CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-90970 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 02.10.2026 9.9
CVE-2026-19652 Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter 02.10.2026 9.8
CVE-2026-83632 Apache Thrift: C++ THttpTransport grows its line buffer without bound 02.10.2026 9.2
CVE-2026-104610 Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow 02.10.2026 10
CVE-2026-104611 Tenda AC9 POST Request fast_setting_internet_set stack-based overflow 02.10.2026 9.4
CVE-2026-104467 YesWiki before 4.6.7 Authorization Bypass via Public API Mode 02.10.2026 9.2
CVE-2026-91135 Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) 02.10.2026 9.2
CVE-2026-86325 02.10.2026 9.4
CVE-2026-94541 WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter 02.10.2026 9.8
CVE-2026-97637 JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response 02.10.2026 9.8
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value 02.10.2026 9.1
CVE-2026-93029 02.10.2026 9
CVE-2026-93697 02.10.2026 9
CVE-2026-93698 02.10.2026 9.9
CVE-2026-15896 Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter 02.10.2026 9.1
CVE-2026-19660 Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter 02.10.2026 9.8
CVE-2026-14378 DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow 02.10.2026 9.8
CVE-2026-104480 Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership 02.10.2026 9.4
CVE-2026-86345 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result 02.10.2026 9
CVE-2026-103764 Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport 01.10.2026 9.3
CVE-2026-18397 SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability 01.10.2026 9.4
CVE-2026-71449 01.10.2026 9.3
CVE-2026-55393 Local File Inclusion in Teledyne FLIR Robots running Aware2 01.10.2026 10
CVE-2026-55395 Hardcoded Passwords in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-14984 Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-102628 Cadmos LTI exposure of sensitive information via debug mode 01.10.2026 9.2
CVE-2026-102667 Joyland AI WebView command injection 01.10.2026 9
CVE-2026-53953 GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover 01.10.2026 9.1
CVE-2026-56660 GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction 01.10.2026 9.1
CVE-2026-56662 GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request 01.10.2026 9.6
CVE-2026-104286 02.10.2026 9.8
CVE-2026-55083 DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) 01.10.2026 9.1
CVE-2026-103922 Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path 01.10.2026 9.3
CVE-2026-13043 WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access 01.10.2026 9.3
CVE-2026-96658 Foreman: safemode bypass leading to rce 02.10.2026 9.9
CVE-2026-96659 Foreman: excessive permissions for viewer role on preview 01.10.2026 9.1
CVE-2026-94620 Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 01.10.2026 9.4
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability 01.10.2026 9.8
CVE-2026-79898 Fortra BoKS Manager crlserver command injection vulnerability 01.10.2026 9.1
CVE-2026-103752 WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability 01.10.2026 9.8
CVE-2026-62071 WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability 01.10.2026 9.3
CVE-2026-79901 Predictable Active Directory service-account passwords in BoKS Manager 01.10.2026 9.9
CVE-2026-103244 ground-station before 0.8.0 Authentication Bypass via setup.restore 01.10.2026 9.3
CVE-2026-103264 Fleet before 4.87.0 Authentication Bypass via Device Identifiers 01.10.2026 9.3
CVE-2026-103655 MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period 01.10.2026 9.3
CVE-2026-15989 Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter 01.10.2026 9.8
CVE-2026-75957 Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter 01.10.2026 9.8
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects 01.10.2026 9.3
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted 01.10.2026 9.3
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed 01.10.2026 9.3
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens 01.10.2026 9.3
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process 01.10.2026 9.3
CVE-2026-76142 Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface 01.10.2026 9.3
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field 01.10.2026 9.1
CVE-2026-14157 02.10.2026 9.4
CVE-2026-101283 01.10.2026 9.2
CVE-2026-101276 01.10.2026 9.2
CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication 01.10.2026 9.1
CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102115 Kiteworks Core Authentication Bypass in the Password Reset Workflow 01.10.2026 9.8
CVE-2026-102147 Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) 01.10.2026 9.3
CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control 01.10.2026 9.4
CVE-2026-102992 piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env 30.09.2026 9.2
CVE-2026-103547 30.09.2026 9.2
CVE-2026-100512 WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-103473 Deno 2.7.0 through 2.9.7 Command Injection via node:child_process 30.09.2026 9.2
CVE-2026-103475 yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure 30.09.2026 9.3
CVE-2026-55107 Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) 30.09.2026 10
CVE-2026-55181 Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false 30.09.2026 9.4
CVE-2026-55494 Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset 30.09.2026 9.8
CVE-2026-62308 Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint 30.09.2026 9.1
CVE-2026-55176 Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token 30.09.2026 9
CVE-2026-102489 Undisclosed RCE in Zammad v6.3 and higher 02.10.2026 9.4
CVE-2026-102490 Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha 02.10.2026 9.4
CVE-2026-19445 Use-after-free of a server-side SSLContext when sni_callback switches contexts 02.10.2026 9.2
CVE-2026-75969 PTZOptics Missing Authentication in Firmware Upload 30.09.2026 9.1
CVE-2026-103470 30.09.2026 9.3
CVE-2026-102427 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 30.09.2026 10
CVE-2026-103395 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service 30.09.2026 9.3
CVE-2026-76570 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 30.09.2026 10
CVE-2026-18782 SQL Injection in Trex Digital Manufacturing's Trex MES 30.09.2026 9.8
CVE-2026-93903 30.09.2026 9.4
CVE-2026-82307 Multiple Vulnerabilities in Dolusoft Software's SOPLOG 30.09.2026 9.8
CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 01.10.2026 9.8
CVE-2026-94389 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability 30.09.2026 9
CVE-2026-96349 WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability 30.09.2026 10
CVE-2026-96350 WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability 30.09.2026 9.8
CVE-2026-96822 WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability 30.09.2026 9.3
CVE-2026-97248 WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-97274 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability 30.09.2026 9.8
CVE-2026-74864 Authentication Bypass in sogo_yhn 30.09.2026 9.3
CVE-2026-74865 Authentication Bypass in sogo_yhn 30.09.2026 9.2
CVE-2026-77185 Apache MINA SSHD: Asynchronous authentication can bypass signature verification 30.09.2026 9.1
CVE-2026-94053 Apache MINA SSHD: LDAP injection in sshd-ldap 30.09.2026 9.1
CVE-2026-94052 Apache MINA SSHD: LDAP password authentication ineffective 30.09.2026 9.1
CVE-2026-102455 DigiWin|EasyFlow .NET - Insecure Deserialization 30.09.2026 9.3
CVE-2026-102458 DigiWin|EasyFlow .NET - Missing Authentication 30.09.2026 9.3
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade 30.09.2026 9.2
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability 30.09.2026 9.1
CVE-2026-102911 zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection 30.09.2026 9.4
CVE-2026-103110 02.10.2026 9.8
CVE-2026-103056 AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR 30.09.2026 9.4
CVE-2026-102794 Ziroom ZHOME A0101 ping command injection 30.09.2026 9.4
CVE-2026-102793 Ziroom ZHOME A0101 set_time_zone command injection 01.10.2026 9.4
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution 01.10.2026 9.2
CVE-2026-103040 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service 30.09.2026 9.3
CVE-2026-103041 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service 30.09.2026 9.3
CVE-2026-102792 Ziroom ZHOME A0101 set_syslog command injection 02.10.2026 9.4
CVE-2026-70356 Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type 30.09.2026 9.4
CVE-2026-71379 Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties 30.09.2026 10
CVE-2026-96587 Use of Hard-coded Credentials in Viidure Dashcam Android Application 29.09.2026 10
CVE-2026-53988 Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints 02.10.2026 9.2
CVE-2026-100291 Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 29.09.2026 9.3
CVE-2026-76721 Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs 30.09.2026 9.8
CVE-2026-76722 Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs 01.10.2026 9.8
CVE-2026-76723 Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS 01.10.2026 9.6
CVE-2026-76724 Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol 01.10.2026 9.6
CVE-2026-76725 Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs 01.10.2026 9.6
CVE-2026-102829 simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 30.09.2026 9.2
CVE-2026-102828 simple-git unsafe-operation guard does not block trailer command configuration 30.09.2026 9.2
CVE-2026-84436 IBM Guardium Data Protection is affected by multiple vulnerabilities. 30.09.2026 9.1
CVE-2026-102710 30.09.2026 9.3
CVE-2026-102761 30.09.2026 9.3
CVE-2026-102425 Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 01.10.2026 9.5
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 30.09.2026 9.3
CVE-2026-22094 Weak root password in EVbee DC 80 30.09.2026 9.3
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026 9.3
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026 9.3
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026 9
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026 9.3
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 30.09.2026 9.2
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026 10
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026 9.4
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 01.10.2026 9.3
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 01.10.2026 9.4
CVE-2026-101262 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101261 Ziroom ZHOME A0101 firstSetup_wifi command injection 01.10.2026 9.4
CVE-2026-101260 Ziroom ZHOME A0101 firstLogin command injection 29.09.2026 9.4
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection 29.09.2026 9.1
CVE-2026-101187 Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection 29.09.2026 9.4
CVE-2026-102268 PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard 29.09.2026 9.1
CVE-2026-100752 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 30.09.2026 9.3
CVE-2026-101108 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 30.09.2026 9.3
CVE-2026-101110 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 30.09.2026 9.3
CVE-2026-49994 Bluehood: Missing authentication on Bluehood API routes when web auth is enabled 28.09.2026 9.1
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access 28.09.2026 9.3
CVE-2026-101894 @xhmikosr/decompress: Path traversal via symlink chain 28.09.2026 9.1
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution 28.09.2026 9.3
CVE-2026-101081 D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow 28.09.2026 9.4
CVE-2026-88804 Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher 28.09.2026 9.6
CVE-2026-12342 SailPoint IdentityIQ Improper Form Validation Vulnerability 29.09.2026 9.6
CVE-2026-101076 Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection 01.10.2026 10
CVE-2026-101077 Netcore NR289-GE boa_temp process_request missing authentication 28.09.2026 10
CVE-2026-101075 Netcore NR289-GE Location Time location_time.cgi system os command injection 28.09.2026 10
CVE-2026-101074 Netcore NR289-GE Authentication boa password-check stack-based overflow 28.09.2026 9.3
CVE-2026-90924 Default Admin Credentials in Innotim Software's Logsign SIEM 28.09.2026 9.8
CVE-2026-101072 Netcore NR289-GE CGI ap_ip.cgi system os command injection 28.09.2026 10
CVE-2026-73640 Time-based SQL Injection in Dayforce Payroll 28.09.2026 9.3
CVE-2026-73642 Path Traversal in Dayforce Payroll 28.09.2026 9.2
CVE-2026-85185 Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root 28.09.2026 9.6
CVE-2026-85526 Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD 29.09.2026 9.9
CVE-2026-87799 Arbitrary file write on LXD host via symlink in migration stream 29.09.2026 9.9
CVE-2026-81867 Deserialization of Untrusted Data in Application Integration allows Remote Code Execution 30.09.2026 9.4
CVE-2026-101039 FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow 28.09.2026 10
CVE-2026-101038 FAST FAC1200R MmtAtePrase stack-based overflow 28.09.2026 9.4
CVE-2026-19759 Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution 28.09.2026 9.4
CVE-2026-101037 FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow 01.10.2026 9.4
CVE-2026-82384 Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint 29.09.2026 9.8
CVE-2026-82377 Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers 29.09.2026 9.9
CVE-2026-82378 Apache Roller: OAuth authorization endpoint trusts request-supplied identity 29.09.2026 9
CVE-2026-101008 aaPanel BaoTa File Merge files.py merge_split_file command injection 28.09.2026 9.4
CVE-2026-101009 aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection 01.10.2026 9.3
CVE-2026-101007 aaPanel BaoTa Database Backup database.py InputSql os command injection 28.09.2026 9.3
CVE-2026-101002 Netcore NBR200V2 Tools Ping network_tools system os command injection 28.09.2026 9.4
CVE-2026-101001 Netcore NBR200V2 Web Management network_tools eval os command injection 28.09.2026 10
CVE-2026-101000 Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization 01.10.2026 10
CVE-2026-100896 TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection 28.09.2026 9.4
CVE-2026-100886 Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication 28.09.2026 10
CVE-2026-101065 Obot Quickstart Docker Deployment Unauthenticated Admin Access 30.09.2026 9.3
CVE-2026-101084 obot before v0.21.1 Authorization Bypass via /mcp-connect 30.09.2026 9.3
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri 28.09.2026 9.3
CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands 29.09.2026 9.5
CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 28.09.2026 9.5
CVE-2026-88773 HTTP Request Smuggling 29.09.2026 9.3
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 28.09.2026 9.8
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 28.09.2026 9.5
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 30.09.2026 9.1
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 28.09.2026 9.4
CVE-2026-82901 Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field 26.09.2026 9.8
CVE-2026-85984 miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter 26.09.2026 9.8
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.4
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.2
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 10
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 29.09.2026 9.5
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 27.09.2026 9.3
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 28.09.2026 9.2
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 28.09.2026 9.2
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 28.09.2026 9.2
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026 9.4
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026 9.4
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 28.09.2026 9.4
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026 9.3
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026 9

Latest Updates

CVE Title Updated Score
CVE-2026-104845 Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization 02.10.2026 7.5
CVE-2026-104907 MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler 02.10.2026
CVE-2026-104908 MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging 02.10.2026
CVE-2026-104844 PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion 02.10.2026 5.9
CVE-2026-104906 MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output 02.10.2026
CVE-2026-51911 02.10.2026
CVE-2026-51914 02.10.2026
CVE-2026-51915 02.10.2026
CVE-2026-51916 02.10.2026
CVE-2026-51917 02.10.2026
CVE-2026-51918 02.10.2026
CVE-2026-51922 02.10.2026
CVE-2026-104843 uv: Path traversal on Windows through wheel extraction 02.10.2026
CVE-2026-51898 02.10.2026
CVE-2026-51899 02.10.2026
CVE-2026-51901 02.10.2026
CVE-2026-51904 02.10.2026
CVE-2026-51906 02.10.2026
CVE-2026-51907 02.10.2026
CVE-2026-104900 MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index 02.10.2026
CVE-2026-104901 MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server 02.10.2026
CVE-2026-94483 Next.js: Server-Side Request Forgery in Image Optimization 02.10.2026
CVE-2026-94484 Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service 02.10.2026
CVE-2026-94485 Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass 02.10.2026
CVE-2026-94486 Next.js: Information disclosure in the Next.js development server's Model Context Protocol endpoint 02.10.2026
CVE-2026-94543 Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications 02.10.2026
CVE-2026-94544 Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages 02.10.2026
CVE-2026-104638 onetwothreeneth HospitalManagementSystem sessions.php improper authentication 02.10.2026
CVE-2026-104637 onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted upload 02.10.2026
CVE-2026-32584 WordPress Smart One Click Setup – Complete Demo Import &amp; Export plugin <= 1.4.3 - Sensitive Data Exposure vulnerability 02.10.2026 5.3
CVE-2026-32585 WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerability 02.10.2026 6.5
CVE-2026-39439 WordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerability 02.10.2026 6.5
CVE-2026-39444 WordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object References (IDOR) vulnerability 02.10.2026 5.4
CVE-2026-39600 WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Forwards vulnerability 02.10.2026 4.7
CVE-2026-39601 WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability 02.10.2026 3.7
CVE-2026-39717 WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability 02.10.2026 4.3
CVE-2026-104625 CodeAstro Simple Loan Management System index.php sql injection 02.10.2026
CVE-2026-90970 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 02.10.2026 9.9
CVE-2026-104026 02.10.2026
CVE-2026-5782 Reflected XSS in Loglama.NET's TurkHotspot 02.10.2026 5.2
CVE-2026-104614 CodeAstro Simple Pharmacy Management System delete.php sql injection 02.10.2026
CVE-2026-94422 xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape 02.10.2026
CVE-2026-19652 Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter 02.10.2026 9.8
CVE-2026-93875 JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter 02.10.2026 7.2
CVE-2026-104613 CodeAstro Simple Pharmacy Management System view.php sql injection 02.10.2026
CVE-2026-104721 Logback: Incomplete protection against CVE-2026-19880 02.10.2026
CVE-2026-85215 SQL Injection in GG Soft's Paperwork 02.10.2026 7.1
CVE-2026-104612 SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting 02.10.2026
CVE-2026-61374 Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit 02.10.2026
CVE-2026-63772 Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count 02.10.2026
CVE-2026-66054 Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize 02.10.2026
CVE-2026-66055 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language) 02.10.2026
CVE-2026-102797 WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability 02.10.2026 6.4
CVE-2026-102798 WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability 02.10.2026 6.5
CVE-2026-104733 User Impersonation/Authorization Bypass in XMPP Server ejabberd 02.10.2026
CVE-2026-11795 User Enumeration in Softtr's E-Commerce Pack 02.10.2026 5.3
CVE-2026-66081 Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages 02.10.2026
CVE-2026-66331 Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize 02.10.2026
CVE-2026-66837 Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length 02.10.2026
CVE-2026-66858 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml) 02.10.2026
CVE-2026-66859 Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route 02.10.2026
CVE-2026-83632 Apache Thrift: C++ THttpTransport grows its line buffer without bound 02.10.2026
CVE-2026-83663 Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go) 02.10.2026
CVE-2026-104610 Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow 02.10.2026
CVE-2026-104611 Tenda AC9 POST Request fast_setting_internet_set stack-based overflow 02.10.2026
CVE-2026-83745 Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D) 02.10.2026
CVE-2026-85209 IDOR in AVEZ Electronics's LMS 02.10.2026 6.5
CVE-2026-85476 Apache Thrift: c_glib `read_all` spins when the underlying read returns 0 02.10.2026
CVE-2026-94654 Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame 02.10.2026
CVE-2026-94655 Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic 02.10.2026
CVE-2026-94656 Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound 02.10.2026
CVE-2026-94657 Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound 02.10.2026
CVE-2026-94658 Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic) 02.10.2026
CVE-2026-96277 Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception 02.10.2026
CVE-2026-96286 Apache Thrift: Perl servers end `serve()` when serving one connection fails 02.10.2026
CVE-2026-96287 Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic) 02.10.2026
CVE-2026-96289 Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard 02.10.2026
CVE-2026-94646 Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers) 02.10.2026
CVE-2026-94648 Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound 02.10.2026
CVE-2026-94652 Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back 02.10.2026
CVE-2026-94653 Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic) 02.10.2026
CVE-2026-104609 onetwothreeneth HospitalManagementSystem edit_accounts.php get sql injection 02.10.2026
CVE-2026-92834 Apache Thrift: C++ WebSocket server transport does not read a full request length 02.10.2026
CVE-2026-94636 Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up 02.10.2026
CVE-2026-94637 Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame 02.10.2026
CVE-2026-94638 Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize` 02.10.2026
CVE-2026-103762 SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints 02.10.2026
CVE-2026-103763 SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo 02.10.2026
CVE-2026-104410 SiYuan before 3.8.5 Information Disclosure via /api/export/preview 02.10.2026
CVE-2026-104411 Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads 02.10.2026
CVE-2026-104412 Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment 02.10.2026
CVE-2026-104413 Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images 02.10.2026
CVE-2026-104414 Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses 02.10.2026
CVE-2026-104415 Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API 02.10.2026
CVE-2026-104416 Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API 02.10.2026
CVE-2026-104417 Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting 02.10.2026
CVE-2026-104418 Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files 02.10.2026
CVE-2026-104419 Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes 02.10.2026
CVE-2026-104420 Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks 02.10.2026
CVE-2026-104421 Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout 02.10.2026
CVE-2026-104422 Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite 02.10.2026
CVE-2026-104423 Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification 02.10.2026
CVE-2026-104424 Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate 02.10.2026
CVE-2026-104425 Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions 02.10.2026
CVE-2026-104426 Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check 02.10.2026
CVE-2026-104427 Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry 02.10.2026
CVE-2026-104428 Zebra before 11.0.0 Denial of Service via getblock Verbosity 2 02.10.2026
CVE-2026-104429 Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages 02.10.2026
CVE-2026-104430 Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount 02.10.2026
CVE-2026-104431 Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification 02.10.2026
CVE-2026-104432 Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response 02.10.2026
CVE-2026-104434 Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC 02.10.2026
CVE-2026-104435 Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output 02.10.2026
CVE-2026-104436 Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length 02.10.2026
CVE-2026-104437 Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling 02.10.2026
CVE-2026-104438 YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions 02.10.2026
CVE-2026-104439 YesWiki before 4.6.7 User Enumeration via Lost-Password Flow 02.10.2026
CVE-2026-104440 YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter 02.10.2026
CVE-2026-104441 YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action 02.10.2026
CVE-2026-104442 YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action 02.10.2026
CVE-2026-104443 YesWiki before 4.6.7 Scope Bypass via Triples Delete API 02.10.2026
CVE-2026-104444 YesWiki before 4.6.7 Authorization Bypass via Comments API editComment 02.10.2026
CVE-2026-104445 YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing 02.10.2026
CVE-2026-104446 YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler 02.10.2026
CVE-2026-104447 YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction 02.10.2026
CVE-2026-104448 YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler 02.10.2026
CVE-2026-104449 YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche 02.10.2026
CVE-2026-104450 YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action 02.10.2026
CVE-2026-104451 YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler 02.10.2026
CVE-2026-104452 YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler 02.10.2026
CVE-2026-104453 YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action 02.10.2026
CVE-2026-104454 YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint 02.10.2026
CVE-2026-104455 YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action 02.10.2026
CVE-2026-104456 YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username 02.10.2026
CVE-2026-104457 YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter 02.10.2026
CVE-2026-104458 YesWiki before 4.6.7 SSRF Guard Bypass via IPv6 Transition Addresses 02.10.2026
CVE-2026-104459 YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle 02.10.2026
CVE-2026-104460 YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch 02.10.2026
CVE-2026-104461 YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField 02.10.2026
CVE-2026-104462 YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter 02.10.2026
CVE-2026-104463 YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox 02.10.2026
CVE-2026-104464 YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter 02.10.2026
CVE-2026-104465 YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler 02.10.2026
CVE-2026-104466 YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute 02.10.2026
CVE-2026-104467 YesWiki before 4.6.7 Authorization Bypass via Public API Mode 02.10.2026
CVE-2026-104468 YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction 02.10.2026
CVE-2026-104469 YesWiki before 4.6.7 Session Fixation via Login in AuthController.php 02.10.2026
CVE-2026-104470 YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action 02.10.2026
CVE-2026-104471 YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import 02.10.2026
CVE-2026-104472 YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler 02.10.2026
CVE-2026-104473 YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages 02.10.2026
CVE-2026-85086 Apache Thrift: Perl TLS client disables certificate verification by default 02.10.2026
CVE-2026-85087 Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op 02.10.2026
CVE-2026-85088 Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match 02.10.2026
CVE-2026-86535 Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely 02.10.2026
CVE-2026-86536 Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScript 02.10.2026
CVE-2026-86537 Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service 02.10.2026
CVE-2026-87117 Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element spec 02.10.2026
CVE-2026-90440 Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service 02.10.2026
CVE-2026-82458 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available 02.10.2026
CVE-2026-82459 Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process 02.10.2026
CVE-2026-61373 Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation 02.10.2026
CVE-2026-96288 Apache Thrift: Erlang generated struct reads have no recursion-depth guard (unbounded memory) 02.10.2026
CVE-2026-96292 Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic) 02.10.2026
CVE-2026-96294 Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection 02.10.2026
CVE-2026-94642 Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception 02.10.2026
CVE-2026-96990 Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound 02.10.2026
CVE-2026-94644 Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound 02.10.2026
CVE-2026-94645 Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound 02.10.2026
CVE-2026-94650 Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion) 02.10.2026
CVE-2026-85483 Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end 02.10.2026
CVE-2026-85493 Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME) 02.10.2026
CVE-2026-85494 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language) 02.10.2026
CVE-2026-94651 Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error 02.10.2026
CVE-2026-104606 itsourcecode Online Admission System Project confirm.php sql injection 02.10.2026
CVE-2026-91135 Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) 02.10.2026
CVE-2026-97876 Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address 02.10.2026 6.4
CVE-2026-59666 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59667 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59668 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-86325 02.10.2026
CVE-2026-86326 02.10.2026
CVE-2026-91137 Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements 02.10.2026
CVE-2026-93925 Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol id 02.10.2026
CVE-2026-93926 Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error path 02.10.2026
CVE-2026-94633 Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length 02.10.2026
CVE-2026-103877 Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements 02.10.2026
CVE-2026-103878 Apache Directory LDAP API: Injection of plaintext responses during StartTLS 02.10.2026
CVE-2026-103880 Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords 02.10.2026
CVE-2026-103885 Apache Directory LDAP API: Denial of service via crafted telephone number values 02.10.2026
CVE-2026-59662 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59663 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59664 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59665 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-94634 Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default 02.10.2026
CVE-2026-104403 WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability 02.10.2026 5.3
CVE-2026-103552 Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder 02.10.2026
CVE-2026-59659 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59660 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59661 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-95662 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-94180 WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability 02.10.2026 4.3
CVE-2026-94405 WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability 02.10.2026 5.3
CVE-2026-94639 Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget) 02.10.2026
CVE-2026-102731 Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode 02.10.2026
CVE-2026-59672 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59673 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-80298 SQL Injection in HAVELSAN's Sef - AI Chatbot Platform 02.10.2026 8.8
CVE-2026-85492 All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname 02.10.2026 6.1
CVE-2026-87920 W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content 02.10.2026 7.2
CVE-2026-94541 WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter 02.10.2026 9.8
CVE-2026-94635 Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name 02.10.2026
CVE-2026-97652 WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key 02.10.2026 6.1
CVE-2026-59670 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-59671 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-80337 Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform 02.10.2026 5.3
CVE-2026-80443 Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform 02.10.2026 7.4
CVE-2026-80464 API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform 02.10.2026 4.9
CVE-2026-95512 Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader 02.10.2026
CVE-2026-59669 Multiple vulnerabilities in the Repasat application 02.10.2026
CVE-2026-91784 Argument Injection leading to arbitrary process termination in gotop 02.10.2026
CVE-2026-18036 NTRU leaks private key information by reducing secret values with a non-constant-time integer division 02.10.2026
CVE-2026-100107 Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) 02.10.2026 7.2
CVE-2026-100182 Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor 02.10.2026 7.2
CVE-2026-102002 Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget 02.10.2026 3.1
CVE-2026-102772 CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field 02.10.2026 7.2
CVE-2026-103426 Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter 02.10.2026 7.2
CVE-2026-12951 MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter 02.10.2026 6.5
CVE-2026-17508 Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points 02.10.2026
CVE-2026-93756 Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview 02.10.2026 7.2
CVE-2026-93880 Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder 02.10.2026 6.1
CVE-2026-94432 Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter 02.10.2026 5.3
CVE-2026-95670 No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect 02.10.2026 7.2
CVE-2026-95817 DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content 02.10.2026 7.2
CVE-2026-96566 Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter 02.10.2026 7.2
CVE-2026-96567 MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta) 02.10.2026 7.2
CVE-2026-96578 GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content 02.10.2026 7.2
CVE-2026-96647 Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter 02.10.2026 6.4
CVE-2026-96871 Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter 02.10.2026 7.2
CVE-2026-97336 CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type 02.10.2026 7.2
CVE-2026-97338 Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name 02.10.2026 6.4
CVE-2026-97342 JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action 02.10.2026 7.2
CVE-2026-97634 Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter 02.10.2026 6.5
CVE-2026-97637 JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response 02.10.2026 9.8
CVE-2026-97641 Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content 02.10.2026 7.2
CVE-2026-97663 Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name 02.10.2026 7.2
CVE-2026-103600 Unbounded ASN.1 nesting depth causes process-terminating stack overflow 02.10.2026
CVE-2026-103601 CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag check 02.10.2026
CVE-2026-103602 Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts 02.10.2026
CVE-2026-103603 Unbounded HSS public key level count allows huge array allocation during signature verification 02.10.2026
CVE-2026-103604 Quadratic-time escaping when converting X.509 distinguished names to strings 02.10.2026
CVE-2026-17507 MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range sender 02.10.2026
CVE-2026-63570 Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links 02.10.2026
CVE-2026-63571 Attribute certificate path validation does not verify the attribute certificate's signature 02.10.2026
CVE-2026-63572 Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files 02.10.2026
CVE-2026-63573 Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap 02.10.2026
CVE-2026-63574 Unbounded allocation from OpenPGP signature and user attribute subpacket lengths 02.10.2026
CVE-2026-63575 PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count 02.10.2026
CVE-2026-63576 URI name constraints checked against a mis-parsed host 02.10.2026
CVE-2026-63577 Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix 02.10.2026
CVE-2026-63578 Unbounded PBE iteration count when decrypting PKCS#8 private keys 02.10.2026
CVE-2026-102565 BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter 02.10.2026 7.2
CVE-2026-13413 CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match 02.10.2026 5.3
CVE-2026-15999 AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication 02.10.2026
CVE-2026-16000 KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used 02.10.2026
CVE-2026-16001 IesEngine stream-mode MAC forgery via length-dependent KDF split 02.10.2026
CVE-2026-1661 WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection 02.10.2026 4.3
CVE-2026-63566 DTLS handshake reassembler allocates buffer from unchecked 24-bit length 02.10.2026
CVE-2026-63567 IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) 02.10.2026
CVE-2026-63568 Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion 02.10.2026
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value 02.10.2026
CVE-2026-79618 WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form 02.10.2026 4.3
CVE-2026-84740 The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter 02.10.2026 6.5
CVE-2026-85005 Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization 02.10.2026 5.4
CVE-2026-90952 WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API 02.10.2026 5.3
CVE-2026-90987 Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price 02.10.2026 5.3
CVE-2026-91020 WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount 02.10.2026 5.3
CVE-2026-92924 Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data 02.10.2026 5.4
CVE-2026-97219 MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter 02.10.2026 4.3
CVE-2026-93029 02.10.2026
CVE-2026-93697 02.10.2026
CVE-2026-93698 02.10.2026
CVE-2026-13718 Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content 02.10.2026
CVE-2026-81740 Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback 02.10.2026
CVE-2026-85004 Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect 02.10.2026
CVE-2026-85016 Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter 02.10.2026
CVE-2026-90988 Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum 02.10.2026
CVE-2026-91022 Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color 02.10.2026
CVE-2026-91023 Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured 02.10.2026
CVE-2026-91828 OMGF < 6.3.11 - Unauthenticated DoS via do_optimize 02.10.2026
CVE-2026-94298 BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter 02.10.2026
CVE-2026-97317 Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page 02.10.2026
CVE-2026-97318 Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter 02.10.2026
CVE-2026-15896 Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter 02.10.2026 9.1
CVE-2026-15897 Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login 02.10.2026 8.8
CVE-2026-78471 Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name 02.10.2026 5.4
CVE-2026-84925 Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter 02.10.2026 6.1
CVE-2026-90438 Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission 02.10.2026 7.2
CVE-2026-92174 SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter 02.10.2026 7.5
CVE-2026-92820 Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload 02.10.2026 8.1
CVE-2026-10026 CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution 02.10.2026 7.2
CVE-2026-19660 Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter 02.10.2026 9.8
CVE-2026-14378 DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow 02.10.2026 9.8
CVE-2026-93367 Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title) 02.10.2026 7.2
CVE-2026-104123 SourceCodester Online Reviewer Management System btn_functions.php activity sql injection 02.10.2026
CVE-2026-104120 modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery 02.10.2026
CVE-2026-104054 calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization 02.10.2026