| CVE-2026-108549 |
cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing |
10.10.2026 |
9.2 |
| CVE-2026-108551 |
openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates |
10.10.2026 |
9.3 |
| CVE-2026-104803 |
WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback |
10.10.2026 |
9.8 |
| CVE-2026-62045 |
WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-62046 |
WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93927 |
WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93929 |
WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93930 |
WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93931 |
WordPress Smash theme <= 1.12.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93932 |
WordPress Smart Casa theme <= 1.0.12 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93933 |
WordPress Rosalinda theme <= 1.2.4 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93934 |
WordPress Partiso theme <= 1.1.13 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93935 |
WordPress Let's Play theme <= 1.1.15 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93936 |
WordPress IPharm theme <= 1.2.4 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93937 |
WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93938 |
WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93940 |
WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93941 |
WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93942 |
WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93943 |
WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93944 |
WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-93945 |
WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-104801 |
PPOM <= 34.0.10 - Unauthenticated Arbitrary File Deletion via 'ppom[fields][<data_name>][n][org]' Parameter |
10.10.2026 |
9.1 |
| CVE-2026-103889 |
3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'xpv_image' Parameter |
10.10.2026 |
9.8 |
| CVE-2026-97670 |
Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Field |
10.10.2026 |
9.1 |
| CVE-2026-104732 |
Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler |
10.10.2026 |
9.8 |
| CVE-2026-107645 |
Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter |
10.10.2026 |
9.1 |
| CVE-2026-94589 |
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.4.5 - Unauthenticated Arbitrary File Upload via Signature Field File Upload |
10.10.2026 |
9.8 |
| CVE-2026-108474 |
|
09.10.2026 |
9.8 |
| CVE-2026-108267 |
Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session |
09.10.2026 |
9.1 |
| CVE-2026-108268 |
enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session |
09.10.2026 |
9.1 |
| CVE-2026-108269 |
ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session |
09.10.2026 |
9.1 |
| CVE-2026-108266 |
Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session |
09.10.2026 |
9.1 |
| CVE-2026-108264 |
Wizarr: Authenticated Server-Side Template Injection (SSTI) in wizard step rendering leads to Remote Code Execution (RCE) |
09.10.2026 |
9.1 |
| CVE-2026-108265 |
enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session |
09.10.2026 |
9.1 |
| CVE-2026-108261 |
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment |
09.10.2026 |
9.3 |
| CVE-2026-108263 |
Astron Agent: Unsandboxed code-node leads to cross-tenant RCE |
09.10.2026 |
9.9 |
| CVE-2026-107845 |
Contao: Cross-site scripting in the comments bundle |
09.10.2026 |
9.3 |
| CVE-2026-107824 |
x64dbg-MCP Server exposes debugger operations to unauthenticated network clients |
09.10.2026 |
9.3 |
| CVE-2026-108157 |
Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking |
09.10.2026 |
9.2 |
| CVE-2026-107806 |
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite |
09.10.2026 |
9.4 |
| CVE-2026-15340 |
Savannah lwIP SMTP client Classic Buffer Overflow |
09.10.2026 |
9.3 |
| CVE-2026-108107 |
PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php |
09.10.2026 |
9.3 |
| CVE-2026-108109 |
PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code |
09.10.2026 |
9.3 |
| CVE-2026-28745 |
Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format |
09.10.2026 |
9.3 |
| CVE-2026-33367 |
Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function |
09.10.2026 |
9.3 |
| CVE-2026-39460 |
Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials |
09.10.2026 |
9.3 |
| CVE-2026-105278 |
Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials |
09.10.2026 |
9.3 |
| CVE-2026-32645 |
Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials |
09.10.2026 |
9.2 |
| CVE-2026-100730 |
Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data |
09.10.2026 |
9.3 |
| CVE-2026-86405 |
Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop |
09.10.2026 |
9.8 |
| CVE-2026-85531 |
Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x |
09.10.2026 |
9.8 |
| CVE-2026-93947 |
WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability |
09.10.2026 |
9.3 |
| CVE-2026-94503 |
WordPress Zombify plugin <= 1.7.7 - Arbitrary File Upload vulnerability |
09.10.2026 |
10 |
| CVE-2026-96327 |
WordPress WPLMS plugin < 1.9.9.8.2 - SQL Injection vulnerability |
09.10.2026 |
9.3 |
| CVE-2026-96328 |
WordPress JNews - Pay Writer plugin <= 12.0.1 - SQL Injection vulnerability |
09.10.2026 |
9.3 |
| CVE-2026-96330 |
WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability |
09.10.2026 |
9.3 |
| CVE-2026-96331 |
WordPress Ajax Search Pro plugin <= 4.29.1 - SQL Injection vulnerability |
09.10.2026 |
9.3 |
| CVE-2026-96809 |
WordPress EduAdmin Booking plugin < 6.0.0 - SQL Injection vulnerability |
09.10.2026 |
9.3 |
| CVE-2026-107935 |
Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose |
09.10.2026 |
9.3 |
| CVE-2026-107908 |
Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message |
09.10.2026 |
9.3 |
| CVE-2026-107910 |
Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling |
09.10.2026 |
9.2 |
| CVE-2026-5759 |
Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB |
09.10.2026 |
9.3 |
| CVE-2026-7827 |
Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB |
09.10.2026 |
9.2 |
| CVE-2026-69435 |
Azure SRE Agent Elevation of Privilege Vulnerability |
10.10.2026 |
9.6 |
| CVE-2026-77900 |
Azure App Service Remote Code Execution Vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-88131 |
Microsoft Dataverse Remote Code Execution Vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-94510 |
Microsoft Bookings Elevation of Privilege Vulnerability |
10.10.2026 |
9.9 |
| CVE-2026-96207 |
Microsoft Partner Center Elevation of Privilege Vulnerability |
10.10.2026 |
10 |
| CVE-2026-107726 |
Hazelcast: Arbitrary member memory access by low-privileged client |
09.10.2026 |
9.3 |
| CVE-2026-107722 |
fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion |
08.10.2026 |
9.8 |
| CVE-2026-75875 |
Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection |
10.10.2026 |
9.8 |
| CVE-2026-80381 |
Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection |
10.10.2026 |
9.8 |
| CVE-2026-84249 |
IBM Guardium Data Protection is affected by vulnerability |
10.10.2026 |
9.8 |
| CVE-2026-107406 |
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service |
10.10.2026 |
9.5 |
| CVE-2026-16823 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
10.10.2026 |
9.1 |
| CVE-2026-16916 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
10.10.2026 |
9.1 |
| CVE-2026-19491 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
10.10.2026 |
9.1 |
| CVE-2026-78401 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
10.10.2026 |
9.8 |
| CVE-2026-78406 |
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access |
10.10.2026 |
9.8 |
| CVE-2026-79842 |
|
10.10.2026 |
9.1 |
| CVE-2026-107779 |
Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE |
08.10.2026 |
9.3 |
| CVE-2026-107780 |
Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter |
08.10.2026 |
9.3 |
| CVE-2026-107781 |
Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById |
09.10.2026 |
9.1 |
| CVE-2026-106126 |
Command Injection |
08.10.2026 |
9.4 |
| CVE-2026-104075 |
TVU Networks Receiver/Transceiver Authentication Bypass via /tvu/Login |
08.10.2026 |
9.3 |
| CVE-2026-104076 |
TVU Networks Receiver/Transceiver Missing Authentication via REST API |
09.10.2026 |
9.3 |
| CVE-2026-84244 |
IBM Guardium Data Protection Cross-Site Scripting |
08.10.2026 |
9.3 |
| CVE-2026-84272 |
IBM Guardium Data Protection Missing Authentication |
10.10.2026 |
9.8 |
| CVE-2026-107699 |
ppt2png through 0.0.6 OS Command Injection via input and output paths |
08.10.2026 |
9.3 |
| CVE-2026-107700 |
dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument |
09.10.2026 |
9.3 |
| CVE-2026-107703 |
@enmaso/node-convert through 1.0.0 OS Command Injection via filepath and convertTo |
08.10.2026 |
9.3 |
| CVE-2026-107704 |
image_optimizer 1.3.0 through 1.9.0 OS Command Injection via identify_format |
09.10.2026 |
9.3 |
| CVE-2026-9209 |
mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx |
08.10.2026 |
9.3 |
| CVE-2026-14269 |
IBM DataPower Gateway Buffer Overflow |
09.10.2026 |
9.8 |
| CVE-2026-107640 |
Integrics Enswitch 3.13 through 4.4 Authentication Bypass via Password Reset API |
08.10.2026 |
9.3 |
| CVE-2026-14502 |
IBM DataPower Gateway Improper Authentication |
09.10.2026 |
9.8 |
| CVE-2026-14992 |
IBM DataPower Gateway Out-of-bounds Write |
09.10.2026 |
9.8 |
| CVE-2026-14990 |
IBM DataPower Gateway affected by cross-site scripting |
08.10.2026 |
9.3 |
| CVE-2026-14991 |
IBM DataPower Gateway Out-of-bounds Write |
10.10.2026 |
9.8 |
| CVE-2026-103663 |
Path Traversal leading to Remote Code Execution in Ollama |
08.10.2026 |
9.4 |
| CVE-2026-15762 |
IBM DataPower Gateway Out-of-bounds Write |
09.10.2026 |
9.8 |
| CVE-2026-16340 |
IBM DataPower Gateway Out-of-bounds Write |
09.10.2026 |
9.8 |
| CVE-2026-19218 |
Password Reset Code Brute Force Leading to Account Takeover in AKIN Software's MyRezzta |
08.10.2026 |
9.1 |
| CVE-2026-92555 |
Database Credentials Disclosure in AKIN Software's AKINSOFT WOLVOX Control Panel |
08.10.2026 |
9.8 |
| CVE-2026-107510 |
Authenticated argument injection in NIOS command line leading to privilege escalation |
09.10.2026 |
9.1 |
| CVE-2026-105110 |
Iskratel Innbox Unauthenticated Remote Code Execution via login.xgi CLI Parameter |
08.10.2026 |
9.3 |
| CVE-2026-12260 |
SQL injection in the NetBoard CRM demo platform |
08.10.2026 |
10 |
| CVE-2026-85097 |
Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter |
08.10.2026 |
9.8 |
| CVE-2026-107459 |
Openfind|SecuShare Pro - OS Command Injection |
08.10.2026 |
9.3 |
| CVE-2026-17609 |
Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter |
10.10.2026 |
9.1 |
| CVE-2026-107282 |
AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host |
10.10.2026 |
9.4 |
| CVE-2026-76268 |
Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise |
09.10.2026 |
9.8 |
| CVE-2026-95605 |
WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability |
07.10.2026 |
9.3 |
| CVE-2026-95606 |
WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability |
07.10.2026 |
9.8 |
| CVE-2026-20328 |
Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability |
08.10.2026 |
9.1 |
| CVE-2026-62176 |
PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation |
07.10.2026 |
9.1 |
| CVE-2026-62252 |
Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login |
07.10.2026 |
9.8 |
| CVE-2026-62253 |
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default) |
10.10.2026 |
9.8 |
| CVE-2026-76454 |
Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability |
07.10.2026 |
9.1 |
| CVE-2026-76455 |
Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities |
08.10.2026 |
9.8 |
| CVE-2026-76459 |
Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Write Vulnerabilities |
09.10.2026 |
9.8 |
| CVE-2026-76464 |
Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities |
07.10.2026 |
9.6 |
| CVE-2026-76465 |
Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability |
08.10.2026 |
9.8 |
| CVE-2026-76471 |
Cisco NX-OS Software NX-API Remote Code Execution Vulnerability |
08.10.2026 |
9.8 |
| CVE-2026-76480 |
Cisco License On-Prem Security Hardening Release |
08.10.2026 |
9.8 |
| CVE-2026-76482 |
Cisco License On-Prem Security Hardening Release |
08.10.2026 |
10 |
| CVE-2026-76483 |
Cisco License On-Prem Security Hardening Release |
08.10.2026 |
9.1 |
| CVE-2026-76485 |
Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability |
08.10.2026 |
9.8 |
| CVE-2026-76486 |
Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability |
08.10.2026 |
9.8 |
| CVE-2026-76498 |
Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Access Control Vulnerabilities |
07.10.2026 |
9.8 |
| CVE-2026-76499 |
Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization Vulnerabilities |
07.10.2026 |
9.8 |
| CVE-2026-76500 |
Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime Vulnerabilities |
08.10.2026 |
9.8 |
| CVE-2026-76501 |
Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability |
08.10.2026 |
9.8 |
| CVE-2026-92414 |
Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens |
07.10.2026 |
9.3 |
| CVE-2026-107204 |
LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint |
07.10.2026 |
9.3 |
| CVE-2026-107194 |
|
10.10.2026 |
9.2 |
| CVE-2026-107183 |
llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser |
07.10.2026 |
9.2 |
| CVE-2026-96408 |
|
07.10.2026 |
9.3 |
| CVE-2026-105192 |
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization |
07.10.2026 |
9.8 |
| CVE-2026-103416 |
|
07.10.2026 |
9.3 |
| CVE-2025-64393 |
|
08.10.2026 |
9.4 |
| CVE-2026-102782 |
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 |
08.10.2026 |
9.3 |
| CVE-2026-107102 |
Account Takeover Vulnerability in Manacle Technologies ERP System |
07.10.2026 |
9.3 |
| CVE-2026-107103 |
SQL Injection Vulnerability in Manacle Technologies ERP System |
07.10.2026 |
9.3 |
| CVE-2026-107104 |
Unsafe Deserialization Vulnerability in Manacle Technologies ERP System |
07.10.2026 |
9.3 |
| CVE-2026-59346 |
VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability |
07.10.2026 |
9.3 |
| CVE-2026-19572 |
FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability |
07.10.2026 |
9.3 |
| CVE-2026-14911 |
|
07.10.2026 |
9.3 |
| CVE-2026-16516 |
wolfSSH ECDSA host key curve not validated against negotiated algorithm |
07.10.2026 |
9 |
| CVE-2026-19386 |
|
08.10.2026 |
9.3 |
| CVE-2026-105324 |
An HTTP header injection vulnerability was found in the ADM |
07.10.2026 |
9.2 |
| CVE-2026-104334 |
Langflow OSS is affected by multiple vulnerabilities |
08.10.2026 |
9.8 |
| CVE-2026-93674 |
Langflow OSS is affected by multiple vulnerabilities |
08.10.2026 |
9.8 |
| CVE-2026-106501 |
Backstage: Sensitive information exposure in Scaffolder |
07.10.2026 |
9.6 |
| CVE-2026-101157 |
Security Advisory 0192 |
06.10.2026 |
9.3 |
| CVE-2026-102159 |
Security Advisory 0190 |
06.10.2026 |
9.3 |
| CVE-2026-102162 |
Security Advisory 0193 |
06.10.2026 |
9.4 |
| CVE-2026-102167 |
Security Advisory 0197 |
06.10.2026 |
9 |
| CVE-2026-106445 |
Handlebars: JavaScript Injection via Own Property Check Bypass |
09.10.2026 |
9.2 |
| CVE-2026-106446 |
Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams) |
07.10.2026 |
9.8 |
| CVE-2026-101158 |
Security Advisory 0185 |
06.10.2026 |
9.3 |
| CVE-2026-76750 |
Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager |
08.10.2026 |
9.8 |
| CVE-2026-76751 |
Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution |
08.10.2026 |
9.8 |
| CVE-2026-76752 |
Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access |
08.10.2026 |
9.8 |
| CVE-2026-76753 |
Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager |
08.10.2026 |
9.8 |
| CVE-2026-76754 |
Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager |
08.10.2026 |
9.8 |
| CVE-2026-79794 |
Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface |
08.10.2026 |
9.1 |
| CVE-2026-79796 |
Authentication Bypass Vulnerabilities in ClearPass Policy Manager |
08.10.2026 |
9.8 |
| CVE-2026-79798 |
Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface |
08.10.2026 |
9.9 |
| CVE-2026-79801 |
Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent |
08.10.2026 |
9.8 |
| CVE-2026-79805 |
Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager |
08.10.2026 |
9.8 |
| CVE-2026-76742 |
Authentication Bypass in the Web Management Interface of AOS-S |
08.10.2026 |
9.8 |
| CVE-2026-76743 |
Authentication Bypass Vulnerability in the Management Interface of AOS-S |
08.10.2026 |
9.8 |
| CVE-2026-76744 |
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S |
08.10.2026 |
9.8 |
| CVE-2026-76745 |
Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S |
08.10.2026 |
9.6 |
| CVE-2026-76746 |
Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S |
07.10.2026 |
9.3 |
| CVE-2026-76747 |
Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S |
07.10.2026 |
9.1 |
| CVE-2026-86360 |
|
06.10.2026 |
9.6 |
| CVE-2026-106102 |
Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() |
06.10.2026 |
10 |
| CVE-2026-105863 |
Payload authentication token field handling issue |
09.10.2026 |
9.2 |
| CVE-2026-105857 |
Payload: RCE in Payload Form Builder |
06.10.2026 |
10 |
| CVE-2026-105859 |
Payload: Unauthorized update to collection documents |
06.10.2026 |
9.8 |
| CVE-2026-104070 |
SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE |
09.10.2026 |
9.3 |
| CVE-2026-105851 |
Payload: Field access control bypass on auth collections |
06.10.2026 |
9.3 |
| CVE-2026-105844 |
Payload: Prototype pollution in Payload Import Export plugin |
09.10.2026 |
9.3 |
| CVE-2026-105845 |
Payload: SQL Injection in SQLite and Postgres |
06.10.2026 |
9.8 |
| CVE-2026-67273 |
|
08.10.2026 |
9.6 |
| CVE-2026-54472 |
|
06.10.2026 |
9.8 |
| CVE-2026-61421 |
|
06.10.2026 |
9.8 |
| CVE-2026-67269 |
|
08.10.2026 |
9.9 |
| CVE-2026-63688 |
|
06.10.2026 |
10 |
| CVE-2026-63692 |
|
09.10.2026 |
10 |
| CVE-2026-105793 |
Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` |
06.10.2026 |
9.1 |
| CVE-2026-105794 |
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL |
06.10.2026 |
9.1 |
| CVE-2026-106037 |
Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service |
06.10.2026 |
9.3 |
| CVE-2026-91140 |
OS command injection in Progress Software Autonomous REST Connector GenAI Agents |
07.10.2026 |
9.6 |
| CVE-2026-105835 |
PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint |
09.10.2026 |
9.1 |
| CVE-2026-82531 |
Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache |
06.10.2026 |
9.2 |
| CVE-2026-32557 |
WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-32568 |
WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-32579 |
WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability |
06.10.2026 |
10 |
| CVE-2026-39746 |
WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39753 |
WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability |
06.10.2026 |
9.8 |
| CVE-2026-39755 |
WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-39757 |
WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-39759 |
WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability |
06.10.2026 |
9.9 |
| CVE-2026-39761 |
WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability |
06.10.2026 |
9.8 |
| CVE-2026-39764 |
WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39770 |
WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability |
06.10.2026 |
10 |
| CVE-2026-39773 |
WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability |
06.10.2026 |
10 |
| CVE-2026-39785 |
WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39795 |
WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-39797 |
WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability |
06.10.2026 |
9.8 |
| CVE-2026-41555 |
WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-42415 |
WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-42417 |
WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-98323 |
RDMA/siw: Bound fragmented header copies by the remaining length |
07.10.2026 |
9.8 |
| CVE-2026-98365 |
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access |
07.10.2026 |
9.8 |
| CVE-2026-85153 |
Information Disclosure Vulnerability in Schmooze dating mobile Application |
06.10.2026 |
9.3 |
| CVE-2026-105778 |
Tenda AC5 Wifi setWifi stack-based overflow |
06.10.2026 |
9.4 |
| CVE-2026-94293 |
Missing authentication for critical function in the aas-edge-client REST API |
06.10.2026 |
9.3 |
| CVE-2026-105484 |
TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection |
06.10.2026 |
10 |
| CVE-2026-105763 |
Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL |
08.10.2026 |
9.6 |
| CVE-2026-21589 |
|
07.10.2026 |
9.3 |
| CVE-2026-91107 |
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) |
06.10.2026 |
9.3 |
| CVE-2026-105697 |
Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration |
09.10.2026 |
9.9 |
| CVE-2026-105740 |
Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server |
06.10.2026 |
9.9 |
| CVE-2026-77226 |
Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint |
07.10.2026 |
9.2 |
| CVE-2026-105691 |
Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color |
06.10.2026 |
9.9 |
| CVE-2026-103352 |
WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability |
05.10.2026 |
9.3 |
| CVE-2026-105636 |
Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) |
07.10.2026 |
9.9 |
| CVE-2026-105637 |
Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) |
05.10.2026 |
9.6 |
| CVE-2026-105638 |
Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force |
05.10.2026 |
9.1 |
| CVE-2026-105639 |
Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane |
06.10.2026 |
9.8 |
| CVE-2026-105640 |
Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) |
05.10.2026 |
9.1 |
| CVE-2026-105641 |
Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass |
07.10.2026 |
9.8 |
| CVE-2026-97283 |
WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability |
05.10.2026 |
9.8 |
| CVE-2026-102428 |
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 |
05.10.2026 |
9.3 |
| CVE-2026-79820 |
|
05.10.2026 |
9 |
| CVE-2026-105285 |
Totolink A3002MU QoS Rule formIpQoS stack-based overflow |
05.10.2026 |
10 |
| CVE-2026-105284 |
Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization |
05.10.2026 |
10 |
| CVE-2026-100102 |
RCE via exposed JDWP debug agent in P4Search |
05.10.2026 |
9.5 |
| CVE-2026-100103 |
Authentication bypass via default auth token in P4Search |
05.10.2026 |
10 |
| CVE-2026-103510 |
Authentication bypass via blank auth token in P4Search |
05.10.2026 |
9.5 |
| CVE-2026-105223 |
maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification |
05.10.2026 |
9.1 |
| CVE-2026-105293 |
Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers |
05.10.2026 |
9.2 |
| CVE-2026-105294 |
Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig |
05.10.2026 |
9.1 |
| CVE-2026-105221 |
Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification |
05.10.2026 |
9.1 |
| CVE-2026-105222 |
alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer |
05.10.2026 |
9.1 |
| CVE-2026-105216 |
go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper |
05.10.2026 |
9.1 |
| CVE-2026-105218 |
gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client |
05.10.2026 |
9.1 |
| CVE-2026-105086 |
WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title |
05.10.2026 |
9.3 |
| CVE-2026-105089 |
WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates |
06.10.2026 |
9.3 |
| CVE-2026-105207 |
ZITADEL before 4.17.3 Account Takeover via External IdP Linking |
06.10.2026 |
9.3 |
| CVE-2026-105209 |
ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment |
05.10.2026 |
9.3 |
| CVE-2026-105211 |
ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode |
05.10.2026 |
9.2 |
| CVE-2026-105215 |
ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback |
05.10.2026 |
9.3 |
| CVE-2026-103355 |
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability |
06.10.2026 |
9.3 |
| CVE-2026-105134 |
Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection |
05.10.2026 |
10 |
| CVE-2026-105135 |
InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection |
06.10.2026 |
10 |