| CVE-2026-42356 |
Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories |
01.10.2026 |
|
| CVE-2026-42528 |
Apache HTTP Server: mod_dav shared lock overflow |
01.10.2026 |
|
| CVE-2026-46729 |
Apache HTTP Server: mod_heartmonitor denial of service |
01.10.2026 |
|
| CVE-2026-94620 |
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) |
01.10.2026 |
|
| CVE-2026-103505 |
AWS EFS CSI Driver Mount Option Injection via mounttargetipmap |
01.10.2026 |
6.5 |
| CVE-2026-12627 |
Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability |
01.10.2026 |
9.8 |
| CVE-2026-18734 |
|
01.10.2026 |
|
| CVE-2026-17053 |
SMBus callback-removal syscalls accept an unvalidated user pointer, letting user threads manipulate kernel callback state |
01.10.2026 |
4.4 |
| CVE-2026-79896 |
Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability |
01.10.2026 |
7.5 |
| CVE-2026-56599 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
01.10.2026 |
2.2 |
| CVE-2026-67104 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
01.10.2026 |
5.3 |
| CVE-2026-67105 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
01.10.2026 |
7.4 |
| CVE-2026-67106 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
01.10.2026 |
5.3 |
| CVE-2026-79898 |
Fortra BoKS Manager crlserver command injection vulnerability |
01.10.2026 |
9.1 |
| CVE-2026-103004 |
next.js cache leak on warm `use cache` handlers accessing root param |
01.10.2026 |
|
| CVE-2026-56589 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
01.10.2026 |
7.2 |
| CVE-2026-97280 |
WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-79899 |
Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability |
01.10.2026 |
7.9 |
| CVE-2024-58388 |
Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html |
01.10.2026 |
|
| CVE-2026-100514 |
WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability |
01.10.2026 |
7.5 |
| CVE-2026-100517 |
WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object References (IDOR) vulnerability |
01.10.2026 |
7.5 |
| CVE-2026-102378 |
WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
7.1 |
| CVE-2026-103068 |
WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability |
01.10.2026 |
8.8 |
| CVE-2026-103347 |
WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-103687 |
rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist |
01.10.2026 |
|
| CVE-2026-103752 |
WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability |
01.10.2026 |
9.8 |
| CVE-2026-62071 |
WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability |
01.10.2026 |
9.3 |
| CVE-2026-62073 |
WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability |
01.10.2026 |
7.5 |
| CVE-2026-94390 |
WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object Injection vulnerability |
01.10.2026 |
7.2 |
| CVE-2026-95588 |
WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deletion vulnerability |
01.10.2026 |
8.6 |
| CVE-2026-97251 |
WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure Direct Object References (IDOR) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-97258 |
WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-97260 |
WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
7.1 |
| CVE-2026-97268 |
WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
7.1 |
| CVE-2026-97269 |
WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-97273 |
WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
7.1 |
| CVE-2026-97277 |
WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability |
01.10.2026 |
7.6 |
| CVE-2026-97281 |
WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability |
01.10.2026 |
6.3 |
| CVE-2026-97284 |
WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability |
01.10.2026 |
8.8 |
| CVE-2026-97297 |
WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability |
01.10.2026 |
7.6 |
| CVE-2026-79900 |
Heap overflow in KSL checksum initialization |
01.10.2026 |
6.5 |
| CVE-2026-95137 |
|
01.10.2026 |
|
| CVE-2026-79901 |
Predictable Active Directory service-account passwords in BoKS Manager |
01.10.2026 |
9.9 |
| CVE-2026-103686 |
rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting |
01.10.2026 |
|
| CVE-2026-66249 |
HCL iControl is affected by a Missing Secure Attribute vulnerability |
01.10.2026 |
3.1 |
| CVE-2026-66253 |
HCL iControl is affected by a Session Timeout vulnerability |
01.10.2026 |
3.1 |
| CVE-2026-102504 |
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol |
01.10.2026 |
|
| CVE-2026-102505 |
Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp |
01.10.2026 |
|
| CVE-2026-66246 |
HCL iControl is affected by multiple security vulnerabilities |
01.10.2026 |
8.8 |
| CVE-2026-66247 |
|
01.10.2026 |
4.3 |
| CVE-2026-66248 |
HCL iControl is affected by an Improper Error Handling vulnerability |
01.10.2026 |
3.1 |
| CVE-2026-102379 |
WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection vulnerability |
01.10.2026 |
8.5 |
| CVE-2026-102381 |
WordPress Majestic Support plugin <= 1.2.0 - Broken Access Control vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-102382 |
WordPress Majestic Support plugin <= 1.2.0 - Insecure Direct Object References (IDOR) vulnerability |
01.10.2026 |
4.3 |
| CVE-2026-102390 |
WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-102394 |
WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-103063 |
WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-103064 |
WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-103338 |
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability |
01.10.2026 |
8.5 |
| CVE-2026-103339 |
WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-103340 |
WordPress Site Reviews plugin <= 8.3.2 - Broken Access Control vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-103341 |
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Broken Access Control vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-103343 |
WordPress FluentForm plugin <= 6.2.14 - Cross Site Scripting (XSS) vulnerability |
01.10.2026 |
6.5 |
| CVE-2026-103345 |
WordPress Pie Register plugin <= 3.8.4.13 - Sensitive Data Exposure vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-62058 |
WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-62059 |
WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability |
01.10.2026 |
7.6 |
| CVE-2026-62060 |
WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability |
01.10.2026 |
7.6 |
| CVE-2026-62061 |
WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (IDOR) vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-62063 |
WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability |
01.10.2026 |
5.4 |
| CVE-2026-103067 |
WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability |
01.10.2026 |
8 |
| CVE-2026-103754 |
Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory |
01.10.2026 |
|
| CVE-2026-103336 |
WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-103678 |
Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value |
01.10.2026 |
|
| CVE-2026-103679 |
Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction |
01.10.2026 |
|
| CVE-2026-103680 |
Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation |
01.10.2026 |
|
| CVE-2026-103858 |
MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions |
01.10.2026 |
|
| CVE-2026-94212 |
Apache APISIX: unauthenticated impersonation issue in saml-auth |
01.10.2026 |
|
| CVE-2026-94220 |
Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin |
01.10.2026 |
|
| CVE-2026-94250 |
Apache APISIX: Batch response aggregation can exhaust worker memory |
01.10.2026 |
|
| CVE-2026-94269 |
Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch |
01.10.2026 |
|
| CVE-2026-94276 |
Apache APISIX: Openid-connect introspection validation issue |
01.10.2026 |
|
| CVE-2026-78242 |
Apache APISIX: data-mask may fail to redact request headers in logger output |
01.10.2026 |
|
| CVE-2026-82806 |
Apache APISIX: cross-request permission pollution via static permission list mutation |
01.10.2026 |
|
| CVE-2026-103353 |
WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability |
01.10.2026 |
5.3 |
| CVE-2026-88789 |
Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening |
01.10.2026 |
8.6 |
| CVE-2026-103082 |
WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability |
01.10.2026 |
7.2 |
| CVE-2026-103244 |
ground-station before 0.8.0 Authentication Bypass via setup.restore |
01.10.2026 |
|
| CVE-2026-103245 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification |
01.10.2026 |
|
| CVE-2026-103246 |
n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspection |
01.10.2026 |
|
| CVE-2026-103247 |
n8n before 1.123.80 Credential Tampering via Duplicate Node IDs |
01.10.2026 |
|
| CVE-2026-103248 |
n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase |
01.10.2026 |
|
| CVE-2026-103249 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator |
01.10.2026 |
|
| CVE-2026-103250 |
n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory |
01.10.2026 |
|
| CVE-2026-103251 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub |
01.10.2026 |
|
| CVE-2026-103252 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoint |
01.10.2026 |
|
| CVE-2026-103253 |
n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table |
01.10.2026 |
|
| CVE-2026-103254 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation |
01.10.2026 |
|
| CVE-2026-103255 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase |
01.10.2026 |
|
| CVE-2026-103256 |
n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook |
01.10.2026 |
|
| CVE-2026-103257 |
n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node |
01.10.2026 |
|
| CVE-2026-103258 |
n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation |
01.10.2026 |
|
| CVE-2026-103259 |
n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials |
01.10.2026 |
|
| CVE-2026-103260 |
n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node |
01.10.2026 |
|
| CVE-2026-103261 |
Tornado before 6.5.9 Denial of Service via Query String |
01.10.2026 |
|
| CVE-2026-103262 |
Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient |
01.10.2026 |
|
| CVE-2026-103263 |
Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink |
01.10.2026 |
|
| CVE-2026-103264 |
Fleet before 4.87.0 Authentication Bypass via Device Identifiers |
01.10.2026 |
|
| CVE-2026-103265 |
Fleet before 4.89.0 Information Disclosure via MDM Command Results |
01.10.2026 |
|
| CVE-2026-103266 |
Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification |
01.10.2026 |
|
| CVE-2026-103267 |
Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite |
01.10.2026 |
|
| CVE-2026-103268 |
Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset |
01.10.2026 |
|
| CVE-2026-103269 |
Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts |
01.10.2026 |
|
| CVE-2026-103271 |
Ghost 4.0.0 before 6.63.0 Restricted Content Bypass |
01.10.2026 |
|
| CVE-2026-103272 |
Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API |
01.10.2026 |
|
| CVE-2026-103273 |
Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token |
01.10.2026 |
|
| CVE-2026-103274 |
Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read |
01.10.2026 |
|
| CVE-2026-103275 |
Ghost 5.42.2 before 6.58.0 Password Hash Disclosure |
01.10.2026 |
|
| CVE-2026-103276 |
Ghost before 6.20.0 File Read via URL Encoding Bypass |
01.10.2026 |
|
| CVE-2026-103277 |
Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed |
01.10.2026 |
|
| CVE-2026-103278 |
Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe |
01.10.2026 |
|
| CVE-2026-103279 |
Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass |
01.10.2026 |
|
| CVE-2026-103280 |
Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint |
01.10.2026 |
|
| CVE-2026-103281 |
Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API |
01.10.2026 |
|
| CVE-2026-103282 |
Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token |
01.10.2026 |
|
| CVE-2026-103283 |
Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling |
01.10.2026 |
|
| CVE-2026-103284 |
Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback |
01.10.2026 |
|
| CVE-2026-103285 |
Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery |
01.10.2026 |
|
| CVE-2026-103286 |
Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications |
01.10.2026 |
|
| CVE-2026-103287 |
Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook |
01.10.2026 |
|
| CVE-2026-103288 |
Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like |
01.10.2026 |
|
| CVE-2026-103289 |
Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments |
01.10.2026 |
|
| CVE-2026-103290 |
Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize |
01.10.2026 |
|
| CVE-2026-103291 |
Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch |
01.10.2026 |
|
| CVE-2026-103292 |
Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head |
01.10.2026 |
|
| CVE-2026-103757 |
Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation |
01.10.2026 |
|
| CVE-2026-103758 |
Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route |
01.10.2026 |
|
| CVE-2026-7173 |
Multiple vulnerabilities in Entradium by Crocantickets |
01.10.2026 |
|
| CVE-2026-7174 |
Multiple vulnerabilities in Entradium by Crocantickets |
01.10.2026 |
|
| CVE-2026-7175 |
Multiple vulnerabilities in Entradium by Crocantickets |
01.10.2026 |
|
| CVE-2026-7176 |
Multiple vulnerabilities in Entradium by Crocantickets |
01.10.2026 |
|
| CVE-2026-34189 |
CSRF in Event Response Deletion |
01.10.2026 |
|
| CVE-2026-34190 |
CSRF in Alert Command Deletion |
01.10.2026 |
|
| CVE-2026-64946 |
CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager |
01.10.2026 |
|
| CVE-2026-64947 |
CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager |
01.10.2026 |
|
| CVE-2026-64948 |
Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure |
01.10.2026 |
|
| CVE-2026-64949 |
Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager |
01.10.2026 |
|
| CVE-2026-64950 |
Stored Cross-Site Scripting via Directory Name in File Manager Create Directory |
01.10.2026 |
|
| CVE-2026-75786 |
SQL Injection in Grafana Integration Endpoint (query.php) |
01.10.2026 |
|
| CVE-2026-92144 |
Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter |
01.10.2026 |
7.2 |
| CVE-2026-96256 |
Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute |
01.10.2026 |
6.4 |
| CVE-2026-103488 |
|
01.10.2026 |
7.1 |
| CVE-2026-103489 |
|
01.10.2026 |
2 |
| CVE-2026-103490 |
|
01.10.2026 |
7.2 |
| CVE-2026-103491 |
|
01.10.2026 |
6.5 |
| CVE-2026-103492 |
|
01.10.2026 |
6.5 |
| CVE-2026-103493 |
|
01.10.2026 |
8.1 |
| CVE-2026-103494 |
|
01.10.2026 |
6.6 |
| CVE-2026-103495 |
|
01.10.2026 |
4.3 |
| CVE-2026-103496 |
|
01.10.2026 |
5.4 |
| CVE-2026-103497 |
|
01.10.2026 |
5.5 |
| CVE-2026-83589 |
Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect |
01.10.2026 |
|
| CVE-2026-96577 |
Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled |
01.10.2026 |
|
| CVE-2026-103662 |
MISP Reflected XSS in Taxonomy Tag Confirmation Forms |
01.10.2026 |
|
| CVE-2026-103664 |
MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter |
01.10.2026 |
|
| CVE-2026-100179 |
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices() |
01.10.2026 |
6.1 |
| CVE-2026-100184 |
Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value |
01.10.2026 |
4.7 |
| CVE-2026-101925 |
bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name |
01.10.2026 |
6.4 |
| CVE-2026-103431 |
Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape sequences in data received from remote collectl instances |
01.10.2026 |
|
| CVE-2026-103656 |
|
01.10.2026 |
|
| CVE-2026-103659 |
MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes |
01.10.2026 |
|
| CVE-2026-14995 |
Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path |
01.10.2026 |
7.2 |
| CVE-2026-15983 |
Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter |
01.10.2026 |
8.1 |
| CVE-2026-85235 |
Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field |
01.10.2026 |
7.2 |
| CVE-2026-89424 |
Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter |
01.10.2026 |
6.4 |
| CVE-2026-89427 |
Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter |
01.10.2026 |
6.1 |
| CVE-2026-90992 |
Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field |
01.10.2026 |
6.4 |
| CVE-2026-92244 |
PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields |
01.10.2026 |
7.2 |
| CVE-2026-95687 |
WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint |
01.10.2026 |
8.8 |
| CVE-2026-96268 |
Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action |
01.10.2026 |
6.4 |
| CVE-2026-96573 |
Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer |
01.10.2026 |
7.2 |
| CVE-2026-96813 |
Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields |
01.10.2026 |
7.2 |
| CVE-2026-97661 |
Business Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field |
01.10.2026 |
7.2 |
| CVE-2026-103655 |
MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period |
01.10.2026 |
|
| CVE-2026-78249 |
|
01.10.2026 |
|
| CVE-2026-103651 |
MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass |
01.10.2026 |
|
| CVE-2026-15989 |
Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter |
01.10.2026 |
9.8 |
| CVE-2026-19807 |
ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool |
01.10.2026 |
8.8 |
| CVE-2026-19902 |
Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header) |
01.10.2026 |
6.1 |
| CVE-2026-75957 |
Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter |
01.10.2026 |
9.8 |
| CVE-2026-89047 |
Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL |
01.10.2026 |
6.1 |
| CVE-2026-93882 |
LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter |
01.10.2026 |
7.5 |
| CVE-2025-41753 |
Path traversal in dynamically created BACnet File Objects |
01.10.2026 |
|
| CVE-2026-103544 |
datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong session |
01.10.2026 |
|
| CVE-2026-101147 |
Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF |
01.10.2026 |
|
| CVE-2026-101148 |
BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key |
01.10.2026 |
|
| CVE-2026-103543 |
itsourcecode Leave Management System controller.php sql injection |
01.10.2026 |
|
| CVE-2026-19253 |
Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url |
01.10.2026 |
|
| CVE-2026-81739 |
Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback |
01.10.2026 |
|
| CVE-2026-81809 |
Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback |
01.10.2026 |
|
| CVE-2026-86610 |
Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon |
01.10.2026 |
|
| CVE-2026-87970 |
If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes |
01.10.2026 |
|
| CVE-2026-87973 |
If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name |
01.10.2026 |
|
| CVE-2026-89296 |
Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter |
01.10.2026 |
|
| CVE-2026-90972 |
WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion |
01.10.2026 |
|
| CVE-2026-90974 |
WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update |
01.10.2026 |
|
| CVE-2026-92412 |
Five Star Restaurant Reviews < 2.3.14 - Reflected XSS |
01.10.2026 |
|
| CVE-2026-96173 |
Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR |
01.10.2026 |
|
| CVE-2026-96200 |
Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback |
01.10.2026 |
|
| CVE-2026-96255 |
Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log |
01.10.2026 |
|
| CVE-2026-80275 |
Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint |
01.10.2026 |
8.8 |
| CVE-2026-80276 |
Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface |
01.10.2026 |
7.5 |
| CVE-2026-103542 |
formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery |
01.10.2026 |
|
| CVE-2026-103541 |
formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload |
01.10.2026 |
|
| CVE-2026-85679 |
Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.blocks' Block Type Key |
01.10.2026 |
7.2 |
| CVE-2026-88999 |
Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion via 'attachment_id' Parameter |
01.10.2026 |
4.3 |
| CVE-2026-103540 |
formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engine |
01.10.2026 |
|
| CVE-2026-67075 |
HCL Digital Experience is affected by improper input sanitation |
01.10.2026 |
6.5 |
| CVE-2026-103539 |
ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication |
01.10.2026 |
|
| CVE-2026-82824 |
Path traversal may allow arbitrary files to be viewed, created, modified, or deleted |
01.10.2026 |
|
| CVE-2026-82825 |
Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed |
01.10.2026 |
|
| CVE-2026-82826 |
Authentication information or sensitive data may be intercepted in transit |
01.10.2026 |
|
| CVE-2026-82827 |
A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens |
01.10.2026 |
|
| CVE-2026-82828 |
Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges |
01.10.2026 |
|
| CVE-2026-82829 |
Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process |
01.10.2026 |
|
| CVE-2026-76142 |
Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface |
01.10.2026 |
|
| CVE-2026-76143 |
Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass |
01.10.2026 |
|
| CVE-2026-76144 |
Genians, Inc Genian SSL PNS Unrestricted File Upload |
01.10.2026 |
|
| CVE-2026-76145 |
Genians, Inc Genian SSL PNS Improper Privilege Management |
01.10.2026 |
|
| CVE-2026-76146 |
Genians, Inc Genian SSL PNS OS Command Injection |
01.10.2026 |
|
| CVE-2026-76147 |
Genians, Inc Genian NAC/ZTNA Remote Code Execution |
01.10.2026 |
|
| CVE-2026-103538 |
ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication |
01.10.2026 |
|
| CVE-2026-12241 |
Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
01.10.2026 |
5.4 |
| CVE-2026-78210 |
|
01.10.2026 |
|
| CVE-2026-92548 |
WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters |
01.10.2026 |
5.3 |
| CVE-2026-92966 |
Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field |
01.10.2026 |
9.1 |
| CVE-2026-103536 |
ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication |
01.10.2026 |
|
| CVE-2026-103641 |
Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
01.10.2026 |
|
| CVE-2026-103534 |
David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control |
01.10.2026 |
|
| CVE-2026-91109 |
Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter |
01.10.2026 |
6.5 |
| CVE-2026-92245 |
Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce |
01.10.2026 |
7.5 |
| CVE-2026-96561 |
AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection |
01.10.2026 |
7.2 |
| CVE-2026-103533 |
David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal |
01.10.2026 |
|
| CVE-2026-101887 |
BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS |
01.10.2026 |
|
| CVE-2026-92537 |
Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure) |
01.10.2026 |
5.3 |
| CVE-2026-13313 |
|
01.10.2026 |
|
| CVE-2026-14157 |
|
01.10.2026 |
|
| CVE-2026-93495 |
|
01.10.2026 |
|
| CVE-2026-103532 |
immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization |
01.10.2026 |
|
| CVE-2026-103531 |
OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow |
01.10.2026 |
|
| CVE-2026-103530 |
decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery |
01.10.2026 |
|
| CVE-2026-103587 |
QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters |
01.10.2026 |
|
| CVE-2026-103588 |
QloApps through 1.7.0 Reflected XSS via exceptions field |
30.09.2026 |
|
| CVE-2026-103589 |
QloApps through 1.7.0 Reflected XSS via Room Type Editor |
30.09.2026 |
|
| CVE-2026-103590 |
QloApps through 1.7.0 Reflected XSS via Length of Stay Fields |
01.10.2026 |
|
| CVE-2026-103591 |
DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file |
30.09.2026 |
|
| CVE-2026-103592 |
simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers |
30.09.2026 |
|
| CVE-2026-103584 |
attacker-controlled javascript license URL via XSS |
01.10.2026 |
|
| CVE-2026-103585 |
attacker-controlled javascript license URL via XSS |
01.10.2026 |
|
| CVE-2026-47096 |
AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter |
01.10.2026 |
|
| CVE-2026-101283 |
|
01.10.2026 |
|