CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-94620 Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 01.10.2026 9.4
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability 01.10.2026 9.8
CVE-2026-79898 Fortra BoKS Manager crlserver command injection vulnerability 01.10.2026 9.1
CVE-2026-103752 WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability 01.10.2026 9.8
CVE-2026-62071 WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability 01.10.2026 9.3
CVE-2026-79901 Predictable Active Directory service-account passwords in BoKS Manager 01.10.2026 9.9
CVE-2026-103244 ground-station before 0.8.0 Authentication Bypass via setup.restore 01.10.2026 9.3
CVE-2026-103264 Fleet before 4.87.0 Authentication Bypass via Device Identifiers 01.10.2026 9.3
CVE-2026-103655 MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period 01.10.2026 9.3
CVE-2026-15989 Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter 01.10.2026 9.8
CVE-2026-75957 Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter 01.10.2026 9.8
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects 01.10.2026 9.3
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted 01.10.2026 9.3
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed 01.10.2026 9.3
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens 01.10.2026 9.3
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process 01.10.2026 9.3
CVE-2026-76142 Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface 01.10.2026 9.3
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field 01.10.2026 9.1
CVE-2026-14157 01.10.2026 9.4
CVE-2026-101283 01.10.2026 9.2
CVE-2026-101276 01.10.2026 9.2
CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication 01.10.2026 9.1
CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102115 Kiteworks Core Authentication Bypass in the Password Reset Workflow 01.10.2026 9.8
CVE-2026-102147 Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) 01.10.2026 9.3
CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control 01.10.2026 9.4
CVE-2026-102992 piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env 30.09.2026 9.2
CVE-2026-103547 30.09.2026 9.2
CVE-2026-100512 WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-103473 Deno 2.7.0 through 2.9.7 Command Injection via node:child_process 30.09.2026 9.2
CVE-2026-103475 yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure 30.09.2026 9.3
CVE-2026-55107 Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) 30.09.2026 10
CVE-2026-55181 Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false 30.09.2026 9.4
CVE-2026-55494 Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset 30.09.2026 9.8
CVE-2026-62308 Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint 30.09.2026 9.1
CVE-2026-55176 Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token 30.09.2026 9
CVE-2026-102489 Undisclosed RCE in Zammad v6.3 and higher 30.09.2026 9.4
CVE-2026-102490 Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha 30.09.2026 9.4
CVE-2026-19445 Use-after-free of a server-side SSLContext when sni_callback switches contexts 01.10.2026 9.2
CVE-2026-75969 PTZOptics Missing Authentication in Firmware Upload 30.09.2026 9.1
CVE-2026-103470 30.09.2026 9.3
CVE-2026-102427 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 30.09.2026 10
CVE-2026-103395 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service 30.09.2026 9.3
CVE-2026-76570 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 30.09.2026 10
CVE-2026-18782 SQL Injection in Trex Digital Manufacturing's Trex MES 30.09.2026 9.8
CVE-2026-93903 30.09.2026 9.4
CVE-2026-82307 Multiple Vulnerabilities in Dolusoft Software's SOPLOG 30.09.2026 9.8
CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 01.10.2026 9.8
CVE-2026-94389 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability 30.09.2026 9
CVE-2026-96349 WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability 30.09.2026 10
CVE-2026-96350 WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability 30.09.2026 9.8
CVE-2026-96822 WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability 30.09.2026 9.3
CVE-2026-97248 WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-97274 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability 30.09.2026 9.8
CVE-2026-74864 Authentication Bypass in sogo_yhn 30.09.2026 9.3
CVE-2026-74865 Authentication Bypass in sogo_yhn 30.09.2026 9.2
CVE-2026-77185 Apache MINA SSHD: Asynchronous authentication can bypass signature verification 30.09.2026 9.1
CVE-2026-94053 Apache MINA SSHD: LDAP injection in sshd-ldap 30.09.2026 9.1
CVE-2026-94052 Apache MINA SSHD: LDAP password authentication ineffective 30.09.2026 9.1
CVE-2026-102455 DigiWin|EasyFlow .NET - Insecure Deserialization 30.09.2026 9.3
CVE-2026-102458 DigiWin|EasyFlow .NET - Missing Authentication 30.09.2026 9.3
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade 30.09.2026 9.2
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability 30.09.2026 9.1
CVE-2026-102911 zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection 30.09.2026 9.4
CVE-2026-103110 30.09.2026 9.8
CVE-2026-103056 AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR 30.09.2026 9.4
CVE-2026-102794 Ziroom ZHOME A0101 ping command injection 30.09.2026 9.4
CVE-2026-102793 Ziroom ZHOME A0101 set_time_zone command injection 01.10.2026 9.4
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution 01.10.2026 9.2
CVE-2026-103040 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service 30.09.2026 9.3
CVE-2026-103041 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service 30.09.2026 9.3
CVE-2026-102792 Ziroom ZHOME A0101 set_syslog command injection 29.09.2026 9.4
CVE-2026-70356 Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type 30.09.2026 9.4
CVE-2026-71379 Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties 30.09.2026 10
CVE-2026-96587 Use of Hard-coded Credentials in Viidure Dashcam Android Application 29.09.2026 10
CVE-2026-53988 Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints 29.09.2026 9.2
CVE-2026-100291 Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 29.09.2026 9.3
CVE-2026-76721 Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs 30.09.2026 9.8
CVE-2026-76722 Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs 01.10.2026 9.8
CVE-2026-76723 Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS 01.10.2026 9.6
CVE-2026-76724 Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol 01.10.2026 9.6
CVE-2026-76725 Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs 01.10.2026 9.6
CVE-2026-102829 simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 30.09.2026 9.2
CVE-2026-102828 simple-git unsafe-operation guard does not block trailer command configuration 30.09.2026 9.2
CVE-2026-84436 IBM Guardium Data Protection is affected by multiple vulnerabilities. 30.09.2026 9.1
CVE-2026-102710 30.09.2026 9.3
CVE-2026-102761 30.09.2026 9.3
CVE-2026-102425 Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 01.10.2026 9.5
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 30.09.2026 9.3
CVE-2026-22094 Weak root password in EVbee DC 80 30.09.2026 9.3
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026 9.3
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026 9.3
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026 9
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026 9.3
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 30.09.2026 9.2
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026 10
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026 9.4
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 01.10.2026 9.3
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 01.10.2026 9.4
CVE-2026-101262 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101261 Ziroom ZHOME A0101 firstSetup_wifi command injection 01.10.2026 9.4
CVE-2026-101260 Ziroom ZHOME A0101 firstLogin command injection 29.09.2026 9.4
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection 29.09.2026 9.1
CVE-2026-101187 Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection 29.09.2026 9.4
CVE-2026-102268 PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard 29.09.2026 9.1
CVE-2026-100752 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 30.09.2026 9.3
CVE-2026-101108 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 30.09.2026 9.3
CVE-2026-101110 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 30.09.2026 9.3
CVE-2026-49994 Bluehood: Missing authentication on Bluehood API routes when web auth is enabled 28.09.2026 9.1
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access 28.09.2026 9.3
CVE-2026-101894 @xhmikosr/decompress: Path traversal via symlink chain 28.09.2026 9.1
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution 28.09.2026 9.3
CVE-2026-101081 D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow 28.09.2026 9.4
CVE-2026-88804 Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher 28.09.2026 9.6
CVE-2026-12342 SailPoint IdentityIQ Improper Form Validation Vulnerability 29.09.2026 9.6
CVE-2026-101076 Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection 01.10.2026 10
CVE-2026-101077 Netcore NR289-GE boa_temp process_request missing authentication 28.09.2026 10
CVE-2026-101075 Netcore NR289-GE Location Time location_time.cgi system os command injection 28.09.2026 10
CVE-2026-101074 Netcore NR289-GE Authentication boa password-check stack-based overflow 28.09.2026 9.3
CVE-2026-90924 Default Admin Credentials in Innotim Software's Logsign SIEM 28.09.2026 9.8
CVE-2026-101072 Netcore NR289-GE CGI ap_ip.cgi system os command injection 28.09.2026 10
CVE-2026-73640 Time-based SQL Injection in Dayforce Payroll 28.09.2026 9.3
CVE-2026-73642 Path Traversal in Dayforce Payroll 28.09.2026 9.2
CVE-2026-85185 Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root 28.09.2026 9.6
CVE-2026-85526 Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD 29.09.2026 9.9
CVE-2026-87799 Arbitrary file write on LXD host via symlink in migration stream 29.09.2026 9.9
CVE-2026-81867 Deserialization of Untrusted Data in Application Integration allows Remote Code Execution 30.09.2026 9.4
CVE-2026-101039 FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow 28.09.2026 10
CVE-2026-101038 FAST FAC1200R MmtAtePrase stack-based overflow 28.09.2026 9.4
CVE-2026-19759 Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution 28.09.2026 9.4
CVE-2026-101037 FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow 01.10.2026 9.4
CVE-2026-82384 Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint 29.09.2026 9.8
CVE-2026-82377 Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers 29.09.2026 9.9
CVE-2026-82378 Apache Roller: OAuth authorization endpoint trusts request-supplied identity 29.09.2026 9
CVE-2026-101008 aaPanel BaoTa File Merge files.py merge_split_file command injection 28.09.2026 9.4
CVE-2026-101009 aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection 01.10.2026 9.3
CVE-2026-101007 aaPanel BaoTa Database Backup database.py InputSql os command injection 28.09.2026 9.3
CVE-2026-101002 Netcore NBR200V2 Tools Ping network_tools system os command injection 28.09.2026 9.4
CVE-2026-101001 Netcore NBR200V2 Web Management network_tools eval os command injection 28.09.2026 10
CVE-2026-101000 Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization 01.10.2026 10
CVE-2026-100896 TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection 28.09.2026 9.4
CVE-2026-100886 Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication 28.09.2026 10
CVE-2026-101065 Obot Quickstart Docker Deployment Unauthenticated Admin Access 30.09.2026 9.3
CVE-2026-101084 obot before v0.21.1 Authorization Bypass via /mcp-connect 30.09.2026 9.3
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri 28.09.2026 9.3
CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands 29.09.2026 9.5
CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 28.09.2026 9.5
CVE-2026-88773 HTTP Request Smuggling 29.09.2026 9.3
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 28.09.2026 9.8
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 28.09.2026 9.5
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 30.09.2026 9.1
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 28.09.2026 9.4
CVE-2026-82901 Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field 26.09.2026 9.8
CVE-2026-85984 miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter 26.09.2026 9.8
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.4
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.2
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 10
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 29.09.2026 9.5
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 27.09.2026 9.3
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 28.09.2026 9.2
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 28.09.2026 9.2
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 28.09.2026 9.2
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026 9.4
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026 9.4
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 28.09.2026 9.4
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026 9.3
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026 9
CVE-2026-100382 Unauthenticated remote code execution through wikitext in ExternalData 26.09.2026 10
CVE-2026-100389 GestSup before 3.2.62 Remote Code Execution via IMAP Attachment 30.09.2026 9.2
CVE-2026-100390 Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 25.09.2026 9.1
CVE-2026-48482 GLPI: RCE via Form import 30.09.2026 9.4
CVE-2026-84458 Zammad: Account takeover via unverified email matching during SSO auto-link 25.09.2026 9.1
CVE-2026-97063 X-SpringBoot through 6.0 Authentication Bypass via Login Code 25.09.2026 9.3
CVE-2026-97064 X-SpringBoot through 6.0 Authentication Bypass via Static Master Code 30.09.2026 9.3
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 28.09.2026 9.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 29.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 29.09.2026 9.1
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 26.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 28.09.2026 9.3
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026 9.3
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 26.09.2026 9.1

Latest Updates

CVE Title Updated Score
CVE-2026-42356 Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories 01.10.2026
CVE-2026-42528 Apache HTTP Server: mod_dav shared lock overflow 01.10.2026
CVE-2026-46729 Apache HTTP Server: mod_heartmonitor denial of service 01.10.2026
CVE-2026-94620 Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 01.10.2026
CVE-2026-103505 AWS EFS CSI Driver Mount Option Injection via mounttargetipmap 01.10.2026 6.5
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability 01.10.2026 9.8
CVE-2026-18734 01.10.2026
CVE-2026-17053 SMBus callback-removal syscalls accept an unvalidated user pointer, letting user threads manipulate kernel callback state 01.10.2026 4.4
CVE-2026-79896 Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability 01.10.2026 7.5
CVE-2026-56599 HCL BigFix Service Management is affected by multiple security vulnerabilities. 01.10.2026 2.2
CVE-2026-67104 HCL BigFix Service Management is affected by multiple security vulnerabilities. 01.10.2026 5.3
CVE-2026-67105 HCL BigFix Service Management is affected by multiple security vulnerabilities. 01.10.2026 7.4
CVE-2026-67106 HCL BigFix Service Management is affected by multiple security vulnerabilities. 01.10.2026 5.3
CVE-2026-79898 Fortra BoKS Manager crlserver command injection vulnerability 01.10.2026 9.1
CVE-2026-103004 next.js cache leak on warm `use cache` handlers accessing root param 01.10.2026
CVE-2026-56589 HCL BigFix Service Management is affected by multiple security vulnerabilities. 01.10.2026 7.2
CVE-2026-97280 WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability 01.10.2026 6.5
CVE-2026-79899 Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability 01.10.2026 7.9
CVE-2024-58388 Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html 01.10.2026
CVE-2026-100514 WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability 01.10.2026 7.5
CVE-2026-100517 WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object References (IDOR) vulnerability 01.10.2026 7.5
CVE-2026-102378 WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability 01.10.2026 7.1
CVE-2026-103068 WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability 01.10.2026 8.8
CVE-2026-103347 WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability 01.10.2026 5.3
CVE-2026-103687 rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist 01.10.2026
CVE-2026-103752 WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability 01.10.2026 9.8
CVE-2026-62071 WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability 01.10.2026 9.3
CVE-2026-62073 WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability 01.10.2026 7.5
CVE-2026-94390 WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability 01.10.2026 7.2
CVE-2026-95588 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerability 01.10.2026 8.6
CVE-2026-97251 WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Object References (IDOR) vulnerability 01.10.2026 6.5
CVE-2026-97258 WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability 01.10.2026 6.5
CVE-2026-97260 WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability 01.10.2026 7.1
CVE-2026-97268 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability 01.10.2026 7.1
CVE-2026-97269 WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerability 01.10.2026 6.5
CVE-2026-97273 WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability 01.10.2026 7.1
CVE-2026-97277 WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability 01.10.2026 7.6
CVE-2026-97281 WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability 01.10.2026 6.3
CVE-2026-97284 WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability 01.10.2026 8.8
CVE-2026-97297 WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability 01.10.2026 7.6
CVE-2026-79900 Heap overflow in KSL checksum initialization 01.10.2026 6.5
CVE-2026-95137 01.10.2026
CVE-2026-79901 Predictable Active Directory service-account passwords in BoKS Manager 01.10.2026 9.9
CVE-2026-103686 rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting 01.10.2026
CVE-2026-66249 HCL iControl is affected by a Missing Secure Attribute vulnerability 01.10.2026 3.1
CVE-2026-66253 HCL iControl is affected by a Session Timeout vulnerability 01.10.2026 3.1
CVE-2026-102504 Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol 01.10.2026
CVE-2026-102505 Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp 01.10.2026
CVE-2026-66246 HCL iControl is affected by multiple security vulnerabilities 01.10.2026 8.8
CVE-2026-66247 01.10.2026 4.3
CVE-2026-66248 HCL iControl is affected by an Improper Error Handling vulnerability 01.10.2026 3.1
CVE-2026-102379 WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection vulnerability 01.10.2026 8.5
CVE-2026-102381 WordPress Majestic Support plugin <= 1.2.0 - Broken Access Control vulnerability 01.10.2026 5.3
CVE-2026-102382 WordPress Majestic Support plugin <= 1.2.0 - Insecure Direct Object References (IDOR) vulnerability 01.10.2026 4.3
CVE-2026-102390 WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control vulnerability 01.10.2026 5.3
CVE-2026-102394 WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripting (XSS) vulnerability 01.10.2026 6.5
CVE-2026-103063 WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability 01.10.2026 6.5
CVE-2026-103064 WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability 01.10.2026 6.5
CVE-2026-103338 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability 01.10.2026 8.5
CVE-2026-103339 WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability 01.10.2026 6.5
CVE-2026-103340 WordPress Site Reviews plugin <= 8.3.2 - Broken Access Control vulnerability 01.10.2026 5.3
CVE-2026-103341 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Broken Access Control vulnerability 01.10.2026 5.3
CVE-2026-103343 WordPress FluentForm plugin <= 6.2.14 - Cross Site Scripting (XSS) vulnerability 01.10.2026 6.5
CVE-2026-103345 WordPress Pie Register plugin <= 3.8.4.13 - Sensitive Data Exposure vulnerability 01.10.2026 5.3
CVE-2026-62058 WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability 01.10.2026 5.3
CVE-2026-62059 WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability 01.10.2026 7.6
CVE-2026-62060 WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability 01.10.2026 7.6
CVE-2026-62061 WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (IDOR) vulnerability 01.10.2026 5.3
CVE-2026-62063 WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability 01.10.2026 5.4
CVE-2026-103067 WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability 01.10.2026 8
CVE-2026-103754 Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory 01.10.2026
CVE-2026-103336 WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability 01.10.2026 5.3
CVE-2026-103678 Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value 01.10.2026
CVE-2026-103679 Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction 01.10.2026
CVE-2026-103680 Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation 01.10.2026
CVE-2026-103858 MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions 01.10.2026
CVE-2026-94212 Apache APISIX: unauthenticated impersonation issue in saml-auth 01.10.2026
CVE-2026-94220 Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin 01.10.2026
CVE-2026-94250 Apache APISIX: Batch response aggregation can exhaust worker memory 01.10.2026
CVE-2026-94269 Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch 01.10.2026
CVE-2026-94276 Apache APISIX: Openid-connect introspection validation issue 01.10.2026
CVE-2026-78242 Apache APISIX: data-mask may fail to redact request headers in logger output 01.10.2026
CVE-2026-82806 Apache APISIX: cross-request permission pollution via static permission list mutation 01.10.2026
CVE-2026-103353 WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability 01.10.2026 5.3
CVE-2026-88789 Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening 01.10.2026 8.6
CVE-2026-103082 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability 01.10.2026 7.2
CVE-2026-103244 ground-station before 0.8.0 Authentication Bypass via setup.restore 01.10.2026
CVE-2026-103245 n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification 01.10.2026
CVE-2026-103246 n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspection 01.10.2026
CVE-2026-103247 n8n before 1.123.80 Credential Tampering via Duplicate Node IDs 01.10.2026
CVE-2026-103248 n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase 01.10.2026
CVE-2026-103249 n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator 01.10.2026
CVE-2026-103250 n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory 01.10.2026
CVE-2026-103251 n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub 01.10.2026
CVE-2026-103252 n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoint 01.10.2026
CVE-2026-103253 n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table 01.10.2026
CVE-2026-103254 n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation 01.10.2026
CVE-2026-103255 n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase 01.10.2026
CVE-2026-103256 n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook 01.10.2026
CVE-2026-103257 n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node 01.10.2026
CVE-2026-103258 n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation 01.10.2026
CVE-2026-103259 n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials 01.10.2026
CVE-2026-103260 n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node 01.10.2026
CVE-2026-103261 Tornado before 6.5.9 Denial of Service via Query String 01.10.2026
CVE-2026-103262 Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient 01.10.2026
CVE-2026-103263 Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink 01.10.2026
CVE-2026-103264 Fleet before 4.87.0 Authentication Bypass via Device Identifiers 01.10.2026
CVE-2026-103265 Fleet before 4.89.0 Information Disclosure via MDM Command Results 01.10.2026
CVE-2026-103266 Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification 01.10.2026
CVE-2026-103267 Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite 01.10.2026
CVE-2026-103268 Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset 01.10.2026
CVE-2026-103269 Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts 01.10.2026
CVE-2026-103271 Ghost 4.0.0 before 6.63.0 Restricted Content Bypass 01.10.2026
CVE-2026-103272 Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API 01.10.2026
CVE-2026-103273 Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token 01.10.2026
CVE-2026-103274 Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read 01.10.2026
CVE-2026-103275 Ghost 5.42.2 before 6.58.0 Password Hash Disclosure 01.10.2026
CVE-2026-103276 Ghost before 6.20.0 File Read via URL Encoding Bypass 01.10.2026
CVE-2026-103277 Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed 01.10.2026
CVE-2026-103278 Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe 01.10.2026
CVE-2026-103279 Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass 01.10.2026
CVE-2026-103280 Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint 01.10.2026
CVE-2026-103281 Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API 01.10.2026
CVE-2026-103282 Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token 01.10.2026
CVE-2026-103283 Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling 01.10.2026
CVE-2026-103284 Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback 01.10.2026
CVE-2026-103285 Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery 01.10.2026
CVE-2026-103286 Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications 01.10.2026
CVE-2026-103287 Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook 01.10.2026
CVE-2026-103288 Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like 01.10.2026
CVE-2026-103289 Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments 01.10.2026
CVE-2026-103290 Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize 01.10.2026
CVE-2026-103291 Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch 01.10.2026
CVE-2026-103292 Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head 01.10.2026
CVE-2026-103757 Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation 01.10.2026
CVE-2026-103758 Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route 01.10.2026
CVE-2026-7173 Multiple vulnerabilities in Entradium by Crocantickets 01.10.2026
CVE-2026-7174 Multiple vulnerabilities in Entradium by Crocantickets 01.10.2026
CVE-2026-7175 Multiple vulnerabilities in Entradium by Crocantickets 01.10.2026
CVE-2026-7176 Multiple vulnerabilities in Entradium by Crocantickets 01.10.2026
CVE-2026-34189 CSRF in Event Response Deletion 01.10.2026
CVE-2026-34190 CSRF in Alert Command Deletion 01.10.2026
CVE-2026-64946 CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager 01.10.2026
CVE-2026-64947 CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager 01.10.2026
CVE-2026-64948 Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure 01.10.2026
CVE-2026-64949 Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager 01.10.2026
CVE-2026-64950 Stored Cross-Site Scripting via Directory Name in File Manager Create Directory 01.10.2026
CVE-2026-75786 SQL Injection in Grafana Integration Endpoint (query.php) 01.10.2026
CVE-2026-92144 Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter 01.10.2026 7.2
CVE-2026-96256 Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute 01.10.2026 6.4
CVE-2026-103488 01.10.2026 7.1
CVE-2026-103489 01.10.2026 2
CVE-2026-103490 01.10.2026 7.2
CVE-2026-103491 01.10.2026 6.5
CVE-2026-103492 01.10.2026 6.5
CVE-2026-103493 01.10.2026 8.1
CVE-2026-103494 01.10.2026 6.6
CVE-2026-103495 01.10.2026 4.3
CVE-2026-103496 01.10.2026 5.4
CVE-2026-103497 01.10.2026 5.5
CVE-2026-83589 Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect 01.10.2026
CVE-2026-96577 Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled 01.10.2026
CVE-2026-103662 MISP Reflected XSS in Taxonomy Tag Confirmation Forms 01.10.2026
CVE-2026-103664 MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter 01.10.2026
CVE-2026-100179 Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices() 01.10.2026 6.1
CVE-2026-100184 Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value 01.10.2026 4.7
CVE-2026-101925 bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name 01.10.2026 6.4
CVE-2026-103431 Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instances 01.10.2026
CVE-2026-103656 01.10.2026
CVE-2026-103659 MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes 01.10.2026
CVE-2026-14995 Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path 01.10.2026 7.2
CVE-2026-15983 Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter 01.10.2026 8.1
CVE-2026-85235 Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field 01.10.2026 7.2
CVE-2026-89424 Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter 01.10.2026 6.4
CVE-2026-89427 Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter 01.10.2026 6.1
CVE-2026-90992 Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field 01.10.2026 6.4
CVE-2026-92244 PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields 01.10.2026 7.2
CVE-2026-95687 WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint 01.10.2026 8.8
CVE-2026-96268 Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action 01.10.2026 6.4
CVE-2026-96573 Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer 01.10.2026 7.2
CVE-2026-96813 Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields 01.10.2026 7.2
CVE-2026-97661 Business Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field 01.10.2026 7.2
CVE-2026-103655 MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period 01.10.2026
CVE-2026-78249 01.10.2026
CVE-2026-103651 MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass 01.10.2026
CVE-2026-15989 Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter 01.10.2026 9.8
CVE-2026-19807 ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool 01.10.2026 8.8
CVE-2026-19902 Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header) 01.10.2026 6.1
CVE-2026-75957 Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter 01.10.2026 9.8
CVE-2026-89047 Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL 01.10.2026 6.1
CVE-2026-93882 LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter 01.10.2026 7.5
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects 01.10.2026
CVE-2026-103544 datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong session 01.10.2026
CVE-2026-101147 Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF 01.10.2026
CVE-2026-101148 BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key 01.10.2026
CVE-2026-103543 itsourcecode Leave Management System controller.php sql injection 01.10.2026
CVE-2026-19253 Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url 01.10.2026
CVE-2026-81739 Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback 01.10.2026
CVE-2026-81809 Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback 01.10.2026
CVE-2026-86610 Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon 01.10.2026
CVE-2026-87970 If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes 01.10.2026
CVE-2026-87973 If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name 01.10.2026
CVE-2026-89296 Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter 01.10.2026
CVE-2026-90972 WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion 01.10.2026
CVE-2026-90974 WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update 01.10.2026
CVE-2026-92412 Five Star Restaurant Reviews < 2.3.14 - Reflected XSS 01.10.2026
CVE-2026-96173 Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR 01.10.2026
CVE-2026-96200 Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback 01.10.2026
CVE-2026-96255 Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log 01.10.2026
CVE-2026-80275 Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint 01.10.2026 8.8
CVE-2026-80276 Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface 01.10.2026 7.5
CVE-2026-103542 formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery 01.10.2026
CVE-2026-103541 formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload 01.10.2026
CVE-2026-85679 Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key 01.10.2026 7.2
CVE-2026-88999 Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter 01.10.2026 4.3
CVE-2026-103540 formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engine 01.10.2026
CVE-2026-67075 HCL Digital Experience is affected by improper input sanitation 01.10.2026 6.5
CVE-2026-103539 ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication 01.10.2026
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted 01.10.2026
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed 01.10.2026
CVE-2026-82826 Authentication information or sensitive data may be intercepted in transit 01.10.2026
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens 01.10.2026
CVE-2026-82828 Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges 01.10.2026
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process 01.10.2026
CVE-2026-76142 Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface 01.10.2026
CVE-2026-76143 Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass 01.10.2026
CVE-2026-76144 Genians, Inc Genian SSL PNS Unrestricted File Upload 01.10.2026
CVE-2026-76145 Genians, Inc Genian SSL PNS Improper Privilege Management 01.10.2026
CVE-2026-76146 Genians, Inc Genian SSL PNS OS Command Injection 01.10.2026
CVE-2026-76147 Genians, Inc Genian NAC/ZTNA Remote Code Execution 01.10.2026
CVE-2026-103538 ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication 01.10.2026
CVE-2026-12241 Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting 01.10.2026 5.4
CVE-2026-78210 01.10.2026
CVE-2026-92548 WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters 01.10.2026 5.3
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field 01.10.2026 9.1
CVE-2026-103536 ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication 01.10.2026
CVE-2026-103641 Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder 01.10.2026
CVE-2026-103534 David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control 01.10.2026
CVE-2026-91109 Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter 01.10.2026 6.5
CVE-2026-92245 Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce 01.10.2026 7.5
CVE-2026-96561 AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection 01.10.2026 7.2
CVE-2026-103533 David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal 01.10.2026
CVE-2026-101887 BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS 01.10.2026
CVE-2026-92537 Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure) 01.10.2026 5.3
CVE-2026-13313 01.10.2026
CVE-2026-14157 01.10.2026
CVE-2026-93495 01.10.2026
CVE-2026-103532 immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization 01.10.2026
CVE-2026-103531 OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow 01.10.2026
CVE-2026-103530 decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery 01.10.2026
CVE-2026-103587 QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters 01.10.2026
CVE-2026-103588 QloApps through 1.7.0 Reflected XSS via exceptions field 30.09.2026
CVE-2026-103589 QloApps through 1.7.0 Reflected XSS via Room Type Editor 30.09.2026
CVE-2026-103590 QloApps through 1.7.0 Reflected XSS via Length of Stay Fields 01.10.2026
CVE-2026-103591 DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file 30.09.2026
CVE-2026-103592 simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers 30.09.2026
CVE-2026-103584 attacker-controlled javascript license URL via XSS 01.10.2026
CVE-2026-103585 attacker-controlled javascript license URL via XSS 01.10.2026
CVE-2026-47096 AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter 01.10.2026
CVE-2026-101283 01.10.2026