWin|EasyFlow .NET - SQL Injection 30.09.2026
CVE-2026-102457 DigiWin|EasyFlow .NET - Arbitrary File Read 30.09.2026
CVE-2026-102458 DigiWin|EasyFlow .NET - Missing Authentication 30.09.2026
CVE-2026-102459 DigiWin|EasyFlow .NET - Reflected Cross-site Scripting 30.09.2026
CVE-2026-102577 Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass 30.09.2026
CVE-2026-102578 Moodle: sql injection in question bank web service 30.09.2026
CVE-2026-102579 Moodle: user profile information disclosure via grade web service 30.09.2026
CVE-2026-102580 Moodle: arbitrary class instantiation via report builder audience classname 30.09.2026
CVE-2026-102581 Moodle: xss in forum post templates due to insufficient escaping 30.09.2026
CVE-2026-102582 Moodle: manual enrolment page accessible when plugin disabled 30.09.2026
CVE-2026-102583 Moodle: incorrect capability check in ai generate image web service 30.09.2026
CVE-2026-102584 Moodle: missing capability check allows unauthorised grade penalty recalculation 30.09.2026
CVE-2026-102585 Moodle: group validation missing when enrolling user to course 30.09.2026
CVE-2026-102586 Moodle: xss via password reset link due to insufficient username escaping 30.09.2026
CVE-2026-102587 Moodle: user list filters bypass profile field visibility 30.09.2026
CVE-2026-102588 Moodle: csrf in xml grade import 30.09.2026
CVE-2025-14564 Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload 30.09.2026 6.4
CVE-2026-102454 DigiWin|EasyFlow .NET - Arbitrary File Upload 30.09.2026
CVE-2026-102509 Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser 30.09.2026
CVE-2026-102510 Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths 30.09.2026
CVE-2026-102511 Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them 30.09.2026
CVE-2026-75098 Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design 30.09.2026 7.5
CVE-2026-92712 ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter 30.09.2026 6.4
CVE-2026-93908 Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'before_price_text' Parameter 30.09.2026 6.4
CVE-2026-97347 Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header 30.09.2026 7.2
CVE-2026-92873 30.09.2026
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade 30.09.2026
CVE-2026-11895 HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting 30.09.2026 6.4
CVE-2026-14876 Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block 30.09.2026 6.4
CVE-2026-16596 WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter 30.09.2026 6.5
CVE-2026-6170 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute 30.09.2026 6.4
CVE-2026-6171 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute 30.09.2026 6.4
CVE-2026-6172 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'caption' Parameter 30.09.2026 6.4
CVE-2026-6173 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter 30.09.2026 6.4
CVE-2026-6806 Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters 30.09.2026 7.5
CVE-2026-88037 Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title 30.09.2026 6.4
CVE-2026-92871 30.09.2026
CVE-2026-92872 30.09.2026
CVE-2026-93460 30.09.2026
CVE-2026-93462 30.09.2026
CVE-2026-93463 30.09.2026
CVE-2026-93464 30.09.2026
CVE-2026-92867 30.09.2026
CVE-2026-92868 30.09.2026
CVE-2026-92869 30.09.2026
CVE-2026-92870 30.09.2026
CVE-2026-97150 30.09.2026
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability 30.09.2026 9.1
CVE-2026-89294 Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter 30.09.2026 7.5
CVE-2026-100143 FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email 30.09.2026
CVE-2026-75823 WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption 30.09.2026
CVE-2026-75824 WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled 30.09.2026
CVE-2026-75873 Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload 30.09.2026
CVE-2026-80333 Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes 30.09.2026
CVE-2026-82127 Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields 30.09.2026
CVE-2026-83560 New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass 30.09.2026
CVE-2026-85001 EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute 30.09.2026
CVE-2026-85415 Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL 30.09.2026
CVE-2026-85573 All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload 30.09.2026
CVE-2026-85576 All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update 30.09.2026
CVE-2026-86789 Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes 30.09.2026
CVE-2026-87777 Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute 30.09.2026
CVE-2026-88791 Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules 30.09.2026
CVE-2026-88797 Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation 30.09.2026
CVE-2026-89190 Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax 30.09.2026
CVE-2026-89193 Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser 30.09.2026
CVE-2026-90953 Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks 30.09.2026
CVE-2026-91051 EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta 30.09.2026
CVE-2026-91072 EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler 30.09.2026
CVE-2026-91832 WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF 30.09.2026
CVE-2026-92424 Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue 30.09.2026
CVE-2026-92994 Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API 30.09.2026
CVE-2026-93580 InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook 30.09.2026
CVE-2026-94274 YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API 30.09.2026
CVE-2026-94297 Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation 30.09.2026
CVE-2026-96886 Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export 30.09.2026
CVE-2026-97316 Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass 30.09.2026
CVE-2026-102913 SourceCodester Car Driving School Management System Master.php save_enrollment sql injection 30.09.2026
CVE-2026-103111 30.09.2026 7.6
CVE-2026-102912 SourceCodester Online Leave Management System page reports sql injection 30.09.2026
CVE-2026-102910 SourceCodester Online Reviewer Management System exam-delete.php sql injection 30.09.2026
CVE-2026-102911 zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection 30.09.2026
CVE-2026-86134 Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service 30.09.2026
CVE-2026-103110 30.09.2026 9.8
CVE-2026-102909 SourceCodester Online Reviewer Management System btn_functions.php sql injection 30.09.2026
CVE-2026-103109 30.09.2026 7.7
CVE-2026-102908 SourceCodester Online Reviewer Management System questions-view.php sql injection 30.09.2026
CVE-2026-103105 30.09.2026 8.8
CVE-2026-103106 30.09.2026 7.8
CVE-2026-103108 30.09.2026 7.5
CVE-2026-102874 HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection 30.09.2026
CVE-2026-102906 0xshariq github-mcp-server Git Remove MCP Tool github.ts child_process.exec os command injection 30.09.2026
CVE-2026-103099 30.09.2026 7.5
CVE-2026-103100 30.09.2026 7.5
CVE-2026-103101 30.09.2026 8.6
CVE-2026-103102 30.09.2026 8.6
CVE-2026-103104 30.09.2026 7.5
CVE-2026-86556 An information disclosure vulnerability in ZTE U30 Air product 30.09.2026 5.3
CVE-2026-96649 Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) 30.09.2026 7.2
CVE-2026-102847 gedelumbung HospitalManagement Guest Book buku_tamu.php kirim cross site scripting 30.09.2026
CVE-2026-78229 30.09.2026 6.7
CVE-2026-81310 30.09.2026 6.6
CVE-2026-102845 gedelumbung HospitalManagement HTTP Response index.php error_reporting information disclosure 30.09.2026
CVE-2026-102846 gedelumbung HospitalManagement Configuration sistem.php simpan improper authorization 30.09.2026
CVE-2026-102843 gedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversal 30.09.2026
CVE-2026-102844 gedelumbung HospitalManagement laporan_data_pasien.php detail authorization 30.09.2026
CVE-2026-103087 30.09.2026
CVE-2026-103088 30.09.2026 7.5
CVE-2026-102804 Nothings stb stb_hexwave.h hexwave_init integer overflow 30.09.2026
CVE-2026-102805 Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer overflow 30.09.2026
CVE-2026-102842 gedelumbung HospitalManagement KCFinder File Manager app_user_login_model.php cekUserLogin unrestricted upload 30.09.2026
CVE-2026-103053 AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-Action API 30.09.2026
CVE-2026-103054 AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP 30.09.2026
CVE-2026-103055 AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret 30.09.2026
CVE-2026-103056 AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR 30.09.2026
CVE-2026-103057 AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal Endpoints 30.09.2026
CVE-2026-51936 30.09.2026
CVE-2026-102794 Ziroom ZHOME A0101 ping command injection 30.09.2026
CVE-2026-102793 Ziroom ZHOME A0101 set_time_zone command injection 29.09.2026
CVE-2026-103048 Open Redirect in Special:Book 29.09.2026
CVE-2026-103049 XSS in Cargo's Special:CargoQuery page due to unsanitized table headers 29.09.2026
CVE-2026-103050 Stored i18n XSS in MassMessage 29.09.2026
CVE-2026-103051 Stored i18n XSSs in CentralNotice 29.09.2026
CVE-2026-13046 Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution 30.09.2026
CVE-2026-13224 Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read 30.09.2026
CVE-2026-18105 Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service 30.09.2026
CVE-2026-18145 Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution 30.09.2026
CVE-2026-81433 Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution 30.09.2026
CVE-2026-86101 Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access 30.09.2026
CVE-2026-86104 Fireware OS Resource Exhaustion in Login Process Allows Denial of Service 30.09.2026
CVE-2026-86105 Fireware OS Improper Authorization in Access Portal Reverse Proxy 30.09.2026
CVE-2026-86128 Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service 30.09.2026
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution 30.09.2026
CVE-2026-86132 Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service 30.09.2026
CVE-2026-86133 Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service 30.09.2026
CVE-2026-86136 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A 30.09.2026
CVE-2026-90441 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B 30.09.2026
CVE-2026-103047 XSS through i18n message in CentralAuth 29.09.2026
CVE-2026-103040 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service 30.09.2026
CVE-2026-103041 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service 30.09.2026
CVE-2026-103042 LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_value 29.09.2026
CVE-2026-103043 anchorme through 3.0.8 Regular Expression Denial of Service 29.09.2026
CVE-2026-103045 XSS in Refreshed skin 29.09.2026
CVE-2026-102792 Ziroom ZHOME A0101 set_syslog command injection 29.09.2026
CVE-2026-103044 EasyTimeline should not serve image maps as application/xml 29.09.2026
CVE-2026-103046 WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML 29.09.2026
CVE-2026-15278 29.09.2026
CVE-2026-102771 Naichen ThinkCMF Email Template MailController.php templatePut special elements in template engine 30.09.2026
CVE-2026-69662 Toptech TMS7 and TopHAT Eval Injection 30.09.2026 3.7
CVE-2026-71189 Toptech TMS7 and TopHAT Cross-site Scripting 30.09.2026 3.5
CVE-2026-68068 Toptech TMS7 and TopHAT SQL Injection 30.09.2026 9
CVE-2026-71302 Toptech TMS7 and TopHAT Session Fixation 30.09.2026 7.1
CVE-2026-72507 Toptech TMS7 and TopHAT SQL Injection 30.09.2026 9