CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-92414 Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens 07.10.2026 9.3
CVE-2026-107204 LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint 07.10.2026 9.3
CVE-2026-107194 07.10.2026 9.2
CVE-2026-107183 llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser 07.10.2026 9.2
CVE-2026-96408 07.10.2026 9.3
CVE-2026-105192 LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization 07.10.2026 9.8
CVE-2026-103416 07.10.2026 9.3
CVE-2025-64393 07.10.2026 9.4
CVE-2026-102782 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 07.10.2026 9.3
CVE-2026-107102 Account Takeover Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107103 SQL Injection Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107104 Unsafe Deserialization Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-59346 VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability 07.10.2026 9.3
CVE-2026-19572 FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability 07.10.2026 9.3
CVE-2026-14911 07.10.2026 9.3
CVE-2026-16516 wolfSSH ECDSA host key curve not validated against negotiated algorithm 07.10.2026 9
CVE-2026-19386 07.10.2026 9.3
CVE-2026-105324 An HTTP header injection vulnerability was found in the ADM 07.10.2026 9.2
CVE-2026-104334 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 9.8
CVE-2026-93674 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 9.8
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder 06.10.2026 9.6
CVE-2026-101157 Security Advisory 0192 06.10.2026 9.3
CVE-2026-102159 Security Advisory 0190 06.10.2026 9.3
CVE-2026-102162 Security Advisory 0193 06.10.2026 9.4
CVE-2026-102167 Security Advisory 0197 06.10.2026 9
CVE-2026-106445 Handlebars: JavaScript Injection via Own Property Check Bypass 06.10.2026 9.2
CVE-2026-106446 Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams) 06.10.2026 9.8
CVE-2026-101158 Security Advisory 0185 06.10.2026 9.3
CVE-2026-76750 Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager 06.10.2026 9.8
CVE-2026-76751 Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution 06.10.2026 9.8
CVE-2026-76752 Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access 06.10.2026 9.8
CVE-2026-76753 Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager 06.10.2026 9.8
CVE-2026-76754 Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager 06.10.2026 9.8
CVE-2026-79794 Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface 06.10.2026 9.1
CVE-2026-79796 Authentication Bypass Vulnerabilities in ClearPass Policy Manager 07.10.2026 9.8
CVE-2026-79798 Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface 06.10.2026 9.9
CVE-2026-79801 Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent 06.10.2026 9.8
CVE-2026-79805 Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager 06.10.2026 9.8
CVE-2026-76742 Authentication Bypass in the Web Management Interface of AOS-S 07.10.2026 9.8
CVE-2026-76743 Authentication Bypass Vulnerability in the Management Interface of AOS-S 06.10.2026 9.8
CVE-2026-76744 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S 06.10.2026 9.8
CVE-2026-76745 Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S 06.10.2026 9.6
CVE-2026-76746 Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S 06.10.2026 9.3
CVE-2026-76747 Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S 06.10.2026 9.1
CVE-2026-86360 06.10.2026 9.6
CVE-2026-106102 Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() 06.10.2026 10
CVE-2026-105863 Payload authentication token field handling issue 06.10.2026 9.2
CVE-2026-105857 Payload: RCE in Payload Form Builder 06.10.2026 10
CVE-2026-105859 Payload: Unauthorized update to collection documents 06.10.2026 9.8
CVE-2026-104070 SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE 06.10.2026 9.3
CVE-2026-105851 Payload: Field access control bypass on auth collections 06.10.2026 9.3
CVE-2026-105844 Payload: Prototype pollution in Payload Import Export plugin 06.10.2026 9.3
CVE-2026-105845 Payload: SQL Injection in SQLite and Postgres 06.10.2026 9.8
CVE-2026-67273 06.10.2026 9.6
CVE-2026-54472 06.10.2026 9.8
CVE-2026-61421 06.10.2026 9.8
CVE-2026-67269 06.10.2026 9.9
CVE-2026-63688 06.10.2026 10
CVE-2026-63692 06.10.2026 10
CVE-2026-105793 Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` 06.10.2026 9.1
CVE-2026-105794 MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL 06.10.2026 9.1
CVE-2026-106037 Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service 06.10.2026 9.3
CVE-2026-91140 OS command injection in Progress Software Autonomous REST Connector GenAI Agents 07.10.2026 9.6
CVE-2026-105835 PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint 06.10.2026 9.1
CVE-2026-82531 Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache 06.10.2026 9.2
CVE-2026-32557 WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-32568 WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability 06.10.2026 9.9
CVE-2026-32579 WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39746 WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39753 WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39755 WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39757 WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39759 WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39761 WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39764 WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39770 WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39773 WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability 06.10.2026 10
CVE-2026-39785 WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39795 WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39797 WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability 06.10.2026 9.8
CVE-2026-41555 WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42415 WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42417 WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-98323 RDMA/siw: Bound fragmented header copies by the remaining length 07.10.2026 9.8
CVE-2026-98365 RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access 07.10.2026 9.8
CVE-2026-85153 Information Disclosure Vulnerability in Schmooze dating mobile Application 06.10.2026 9.3
CVE-2026-105778 Tenda AC5 Wifi setWifi stack-based overflow 06.10.2026 9.4
CVE-2026-94293 Missing authentication for critical function in the aas-edge-client REST API 06.10.2026 9.3
CVE-2026-105484 TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection 06.10.2026 10
CVE-2026-105763 Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL 05.10.2026 9.6
CVE-2026-21589 07.10.2026 9.3
CVE-2026-91107 openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) 06.10.2026 9.3
CVE-2026-105697 Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration 06.10.2026 9.9
CVE-2026-105740 Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server 06.10.2026 9.9
CVE-2026-77226 Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint 05.10.2026 9.2
CVE-2026-105691 Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color 06.10.2026 9.9
CVE-2026-103352 WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability 05.10.2026 9.3
CVE-2026-105636 Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 05.10.2026 9.9
CVE-2026-105637 Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) 05.10.2026 9.6
CVE-2026-105638 Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force 05.10.2026 9.1
CVE-2026-105639 Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane 06.10.2026 9.8
CVE-2026-105640 Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) 05.10.2026 9.1
CVE-2026-105641 Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass 05.10.2026 9.8
CVE-2026-97283 WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability 05.10.2026 9.8
CVE-2026-102428 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 05.10.2026 9.3
CVE-2026-79820 05.10.2026 9
CVE-2026-105285 Totolink A3002MU QoS Rule formIpQoS stack-based overflow 05.10.2026 10
CVE-2026-105284 Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization 05.10.2026 10
CVE-2026-100102 RCE via exposed JDWP debug agent in P4Search 05.10.2026 9.5
CVE-2026-100103 Authentication bypass via default auth token in P4Search 05.10.2026 10
CVE-2026-103510 Authentication bypass via blank auth token in P4Search 05.10.2026 9.5
CVE-2026-105223 maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105293 Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers 05.10.2026 9.2
CVE-2026-105294 Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig 05.10.2026 9.1
CVE-2026-105221 Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105222 alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer 05.10.2026 9.1
CVE-2026-105216 go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper 05.10.2026 9.1
CVE-2026-105218 gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client 05.10.2026 9.1
CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title 05.10.2026 9.3
CVE-2026-105089 WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates 06.10.2026 9.3
CVE-2026-105207 ZITADEL before 4.17.3 Account Takeover via External IdP Linking 06.10.2026 9.3
CVE-2026-105209 ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment 05.10.2026 9.3
CVE-2026-105211 ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode 05.10.2026 9.2
CVE-2026-105215 ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback 05.10.2026 9.3
CVE-2026-103355 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-105134 Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection 05.10.2026 10
CVE-2026-105135 InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection 06.10.2026 10
CVE-2026-105105 Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration 05.10.2026 9.8
CVE-2026-71885 MLS X.509 credential not bound to the LeafNode signature key 05.10.2026 9.2
CVE-2026-92084 Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output 03.10.2026 9.1
CVE-2026-87115 VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter 03.10.2026 9.1
CVE-2026-105080 06.10.2026 9.4
CVE-2026-84411 MikroTik RouterOS Integer Underflow 03.10.2026 9.3
CVE-2026-95102 Monta monta.app Missing Authentication for Critical Function 03.10.2026 9.3
CVE-2026-75937 OS Command Injection in Digi Accelerated Linux (DAL OS) 03.10.2026 9.4
CVE-2026-82042 UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter 05.10.2026 9.3
CVE-2026-104019 OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio 06.10.2026 9.3
CVE-2026-103956 Missing authentication for critical function in Loom for AWS 02.10.2026 10
CVE-2023-54405 H3C CVM Unauthenticated File Upload via fileUpload/upload Token 05.10.2026 9.3
CVE-2026-104848 Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution 02.10.2026 9.5
CVE-2026-104849 Tinypool: Prototype Pollution Gadget to RCE in run() options 06.10.2026 9.5
CVE-2026-103648 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader 03.10.2026 9.1
CVE-2026-104846 Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940) 05.10.2026 9.8
CVE-2026-90970 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 02.10.2026 9.9
CVE-2026-19652 Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter 03.10.2026 9.8
CVE-2026-83632 Apache Thrift: C++ THttpTransport grows its line buffer without bound 02.10.2026 9.2
CVE-2026-104610 Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow 02.10.2026 10
CVE-2026-104611 Tenda AC9 POST Request fast_setting_internet_set stack-based overflow 02.10.2026 9.4
CVE-2026-104467 YesWiki before 4.6.7 Authorization Bypass via Public API Mode 02.10.2026 9.2
CVE-2026-91135 Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) 02.10.2026 9.2
CVE-2026-86325 02.10.2026 9.4
CVE-2026-94541 WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter 02.10.2026 9.8
CVE-2026-97637 JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response 03.10.2026 9.8
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value 02.10.2026 9.1
CVE-2026-93029 02.10.2026 9
CVE-2026-93697 02.10.2026 9
CVE-2026-93698 02.10.2026 9.9
CVE-2026-15896 Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter 02.10.2026 9.1
CVE-2026-19660 Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter 03.10.2026 9.8
CVE-2026-14378 DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow 03.10.2026 9.8
CVE-2026-104480 Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership 02.10.2026 9.4
CVE-2026-86345 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result 02.10.2026 9
CVE-2026-103764 Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport 02.10.2026 9.3
CVE-2026-18397 SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability 02.10.2026 9.4
CVE-2026-71449 02.10.2026 9.3
CVE-2026-55393 Local File Inclusion in Teledyne FLIR Robots running Aware2 01.10.2026 10
CVE-2026-55395 Hardcoded Passwords in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-14984 Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-102628 Cadmos LTI exposure of sensitive information via debug mode 05.10.2026 9.2
CVE-2026-102667 Joyland AI WebView command injection 07.10.2026 9
CVE-2026-53953 GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover 05.10.2026 9.1
CVE-2026-56660 GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction 01.10.2026 9.1
CVE-2026-56662 GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request 06.10.2026 9.6
CVE-2026-104286 07.10.2026 9.8
CVE-2026-55083 DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) 01.10.2026 9.1
CVE-2026-103922 Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path 01.10.2026 9.3
CVE-2026-13043 WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access 01.10.2026 9.3
CVE-2026-96658 Foreman: safemode bypass leading to rce 07.10.2026 9.9
CVE-2026-96659 Foreman: excessive permissions for viewer role on preview 07.10.2026 9.1
CVE-2026-94620 Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 01.10.2026 9.4
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability 01.10.2026 9.8
CVE-2026-79898 Fortra BoKS Manager crlserver command injection vulnerability 01.10.2026 9.1
CVE-2026-103752 WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability 01.10.2026 9.8
CVE-2026-62071 WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability 01.10.2026 9.3
CVE-2026-79901 Predictable Active Directory service-account passwords in BoKS Manager 01.10.2026 9.9
CVE-2026-103244 ground-station before 0.8.0 Authentication Bypass via setup.restore 01.10.2026 9.3
CVE-2026-103264 Fleet before 4.87.0 Authentication Bypass via Device Identifiers 01.10.2026 9.3
CVE-2026-103655 MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period 01.10.2026 9.3
CVE-2026-15989 Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter 01.10.2026 9.8
CVE-2026-75957 Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter 01.10.2026 9.8
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects 01.10.2026 9.3
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted 01.10.2026 9.3
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed 01.10.2026 9.3
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens 01.10.2026 9.3
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process 01.10.2026 9.3
CVE-2026-76142 Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface 01.10.2026 9.3
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field 01.10.2026 9.1
CVE-2026-14157 02.10.2026 9.4
CVE-2026-101283 01.10.2026 9.2

Latest Updates

CVE Title Updated Score
CVE-2026-106579 ImageMagick: Policy Bypass when using coder as the domain. 07.10.2026 6.2
CVE-2026-106580 ImageMagick: Policy Bypass in CUT encoder 07.10.2026 4
CVE-2026-107208 ImageMagick: Denial of service with crafted XMP profile 07.10.2026 5.3
CVE-2026-107270 Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints 07.10.2026
CVE-2026-107271 Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing 07.10.2026
CVE-2026-107272 Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages 07.10.2026
CVE-2026-107273 Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site 07.10.2026
CVE-2026-107278 MISP Object Sync Drops Objects and Attributes When Description Is Empty 07.10.2026
CVE-2026-92414 Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens 07.10.2026
CVE-2026-92415 Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies 07.10.2026
CVE-2026-106566 ImageMagick: Policy Bypass in delegate symlink cleanup due to missing check 07.10.2026 4
CVE-2026-106567 ImageMagick: Infinite Loop in PSD decoder on 32-bit builds 07.10.2026 5.9
CVE-2026-106568 ImageMagick: Infinite Loop when reading a crafted XMP profile 07.10.2026 5.3
CVE-2026-106569 ImageMagick: Denial of service in ASE decoder because of missing security checks 07.10.2026 5.3
CVE-2026-106570 ImageMagick: Denial of service in distributed pixel cache server 07.10.2026 4.3
CVE-2026-106571 ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a crash 07.10.2026 5.1
CVE-2026-106572 ImageMagick: Stack Overflown CALS decoder due to missing depth check. 07.10.2026 5.3
CVE-2026-106573 ImageMagick: Denial of service in MVG decoder 07.10.2026 5.3
CVE-2026-106574 ImageMagick: Heap Buffer Over-Write in distributed pixel cache server will result in a crash 07.10.2026 5.3
CVE-2026-106575 ImageMagick: Unclosed file pointer in magick script 07.10.2026 5.3
CVE-2026-106576 ImageMagick: Denial of service possible when parsing an XMP profile. 07.10.2026 5.3
CVE-2026-106577 ImageMagick: Code Injection in the postscript coders 07.10.2026 5.3
CVE-2026-106578 ImageMagick: Invalid Memory Free in MVG decoder 07.10.2026 5.9
CVE-2026-107204 LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint 07.10.2026
CVE-2026-107205 LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API 07.10.2026
CVE-2026-107206 LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API 07.10.2026
CVE-2026-107207 LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows SSRF Allowlist Bypass 07.10.2026
CVE-2026-107269 Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy 07.10.2026
CVE-2026-107276 MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests 07.10.2026
CVE-2026-106564 ImageMagick: Heap Buffer Over-Write in EXR decoder 07.10.2026 5.3
CVE-2026-106565 ImageMagick: Infinite Loop in bzip2 compressed images. 07.10.2026 5.9
CVE-2026-33586 Authenticated SMTP Sender Address Forgery 07.10.2026
CVE-2025-70522 07.10.2026
CVE-2026-106560 Backstage: Improper repository path validation in a Scaffolder backend module 07.10.2026 7.1
CVE-2026-106561 Backstage: Sensitive information disclosure in Kubernetes resource queries 07.10.2026 5
CVE-2026-106562 Backstage: Incorrect authorization in search engine permission filtering 07.10.2026 4.3
CVE-2026-106563 Backstage: Improper entity validation in deprecated Kubernetes services endpoint 07.10.2026 5.3
CVE-2025-70515 07.10.2026
CVE-2025-70516 07.10.2026
CVE-2025-70517 07.10.2026
CVE-2025-70518 07.10.2026
CVE-2025-70519 07.10.2026
CVE-2025-70520 07.10.2026
CVE-2025-70521 07.10.2026
CVE-2026-106556 Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization 07.10.2026 7.7
CVE-2026-106558 Backstage: Improper validation of TechDocs MkDocs configuration 07.10.2026 8.8
CVE-2026-106559 Backstage: Improper input validation in Confluence to Markdown scaffolder module 07.10.2026 6.3
CVE-2026-104074 Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE 07.10.2026
CVE-2026-106064 Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions 07.10.2026
CVE-2026-106510 Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml 07.10.2026 7.7
CVE-2026-107167 M17n-lib: heap use-after-free write in re_init_ic() 07.10.2026
CVE-2026-107169 M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 07.10.2026
CVE-2026-107174 Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction 07.10.2026
CVE-2026-107202 CVE-2026-107202 07.10.2026
CVE-2026-62179 PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues 07.10.2026 6.5
CVE-2026-77214 libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer 07.10.2026
CVE-2026-107125 XnView Classic FLI File heap-based overflow 07.10.2026
CVE-2026-46570 07.10.2026
CVE-2026-42616 07.10.2026
CVE-2026-42617 07.10.2026
CVE-2026-46437 wger: API credentials remain valid after logout/password change 07.10.2026 4.8
CVE-2026-46438 wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry 07.10.2026 6.5
CVE-2026-46569 07.10.2026
CVE-2026-46571 07.10.2026
CVE-2026-107194 07.10.2026
CVE-2026-42618 07.10.2026
CVE-2026-46434 wger: Trainer Privilege Escalation - Improper Privilege Management 07.10.2026 7.1
CVE-2026-46572 07.10.2026
CVE-2026-107181 Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme 07.10.2026
CVE-2026-107183 llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser 07.10.2026
CVE-2026-43976 wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) 07.10.2026 7.1
CVE-2026-45161 wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding 07.10.2026 5.4
CVE-2026-102257 07.10.2026
CVE-2026-102258 07.10.2026
CVE-2026-88514 07.10.2026
CVE-2026-102255 07.10.2026
CVE-2026-102256 07.10.2026
CVE-2026-98373 mm/hugetlb: preserve mremap address delta when skipping page tables 07.10.2026
CVE-2026-98374 tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() 07.10.2026
CVE-2026-103435 Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code 07.10.2026
CVE-2026-107151 Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests 07.10.2026
CVE-2026-107162 Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass 07.10.2026
CVE-2026-107168 M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars() 07.10.2026
CVE-2026-107170 M17n-lib: null dereference in minput_open_im() after failed m17n_init() 07.10.2026
CVE-2026-107175 MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes 07.10.2026
CVE-2026-107177 Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens 07.10.2026
CVE-2026-107180 MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances 07.10.2026
CVE-2026-41958 07.10.2026 6.5
CVE-2026-42532 07.10.2026 5.5
CVE-2026-105138 Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API 07.10.2026
CVE-2026-105139 Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources 07.10.2026
CVE-2026-105140 Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership 07.10.2026
CVE-2026-106056 Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting 07.10.2026
CVE-2026-106057 patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt 07.10.2026
CVE-2026-106058 GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames 07.10.2026
CVE-2026-106059 GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript 07.10.2026
CVE-2026-107159 MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header 07.10.2026
CVE-2026-42708 WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability 07.10.2026 7.6
CVE-2026-42710 WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability 07.10.2026 7.6
CVE-2026-42713 WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability 07.10.2026 7.6
CVE-2026-42714 WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection vulnerability 07.10.2026 7.6
CVE-2026-92531 Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET 07.10.2026
CVE-2026-92532 Unrestricted Upload of File with Dangerous Type in BugTracker.NET 07.10.2026
CVE-2026-92533 Path Traversal in BugTracker.NET 07.10.2026
CVE-2026-103668 07.10.2026
CVE-2026-96408 07.10.2026
CVE-2026-42720 WordPress Dynamic User Directory plugin <= 2.4 - SQL Injection vulnerability 07.10.2026 7.6
CVE-2026-42721 WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability 07.10.2026 7.6
CVE-2026-105192 LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization 07.10.2026 9.8
CVE-2026-103075 WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability 07.10.2026 4.3
CVE-2026-104390 WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability 07.10.2026 4.3
CVE-2026-104391 WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-104393 WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-105871 WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-105873 WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-105875 WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-105876 WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vulnerability 07.10.2026 5.3
CVE-2026-105884 WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-27434 WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability 07.10.2026 5.3
CVE-2026-78243 Apache YuniKorn: LDAP Group provider panics on lowercase attribute name 07.10.2026
CVE-2026-92393 Apache YuniKorn: Admission control bypass via workload UPDATE operation 07.10.2026
CVE-2026-97146 Apache YuniKorn: Admission control bypass via system label forgery 07.10.2026
CVE-2026-97294 WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability 07.10.2026 6.5
CVE-2026-103416 07.10.2026
CVE-2026-15894 Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement 07.10.2026 8.8
CVE-2026-19186 Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write 07.10.2026 8.1
CVE-2025-64391 07.10.2026
CVE-2025-64392 07.10.2026
CVE-2025-64393 07.10.2026
CVE-2026-58068 07.10.2026
CVE-2026-58069 07.10.2026
CVE-2026-5703 Path Traversal in Satel Iberia SenNet Datalogger Serie 200 07.10.2026
CVE-2026-90466 Apache Impala: Path traversal executes JARs outside trusted paths 07.10.2026
CVE-2026-93026 07.10.2026
CVE-2026-93684 Apache Impala: Stored XSS in Impala query plans 07.10.2026
CVE-2026-97720 Apache Impala: Impala Executor Webserver Auth Bypass 07.10.2026
CVE-2026-102781 Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 07.10.2026
CVE-2026-102782 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 07.10.2026
CVE-2026-107102 Account Takeover Vulnerability in Manacle Technologies ERP System 07.10.2026
CVE-2026-107103 SQL Injection Vulnerability in Manacle Technologies ERP System 07.10.2026
CVE-2026-107104 Unsafe Deserialization Vulnerability in Manacle Technologies ERP System 07.10.2026
CVE-2026-89417 OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthenticated Stored Cross-Site Scripting via 's' Search Parameter in comments-atom Feed 07.10.2026 7.2
CVE-2026-107121 Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade 07.10.2026
CVE-2026-105322 Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form 07.10.2026 5.3
CVE-2026-82211 Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure 07.10.2026 8.2
CVE-2026-82212 Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler 07.10.2026 7.5
CVE-2026-86833 MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes 07.10.2026 5.4
CVE-2026-103323 Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure 07.10.2026
CVE-2026-103378 Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log File 07.10.2026
CVE-2026-103681 Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete 07.10.2026
CVE-2026-104049 Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint 07.10.2026
CVE-2026-104050 Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers 07.10.2026
CVE-2026-104651 Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR 07.10.2026
CVE-2026-104652 Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID 07.10.2026
CVE-2026-104653 Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions 07.10.2026
CVE-2026-104667 Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order 07.10.2026
CVE-2026-104677 WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP 07.10.2026
CVE-2026-104678 CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update 07.10.2026
CVE-2026-104953 MPG < 4.2.3 - Editor+ SQLi via Project Import 07.10.2026
CVE-2026-105316 Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions 07.10.2026
CVE-2026-86816 WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API 07.10.2026
CVE-2026-87782 Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator 07.10.2026
CVE-2026-87971 If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter 07.10.2026
CVE-2026-96530 Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget 07.10.2026
CVE-2026-97188 String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor 07.10.2026
CVE-2026-97331 User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access 07.10.2026
CVE-2026-97354 PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects 07.10.2026
CVE-2026-103868 Pulp-container: registry credentials are reused across remotes in a worker 07.10.2026
CVE-2026-103869 Pulp-ansible: bearer tokens are reused across remotes in a worker 07.10.2026
CVE-2026-103870 Pulp-rpm: distribution tree publish creates directories from .treeinfo ids 07.10.2026
CVE-2026-59346 VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability 07.10.2026 9.3
CVE-2026-59347 VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability 07.10.2026 8.1
CVE-2026-102173 Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata 07.10.2026 7.2
CVE-2026-19572 FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability 07.10.2026
CVE-2026-83742 wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms 07.10.2026
CVE-2026-84897 wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion 07.10.2026
CVE-2026-106061 Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file 07.10.2026
CVE-2026-14911 07.10.2026
CVE-2026-16516 wolfSSH ECDSA host key curve not validated against negotiated algorithm 07.10.2026
CVE-2026-81535 wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check 07.10.2026
CVE-2026-83540 wolfSSHd on Windows race condition leading to logon token reused across connections 07.10.2026
CVE-2026-106471 Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter multi-@verify hasaccess latching 07.10.2026
CVE-2026-16528 07.10.2026
CVE-2026-19386 07.10.2026
CVE-2026-19396 07.10.2026
CVE-2026-102478 07.10.2026
CVE-2026-105324 An HTTP header injection vulnerability was found in the ADM 07.10.2026
CVE-2026-101329 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 6.5
CVE-2026-101331 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 7.7
CVE-2026-103360 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 8.1
CVE-2026-104334 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 9.8
CVE-2026-88962 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.8
CVE-2026-93443 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 7.5
CVE-2026-93445 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.1
CVE-2026-93447 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 7.5
CVE-2026-93448 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 6.5
CVE-2026-93449 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.5
CVE-2026-93674 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 9.8
CVE-2026-93675 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.8
CVE-2026-93677 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 7.7
CVE-2026-93678 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 7.6
CVE-2026-93679 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 4.3
CVE-2026-97655 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 8.8
CVE-2026-97671 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 6.5
CVE-2026-97673 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.8
CVE-2026-97674 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 8.1
CVE-2026-97676 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.8
CVE-2026-97678 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 8.8
CVE-2026-97679 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 8.8
CVE-2026-97680 Langflow OSS is affected by multiple vulnerabilities 06.10.2026 8.3
CVE-2026-104335 Langflow OSS is affected by multiple vulnerabilities 07.10.2026 8.8
CVE-2026-106583 06.10.2026 2.5
CVE-2026-80048 Sssd: sssd-kcm: local denial of service via excessive memory preallocation 06.10.2026
CVE-2026-106509 Backstage: Improper validation of MkDocs theme configuration in TechDocs 06.10.2026 7.7
CVE-2026-106505 Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend 06.10.2026 7.7
CVE-2026-106506 Backstage: Improper input validation in scaffolder task list ordering 06.10.2026 5.3
CVE-2026-106507 Backstage: TechDocs arbitrary file read via mkdocs snippets 07.10.2026 5.3
CVE-2026-106508 Backstage: Potential file exposure through local TechDocs publisher 06.10.2026 5.3
CVE-2026-101023 Gitea OAuth2 refresh token grant accepts access tokens 06.10.2026
CVE-2026-104633 Gitea migration memory exhaustion from zero page size 07.10.2026
CVE-2026-105267 Gitea tag delete route deletes releases without release permission 06.10.2026
CVE-2026-105268 Gitea issue attachment API allows changing comment attachments 06.10.2026
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder 06.10.2026 9.6
CVE-2026-106502 Backstage: Sensitive information may be exposed in Scaffolder task failure events 07.10.2026 5.3
CVE-2026-106503 Backstage: Scaffolder action input authorization bypass 06.10.2026 8.1
CVE-2026-106504 Backstage: Sensitive information exposure in scaffolder task logs 06.10.2026 6.5
CVE-2026-89182 Gitea push-to-create bypass of FORCE_PRIVATE policy 07.10.2026
CVE-2026-96594 Gitea repository media API stored XSS 07.10.2026
CVE-2026-97626 Gitea profile feed disclosure bypassing user visibility 06.10.2026
CVE-2026-106500 Backstage: Improper task state validation in Scaffolder backend 07.10.2026 8.5