CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-108860 BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key 11.10.2026 9.3
CVE-2026-108576 TOZED X300 IPPingDiagnostics process_ping os command injection 11.10.2026 10
CVE-2026-108753 Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose 11.10.2026 9.3
CVE-2026-108540 OpenSpug File Transfer transfer os command injection 11.10.2026 9.4
CVE-2026-108707 Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect 11.10.2026 9.3
CVE-2026-39801 WordPress AIWU plugin <= 1.5.9 - Privilege Escalation vulnerability 11.10.2026 9.8
CVE-2026-40800 WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin <= 1.5.3 - SQL Injection vulnerability 11.10.2026 9.3
CVE-2026-42696 WordPress SiteVault – Backup, Restore, Migration & Cloning plugin <= 1.5.18 - Remote Code Execution (RCE) vulnerability 11.10.2026 10
CVE-2026-42716 WordPress Payever - WooCommerce Gateway plugin <= 4.8.2 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-42718 WordPress Booster for WooCommerce plugin <= 8.4.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-42719 WordPress Dynamic User Directory plugin <= 2.4 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-42723 WordPress CleanSkin theme <= 1.5.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62022 WordPress Tonda Membership plugin <= 1.0.1 - Privilege Escalation vulnerability 11.10.2026 9.8
CVE-2026-62024 WordPress CodeBard Help Desk plugin <= 1.1.2 - Arbitrary File Upload vulnerability 11.10.2026 9.9
CVE-2026-62025 WordPress Tailored Tools plugin <= 3.0.3 - Arbitrary File Upload vulnerability 11.10.2026 9
CVE-2026-62031 WordPress uListing plugin <= 2.2.0 - SQL Injection vulnerability 11.10.2026 9.3
CVE-2026-62032 WordPress DirectoryPress plugin <= 3.6.27 - Local File Inclusion vulnerability 11.10.2026 9.8
CVE-2026-62050 WordPress Splendour theme <= 1.23 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62051 WordPress Stargaze theme <= 1.10 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62052 WordPress Tipsy theme <= 1.6 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62053 WordPress Wine House theme <= 3.20 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62054 WordPress Yacht Rental theme <= 2.6 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62076 WordPress Kalles theme <= 1.1.7.1 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62077 WordPress Avala theme <= 1.1.4 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62086 WordPress Juno theme <= 2.25 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62087 WordPress Equadio theme <= 1.1.4 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62090 WordPress WineShop theme <= 3.20 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62120 WordPress Law Office theme <= 3.20 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62123 WordPress Invetex theme <= 2.18 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62124 WordPress N7 | Golf Club Sports & Events theme <= 2.21 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62125 WordPress Asia Garden theme <= 1.3.1 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62129 WordPress Creator LMS plugin <= 1.2.21 - Arbitrary File Upload vulnerability 11.10.2026 9.9
CVE-2026-66482 WordPress Drone Media theme <= 2.2.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66483 WordPress Education Center theme <= 3.6.12 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66563 WordPress Windsor theme <= 2.10 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66564 WordPress ShiftCV theme <= 3.0.14 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66565 WordPress FC United theme <= 1.1.1 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66567 WordPress Anesta theme <= 1.5.3 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66568 WordPress Original theme <= 1.9.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-66569 WordPress Kicker theme <= 2.2.1 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-78529 WordPress Alliance theme <= 3.11 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-78531 WordPress Jacqueline theme <= 2.22 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-78533 WordPress Qwery theme <= 3.6.1 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-78535 WordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-81797 WordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-108598 Floci 1.1.0 before 2.2.0 RCE via API Gateway VTL Mapping Templates 10.10.2026 9.3
CVE-2026-105892 WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.13 - Arbitrary File Deletion vulnerability 11.10.2026 9.8
CVE-2026-106610 WordPress miniorange otp verification plugin <= 5.5.7 - Privilege Escalation vulnerability 11.10.2026 9.8
CVE-2026-104398 WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.10 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-105889 WordPress Tickera plugin <= 3.6.0.6 - SQL Injection vulnerability 11.10.2026 9.3
CVE-2026-108549 cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing 10.10.2026 9.2
CVE-2026-108551 openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates 10.10.2026 9.3
CVE-2026-104803 WPCOM Member <= 1.7.27 - Unauthenticated Authentication Bypass via 'uuid' and 'code' Parameters on Social-Login Callback 10.10.2026 9.8
CVE-2026-62045 WordPress Booklovers theme <= 2.13.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-62046 WordPress Gutentype theme <= 2.1.12 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93927 WordPress Veto theme <= 1.6.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93929 WordPress Travesia theme <= 1.1.16 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93930 WordPress Tantra theme <= 2.9.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93931 WordPress Smash theme <= 1.12.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93932 WordPress Smart Casa theme <= 1.0.12 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93933 WordPress Rosalinda theme <= 1.2.4 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93934 WordPress Partiso theme <= 1.1.13 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93935 WordPress Let's Play theme <= 1.1.15 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93936 WordPress IPharm theme <= 1.2.4 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93937 WordPress Hygia theme <= 1.21.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93938 WordPress Hogwords theme <= 1.2.7 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93940 WordPress Greeny theme <= 2.10.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93941 WordPress Edema theme <= 1.2.2.2 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93942 WordPress Dwell theme <= 1.16.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93943 WordPress Convex theme <= 1.16.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93944 WordPress Camelia theme <= 1.2.15 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-93945 WordPress Balance theme <= 1.12.0 - PHP Object Injection vulnerability 11.10.2026 9.8
CVE-2026-104801 PPOM <= 34.0.10 - Unauthenticated Arbitrary File Deletion via 'ppom[fields][<data_name>][n][org]' Parameter 10.10.2026 9.1
CVE-2026-103889 3D Product configurator for WooCommerce <= 2.16.2 - Unauthenticated Remote Code Execution via 'xpv_image' Parameter 10.10.2026 9.8
CVE-2026-97670 Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Field 10.10.2026 9.1
CVE-2026-104732 Advanced IP Blocker <= 8.13.13 - Unauthenticated Authentication Bypass via Missing Step-1 Binding to 2FA Login Handler 10.10.2026 9.8
CVE-2026-107645 Blocksy Companion <= 2.1.58 - Unauthenticated Privilege Escalation to 'role' Parameter 10.10.2026 9.1
CVE-2026-94589 Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.4.5 - Unauthenticated Arbitrary File Upload via Signature Field File Upload 10.10.2026 9.8
CVE-2026-108474 09.10.2026 9.8
CVE-2026-108267 Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session 09.10.2026 9.1
CVE-2026-108268 enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session 09.10.2026 9.1
CVE-2026-108269 ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session 09.10.2026 9.1
CVE-2026-108266 Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session 09.10.2026 9.1
CVE-2026-108264 Wizarr: Authenticated Server-Side Template Injection (SSTI) in wizard step rendering leads to Remote Code Execution (RCE) 09.10.2026 9.1
CVE-2026-108265 enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session 09.10.2026 9.1
CVE-2026-108261 TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment 09.10.2026 9.3
CVE-2026-108263 Astron Agent: Unsandboxed code-node leads to cross-tenant RCE 09.10.2026 9.9
CVE-2026-107845 Contao: Cross-site scripting in the comments bundle 09.10.2026 9.3
CVE-2026-107824 x64dbg-MCP Server exposes debugger operations to unauthenticated network clients 09.10.2026 9.3
CVE-2026-108157 Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking 09.10.2026 9.2
CVE-2026-107806 Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite 09.10.2026 9.4
CVE-2026-15340 Savannah lwIP SMTP client Classic Buffer Overflow 09.10.2026 9.3
CVE-2026-108107 PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php 09.10.2026 9.3
CVE-2026-108109 PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code 09.10.2026 9.3
CVE-2026-28745 Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format 09.10.2026 9.3
CVE-2026-33367 Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function 09.10.2026 9.3
CVE-2026-39460 Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials 09.10.2026 9.3
CVE-2026-105278 Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials 09.10.2026 9.3
CVE-2026-32645 Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials 09.10.2026 9.2
CVE-2026-100730 Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data 09.10.2026 9.3
CVE-2026-86405 Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop 09.10.2026 9.8
CVE-2026-85531 Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x 09.10.2026 9.8
CVE-2026-93947 WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-94503 WordPress Zombify plugin <= 1.7.7 - Arbitrary File Upload vulnerability 09.10.2026 10
CVE-2026-96327 WordPress WPLMS plugin < 1.9.9.8.2 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96328 WordPress JNews - Pay Writer plugin <= 12.0.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96330 WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability 11.10.2026 9.3
CVE-2026-96331 WordPress Ajax Search Pro plugin <= 4.29.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96809 WordPress EduAdmin Booking plugin < 6.0.0 - SQL Injection vulnerability 11.10.2026 9.3
CVE-2026-107935 Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose 09.10.2026 9.3
CVE-2026-107908 Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message 09.10.2026 9.3
CVE-2026-107910 Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling 09.10.2026 9.2
CVE-2026-5759 Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB 09.10.2026 9.3
CVE-2026-7827 Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB 09.10.2026 9.2
CVE-2026-69435 Azure SRE Agent Elevation of Privilege Vulnerability 10.10.2026 9.6
CVE-2026-77900 Azure App Service Remote Code Execution Vulnerability 10.10.2026 9.8
CVE-2026-88131 Microsoft Dataverse Remote Code Execution Vulnerability 10.10.2026 9.8
CVE-2026-94510 Microsoft Bookings Elevation of Privilege Vulnerability 10.10.2026 9.9
CVE-2026-96207 Microsoft Partner Center Elevation of Privilege Vulnerability 10.10.2026 10
CVE-2026-107726 Hazelcast: Arbitrary member memory access by low-privileged client 09.10.2026 9.3
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion 08.10.2026 9.8
CVE-2026-75875 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 10.10.2026 9.8
CVE-2026-80381 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 10.10.2026 9.8
CVE-2026-84249 IBM Guardium Data Protection is affected by vulnerability 10.10.2026 9.8
CVE-2026-107406 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 10.10.2026 9.5
CVE-2026-16823 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.1
CVE-2026-16916 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.1
CVE-2026-19491 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.1
CVE-2026-78401 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.8
CVE-2026-78406 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 10.10.2026 9.8
CVE-2026-79842 10.10.2026 9.1
CVE-2026-107779 Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE 08.10.2026 9.3
CVE-2026-107780 Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter 08.10.2026 9.3
CVE-2026-107781 Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById 09.10.2026 9.1
CVE-2026-106126 Command Injection 08.10.2026 9.4
CVE-2026-104075 TVU Networks Receiver/Transceiver Authentication Bypass via /tvu/Login 08.10.2026 9.3
CVE-2026-104076 TVU Networks Receiver/Transceiver Missing Authentication via REST API 09.10.2026 9.3
CVE-2026-84244 IBM Guardium Data Protection Cross-Site Scripting 08.10.2026 9.3
CVE-2026-84272 IBM Guardium Data Protection Missing Authentication 10.10.2026 9.8
CVE-2026-107699 ppt2png through 0.0.6 OS Command Injection via input and output paths 08.10.2026 9.3
CVE-2026-107700 dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument 09.10.2026 9.3
CVE-2026-107703 @enmaso/node-convert through 1.0.0 OS Command Injection via filepath and convertTo 08.10.2026 9.3
CVE-2026-107704 image_optimizer 1.3.0 through 1.9.0 OS Command Injection via identify_format 09.10.2026 9.3
CVE-2026-9209 mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx 08.10.2026 9.3
CVE-2026-14269 IBM DataPower Gateway Buffer Overflow 09.10.2026 9.8
CVE-2026-107640 Integrics Enswitch 3.13 through 4.4 Authentication Bypass via Password Reset API 08.10.2026 9.3
CVE-2026-14502 IBM DataPower Gateway Improper Authentication 09.10.2026 9.8
CVE-2026-14992 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-14990 IBM DataPower Gateway affected by cross-site scripting 08.10.2026 9.3
CVE-2026-14991 IBM DataPower Gateway Out-of-bounds Write 10.10.2026 9.8
CVE-2026-103663 Path Traversal leading to Remote Code Execution in Ollama 08.10.2026 9.4
CVE-2026-15762 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-16340 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-19218 Password Reset Code Brute Force Leading to Account Takeover in AKIN Software's MyRezzta 08.10.2026 9.1
CVE-2026-92555 Database Credentials Disclosure in AKIN Software's AKINSOFT WOLVOX Control Panel 08.10.2026 9.8
CVE-2026-107510 Authenticated argument injection in NIOS command line leading to privilege escalation 09.10.2026 9.1
CVE-2026-105110 Iskratel Innbox Unauthenticated Remote Code Execution via login.xgi CLI Parameter 08.10.2026 9.3
CVE-2026-12260 SQL injection in the NetBoard CRM demo platform 08.10.2026 10
CVE-2026-85097 Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter 08.10.2026 9.8
CVE-2026-107459 Openfind|SecuShare Pro - OS Command Injection 08.10.2026 9.3
CVE-2026-17609 Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter 10.10.2026 9.1
CVE-2026-107282 AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host 10.10.2026 9.4
CVE-2026-76268 Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise 09.10.2026 9.8
CVE-2026-95605 WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability 07.10.2026 9.3
CVE-2026-95606 WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability 07.10.2026 9.8
CVE-2026-20328 Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability 08.10.2026 9.1
CVE-2026-62176 PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation 07.10.2026 9.1
CVE-2026-62252 Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login 07.10.2026 9.8
CVE-2026-62253 Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default) 10.10.2026 9.8
CVE-2026-76454 Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability 07.10.2026 9.1
CVE-2026-76455 Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities 08.10.2026 9.8
CVE-2026-76459 Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Write Vulnerabilities 09.10.2026 9.8
CVE-2026-76464 Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities 07.10.2026 9.6
CVE-2026-76465 Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76471 Cisco NX-OS Software NX-API Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76480 Cisco License On-Prem Security Hardening Release 08.10.2026 9.8
CVE-2026-76482 Cisco License On-Prem Security Hardening Release 08.10.2026 10
CVE-2026-76483 Cisco License On-Prem Security Hardening Release 08.10.2026 9.1
CVE-2026-76485 Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76486 Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76498 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Access Control Vulnerabilities 07.10.2026 9.8
CVE-2026-76499 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization Vulnerabilities 07.10.2026 9.8
CVE-2026-76500 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime Vulnerabilities 08.10.2026 9.8
CVE-2026-76501 Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-92414 Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens 07.10.2026 9.3
CVE-2026-107204 LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint 07.10.2026 9.3
CVE-2026-107194 10.10.2026 9.2
CVE-2026-107183 llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser 07.10.2026 9.2
CVE-2026-96408 07.10.2026 9.3
CVE-2026-105192 LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization 07.10.2026 9.8
CVE-2026-103416 07.10.2026 9.3
CVE-2025-64393 08.10.2026 9.4
CVE-2026-102782 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 08.10.2026 9.3
CVE-2026-107102 Account Takeover Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107103 SQL Injection Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107104 Unsafe Deserialization Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-59346 VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability 07.10.2026 9.3
CVE-2026-19572 FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability 07.10.2026 9.3
CVE-2026-14911 07.10.2026 9.3
CVE-2026-16516 wolfSSH ECDSA host key curve not validated against negotiated algorithm 07.10.2026 9
CVE-2026-19386 08.10.2026 9.3
CVE-2026-105324 An HTTP header injection vulnerability was found in the ADM 07.10.2026 9.2
CVE-2026-104334 Langflow OSS is affected by multiple vulnerabilities 08.10.2026 9.8
CVE-2026-93674 Langflow OSS is affected by multiple vulnerabilities 08.10.2026 9.8
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder 07.10.2026 9.6
CVE-2026-101157 Security Advisory 0192 06.10.2026 9.3
CVE-2026-102159 Security Advisory 0190 06.10.2026 9.3
CVE-2026-102162 Security Advisory 0193 06.10.2026 9.4
CVE-2026-102167 Security Advisory 0197 06.10.2026 9
CVE-2026-106445 Handlebars: JavaScript Injection via Own Property Check Bypass 09.10.2026 9.2
CVE-2026-106446 Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams) 07.10.2026 9.8
CVE-2026-101158 Security Advisory 0185 06.10.2026 9.3
CVE-2026-76750 Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76751 Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution 08.10.2026 9.8
CVE-2026-76752 Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access 08.10.2026 9.8
CVE-2026-76753 Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76754 Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-79794 Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface 08.10.2026 9.1
CVE-2026-79796 Authentication Bypass Vulnerabilities in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-79798 Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface 08.10.2026 9.9
CVE-2026-79801 Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent 08.10.2026 9.8
CVE-2026-79805 Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76742 Authentication Bypass in the Web Management Interface of AOS-S 08.10.2026 9.8
CVE-2026-76743 Authentication Bypass Vulnerability in the Management Interface of AOS-S 08.10.2026 9.8
CVE-2026-76744 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S 08.10.2026 9.8
CVE-2026-76745 Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S 08.10.2026 9.6
CVE-2026-76746 Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S 07.10.2026 9.3
CVE-2026-76747 Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S 07.10.2026 9.1
CVE-2026-86360 06.10.2026 9.6
CVE-2026-106102 Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() 06.10.2026 10
CVE-2026-105863 Payload authentication token field handling issue 09.10.2026 9.2
CVE-2026-105857 Payload: RCE in Payload Form Builder 06.10.2026 10
CVE-2026-105859 Payload: Unauthorized update to collection documents 06.10.2026 9.8
CVE-2026-104070 SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE 09.10.2026 9.3
CVE-2026-105851 Payload: Field access control bypass on auth collections 06.10.2026 9.3
CVE-2026-105844 Payload: Prototype pollution in Payload Import Export plugin 09.10.2026 9.3
CVE-2026-105845 Payload: SQL Injection in SQLite and Postgres 06.10.2026 9.8
CVE-2026-67273 08.10.2026 9.6
CVE-2026-54472 06.10.2026 9.8
CVE-2026-61421 06.10.2026 9.8
CVE-2026-67269 08.10.2026 9.9
CVE-2026-63688 06.10.2026 10
CVE-2026-63692 09.10.2026 10
CVE-2026-105793 Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` 06.10.2026 9.1
CVE-2026-105794 MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL 06.10.2026 9.1
CVE-2026-106037 Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service 06.10.2026 9.3
CVE-2026-91140 OS command injection in Progress Software Autonomous REST Connector GenAI Agents 07.10.2026 9.6
CVE-2026-105835 PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint 09.10.2026 9.1
CVE-2026-82531 Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache 06.10.2026 9.2
CVE-2026-32557 WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-32568 WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability 06.10.2026 9.9
CVE-2026-32579 WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39746 WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39753 WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39755 WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39757 WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39759 WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39761 WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39764 WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39770 WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39773 WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability 06.10.2026 10
CVE-2026-39785 WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39795 WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39797 WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability 06.10.2026 9.8
CVE-2026-41555 WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42415 WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42417 WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-98323 RDMA/siw: Bound fragmented header copies by the remaining length 07.10.2026 9.8
CVE-2026-98365 RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access 07.10.2026 9.8
CVE-2026-85153 Information Disclosure Vulnerability in Schmooze dating mobile Application 06.10.2026 9.3
CVE-2026-105778 Tenda AC5 Wifi setWifi stack-based overflow 06.10.2026 9.4
CVE-2026-94293 Missing authentication for critical function in the aas-edge-client REST API 06.10.2026 9.3
CVE-2026-105484 TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection 06.10.2026 10
CVE-2026-105763 Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL 08.10.2026 9.6
CVE-2026-21589 07.10.2026 9.3
CVE-2026-91107 openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) 06.10.2026 9.3
CVE-2026-105697 Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration 09.10.2026 9.9
CVE-2026-105740 Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server 06.10.2026 9.9
CVE-2026-77226 Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint 07.10.2026 9.2
CVE-2026-105691 Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color 06.10.2026 9.9
CVE-2026-103352 WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability 05.10.2026 9.3
CVE-2026-105636 Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 07.10.2026 9.9
CVE-2026-105637 Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) 05.10.2026 9.6
CVE-2026-105638 Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force 05.10.2026 9.1
CVE-2026-105639 Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane 06.10.2026 9.8
CVE-2026-105640 Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) 05.10.2026 9.1
CVE-2026-105641 Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass 07.10.2026 9.8
CVE-2026-97283 WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability 05.10.2026 9.8
CVE-2026-102428 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 05.10.2026 9.3
CVE-2026-79820 05.10.2026 9
CVE-2026-105285 Totolink A3002MU QoS Rule formIpQoS stack-based overflow 05.10.2026 10
CVE-2026-105284 Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization 05.10.2026 10
CVE-2026-100102 RCE via exposed JDWP debug agent in P4Search 05.10.2026 9.5
CVE-2026-100103 Authentication bypass via default auth token in P4Search 05.10.2026 10
CVE-2026-103510 Authentication bypass via blank auth token in P4Search 05.10.2026 9.5
CVE-2026-105223 maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105293 Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers 05.10.2026 9.2
CVE-2026-105294 Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig 05.10.2026 9.1
CVE-2026-105221 Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105222 alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer 05.10.2026 9.1

Latest Updates

CVE Title Updated Score
CVE-2026-108913 11.10.2026 7.1
CVE-2026-107761 Channel tokens and organization API key exposed in API responses 11.10.2026
CVE-2026-108902 pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link 11.10.2026
CVE-2026-108903 pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID 11.10.2026
CVE-2026-108904 pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController 11.10.2026
CVE-2026-108905 pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header 11.10.2026
CVE-2026-108684 erzhongxmu Jeewms Autocomplete Data JeecgFormDemoController.java getTreeData sql injection 11.10.2026
CVE-2026-108683 zhayujie CowAgent Media Download memory allocation 11.10.2026
CVE-2026-108866 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserAuths 11.10.2026
CVE-2026-108867 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserRoleSetById 11.10.2026
CVE-2026-108868 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusTemplateAnnouncement 11.10.2026
CVE-2026-108869 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendSysAnnouncement 11.10.2026
CVE-2026-108870 JeecgBoot through 3.9.5 Missing Authorization via POST /sys/role/datarule 11.10.2026
CVE-2026-108871 JeecgBoot through 3.9.5 Missing Authorization via POST /sys/sysDepartRole/datarule 11.10.2026
CVE-2026-108872 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/batchEditUsers 11.10.2026
CVE-2026-108873 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/doUpdateDepartInfo 11.10.2026
CVE-2026-108874 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/changeDepartChargePerson 11.10.2026
CVE-2026-108875 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/addSysUserGroup 11.10.2026
CVE-2026-108876 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/putCancelQuit 11.10.2026
CVE-2026-108877 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/delete 11.10.2026
CVE-2026-108878 JeecgBoot through 3.9.5 Missing Authorization via /airag/app/queryById 11.10.2026
CVE-2026-108879 JeecgBoot through 3.9.5 IDOR via /airag/api/getChatVariable Username Parameter 11.10.2026
CVE-2026-108880 JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/editDictByLowAppId 11.10.2026
CVE-2026-108881 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/getTenantPackInfo 11.10.2026
CVE-2026-108882 JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser 11.10.2026
CVE-2026-108883 JeecgBoot through 3.9.5 Missing Authorization via /sys/thirdApp/editThirdAppConfig 11.10.2026
CVE-2026-108884 JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Delete Endpoint 11.10.2026
CVE-2026-108885 JeecgBoot through 3.9.5 Missing Authorization via /sys/message/sysMessage/delete 11.10.2026
CVE-2026-108886 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/queryChildrenByUsername 11.10.2026
CVE-2026-108887 JeecgBoot through 3.9.5 Missing Authorization via /sys/comment/exportXls 11.10.2026
CVE-2026-108888 JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/exportXls 11.10.2026
CVE-2026-108891 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/getUserDetailByUserId 11.10.2026
CVE-2026-108682 zhayujie CowAgent Web Console upload read denial of service 11.10.2026
CVE-2026-108697 CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction 11.10.2026
CVE-2026-108698 hyper-mcp through 0.8.3 OCI Plugin Signature Verification TOCTOU Race Condition 11.10.2026
CVE-2026-108699 hyper-mcp through 0.8.3 Improper Signature Verification of OCI WebAssembly Plugins 11.10.2026
CVE-2026-108839 thClaws through 0.141.0 Symlink Following File Write via POST /v1/inputs 11.10.2026
CVE-2026-108850 Company Research Agent through 2.2.0 SSRF via /generate-pdf ReportLab Markup 11.10.2026
CVE-2026-108851 phpMyFAQ through 4.1.10 Missing Authorization via MCP Server faq_search Tool 11.10.2026
CVE-2026-108852 Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass 11.10.2026
CVE-2026-108853 UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app 11.10.2026
CVE-2026-108854 Wanwu before 0.6.3 IDOR AppKey Deletion via DELETE /v1/appspace/app/key 11.10.2026
CVE-2026-108855 UnicomAI Wanwu through 0.6.5 Missing Authorization via DELETE /v1/appspace/app/publish 11.10.2026
CVE-2026-108856 UnicomAI Wanwu through 0.6.5 Authorization Bypass via /v1/appspace/app/key AppKey Minting 11.10.2026
CVE-2026-108857 Hugging Face Text Embeddings Inference through 1.9.4 Cleartext API Key Logging 11.10.2026
CVE-2026-108858 Predibase LoRAX through 0.12.1 API Token Exposure via Router Logs 11.10.2026
CVE-2026-108859 mcp-go through 1.2.1 Denial of Service via Unbounded POST Body Buffering 11.10.2026
CVE-2026-108860 BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key 11.10.2026
CVE-2026-108861 Odoo MCP 1.0.0 through 1.3.2 Information Disclosure via execute_method Tool 11.10.2026
CVE-2026-108862 APIPark through 1.9.7-beta IDOR via application authorization endpoints 11.10.2026
CVE-2026-108863 Katanemo Plano through 0.4.37 Missing Authentication on Envoy Admin Interface 11.10.2026
CVE-2026-108864 iFlytek Astron Agent through 1.1.2 Authorization Bypass via /workflow/v1/resume Endpoint 11.10.2026
CVE-2026-108865 AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize 11.10.2026
CVE-2026-108681 zhayujie CowAgent Web Console web_channel.py denial of service 11.10.2026
CVE-2026-108584 FunnyWolf Viper config hard-coded credentials 11.10.2026
CVE-2026-108578 Neterbit NW-431F Embedded Web Server sms.json information disclosure 11.10.2026
CVE-2026-108576 TOZED X300 IPPingDiagnostics process_ping os command injection 11.10.2026
CVE-2026-108577 Konstanty Bialkowski libmodplug ABC Music Format load_abc.cpp abc_add_gchord resource consumption 11.10.2026
CVE-2026-108710 NornicDB through 1.4.1 Missing Authorization via Vector Search Endpoints 11.10.2026
CVE-2026-108711 Plastic Labs Honcho through 3.3.0 Incorrect Authorization via POST /v3/workspaces 11.10.2026
CVE-2026-108712 SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via DetailUserRole Entry Point 11.10.2026
CVE-2026-108713 SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via setCampaignMarketingAndTemplate 11.10.2026
CVE-2026-108714 MCP Kotlin SDK through 0.15.0 Memory Exhaustion via Application.mcpWebSocket 11.10.2026
CVE-2026-108715 LibreNMS through 26.9.1.1 Authorization Bypass via Smokeping Graph auth.inc.php 11.10.2026
CVE-2026-108716 mcp-remote 0.8.0 through 0.14.3 Cleartext Credential Transmission via --device-code OAuth Grant 11.10.2026
CVE-2026-108717 Combodo iTop 3.1.0 through 3.3.0 Missing Authorization via LinkSetController 11.10.2026
CVE-2026-108718 Rill 0.77.0 through 0.90.5 OAuth Missing Authorization via Dynamic Client Registration 11.10.2026
CVE-2026-108719 LLMGateway through 1.20.0 Blind SSRF via Video-Generation callback_url 11.10.2026
CVE-2026-108720 phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages 11.10.2026
CVE-2026-108721 Open Computer Use through 1.0.0 Denylist Bypass via Case-Variant Bundle ID 11.10.2026
CVE-2026-108722 open-computer-use through commit 610bac8 Stored XSS via log.html Session Log 11.10.2026
CVE-2026-108723 answer-me-with-html through 0.5.0 Symlink Following in Code Block src Embedding 11.10.2026
CVE-2026-108724 Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint 11.10.2026
CVE-2026-108725 Cheshire Cat AI core through 2.0.23 Stored XSS via uploads plugin 11.10.2026
CVE-2026-108726 GLPI through 12.0.0 Missing Authorization via ajax/map.php 11.10.2026
CVE-2026-108727 EdgeEver through 1.108.0 Missing Authorization via Memo-Template API Routes 11.10.2026
CVE-2026-108728 Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook 11.10.2026
CVE-2026-108729 Corteza through 2024.9.10 Unauthenticated Attachment Access via Compose Attachment Endpoints 11.10.2026
CVE-2026-108730 Raven 2.0.0 through 3.0.0 Missing Authorization via Legacy Message and File APIs 11.10.2026
CVE-2026-108731 Raven 2.0.0 through 3.0.0 Missing Authorization via join_workspace Invite-Only Bypass 11.10.2026
CVE-2026-108732 Frappe HR (hrms) before 16.11.0 Missing Authorization via get_account_and_amount 11.10.2026
CVE-2026-108733 Frappe HR (hrms) before 16.11.0 Missing Authorization via expire_allocation 11.10.2026
CVE-2026-108734 Frappe CRM 1.49.0 through 1.87.0 Missing Authorization via get_linked_docs_of_document 11.10.2026
CVE-2026-108735 Miniflux 2.3.0 through 2.3.3 SSRF via Per-Feed Proxy URL 11.10.2026
CVE-2026-108736 Speedtest Tracker through 1.15.0 IP Allowlist Bypass via X-Forwarded-For Spoofing 11.10.2026
CVE-2026-108737 Traccar through 6.16.0 Weak Password Recovery via TokenManager Token Purpose Confusion 11.10.2026
CVE-2026-108738 Traccar 5.7 through 6.16.0 Login CSRF via OpenID Connect Callback 11.10.2026
CVE-2026-108739 OpenAgents Workspace through launcher-v1.0.17 Unauthenticated Credential Exposure via /v1/workspaces 11.10.2026
CVE-2026-108740 GoatCounter through 2.7.0 Privilege Escalation via /user/pref Mass Assignment 11.10.2026
CVE-2026-108741 Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker 11.10.2026
CVE-2026-108742 CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation 11.10.2026
CVE-2026-108744 pbi-cli 3.10.1 through 3.12.0 OS Command Injection via Desktop Sync 11.10.2026
CVE-2026-108745 CloudBeaver through 25.3.5 Missing Authorization via /api/sql-result-value Servlet 11.10.2026
CVE-2026-108746 Vearch 3.5.2 through 3.5.9 Incorrect Authorization via Role.HasPermissionForResources 11.10.2026
CVE-2026-108747 Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion 11.10.2026
CVE-2026-108748 Quarkus LangChain4j 1.9.0 through 1.14.1 Memory Exhaustion via /_chat/routes WebSocket 11.10.2026
CVE-2026-108749 docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints 11.10.2026
CVE-2026-108750 OpenDocMan 2.4.0 through 2.10.0 Decompression Bomb DoS via Upload Text Extraction 11.10.2026
CVE-2026-108751 MoAI-ADK through 3.1.2 Symlink Following via moai init Template Deployer 11.10.2026
CVE-2026-108752 JupyterHub through 6.0.1 OAuth Client ID Collision via Unescaped Hyphen 11.10.2026
CVE-2026-108753 Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose 11.10.2026
CVE-2026-108754 GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger 11.10.2026
CVE-2026-108755 Hatchet through 0.110.5 Unauthenticated Memory Exhaustion via SNS Ingestion Endpoint 11.10.2026
CVE-2026-108756 Abilityai Trinity through 0.9.5 Missing Authorization in Telegram Binding Routes 11.10.2026
CVE-2026-108757 Nexting pinclaw through 0.3.0 Missing Authentication via POST /pinclaw/send 11.10.2026
CVE-2026-108758 Easy!Appointments through 1.6.0 Authorization Bypass via booking/register Endpoint 11.10.2026
CVE-2026-108759 mistral.rs 0.9.0 through 0.9.4 Sandbox Escape via Symlink Following in mistralrs-code-exec 11.10.2026
CVE-2026-108760 LlamaFarm through 0.0.34 Unauthenticated API Exposed on All Interfaces 11.10.2026
CVE-2026-108575 BerriAI LiteLLM Secret Resolution main.py get_secret improper authorization 11.10.2026
CVE-2026-108574 BerriAI LiteLLM Spend Tracking spend_management_endpoints.py ui_view_session_spend_logs authorization 11.10.2026
CVE-2026-108573 Open Asset Import Library Assimp PLY File getNextBlock out-of-bounds 11.10.2026
CVE-2026-108572 Casdoor Proxy Validation cas.go CasP3ProxyValidate server-side request forgery 11.10.2026
CVE-2026-108571 Xinhu Rainrock RockOA Openkqj Action openkqjAction.php returnchuli sql injection 11.10.2026
CVE-2026-108570 Furion .NET Framework View ViewEngine.cs RunCompile special elements in template engine 11.10.2026
CVE-2026-108569 Furion .NET Framework StringRenderExtensions.cs String.Replace sql injection 11.10.2026
CVE-2026-108568 InstantSoft icms2 Billing paypal.php validatePaypalOrder data authenticity 11.10.2026
CVE-2026-108567 InstantSoft icms2 Image image.php files_delete_file path traversal 11.10.2026
CVE-2026-108566 InstantSoft icms2 Private Message index.tpl.php index cross site scripting 11.10.2026
CVE-2026-108544 Lippu Docx Reader Office Viewer App path traversal 11.10.2026
CVE-2026-108543 ag2ai ag2 UserProxyAgent os.path.join path traversal 11.10.2026
CVE-2026-108542 021is elvix-sdk MCP Request index.ts server-side request forgery 11.10.2026
CVE-2026-108541 highwarden Super Store Finder index.php sql injection 11.10.2026
CVE-2026-103305 Prenotazioni <= 1.7.5 - Unauthenticated Stored XSS via Settings Update 11.10.2026
CVE-2026-103694 Mobile builder <= 1.4.2 - Subscriber+ Privilege Escalation to Admin 11.10.2026
CVE-2026-103695 Mobile Builder <= 1.4.2 - Unauthenticated SQLi via 'vendor_id' Parameter 11.10.2026
CVE-2026-104028 Anton Extensions <= 1.2.2 - Unauthenticated Arbitrary File Upload to RCE 11.10.2026
CVE-2026-104680 Envira Gallery < 1.16.2 - Multisite Subsite Admin+ Arbitrary Plugin Installation via Onboarding Wizard 11.10.2026
CVE-2026-104681 Envira Gallery < 1.16.2 - Author+ Non-Public Post Title and Excerpt Disclosure via Gallery REST Field 11.10.2026
CVE-2026-104682 Envira Gallery < 1.16.2 - Contributor Missing Authorization via Convert Gallery REST Route 11.10.2026
CVE-2026-104684 Envira Gallery < 1.16.2 - Author+ IDOR via Shortcode 11.10.2026
CVE-2026-106029 WeddingCity Lite <= 1.0.4 - Unauthenticated Arbitrary Post and Attachment Deletion 11.10.2026
CVE-2026-107507 Squadeno < 1.12.0 - Trainer+ Section and Age Group Reassignment via Quick Edit 11.10.2026
CVE-2026-107694 Dokan < 5.2.0 - Vendor+ Cross-Vendor Commission Settings Disclosure via Commission REST Endpoint 11.10.2026
CVE-2026-108540 OpenSpug File Transfer transfer os command injection 11.10.2026
CVE-2026-12980 Post Snippets <= 4.2.4 - Contributor+ Stored XSS via Snippet Variable 11.10.2026
CVE-2026-14854 WooCommerce Bookings < 3.11.0 - Unauthenticated Denial of Service 11.10.2026
CVE-2026-81153 Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Overlay Effect Meta 11.10.2026
CVE-2026-81154 Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Alt Text 11.10.2026
CVE-2026-81155 Robo Gallery < 5.2.6 - Author+ Stored XSS via Gallery Search Label 11.10.2026
CVE-2026-81156 Robo Gallery < 5.2.6 - Contributor+ Stored XSS via Gallery Settings 11.10.2026
CVE-2026-81420 Tcard WP <= 1.8.0 - Unauthenticated SQLi via group_id Parameter 11.10.2026
CVE-2026-81649 Fundiin <= 3.4.0 - Unauthenticated Payment Gateway Settings Update and Credential Disclosure 11.10.2026
CVE-2026-84251 click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Arbitrary Options Update 11.10.2026
CVE-2026-84252 click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Arbitrary Options Update 11.10.2026
CVE-2026-84253 click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Arbitrary Options Update 11.10.2026
CVE-2026-84254 click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Arbitrary Options Update 11.10.2026
CVE-2026-84258 click5 CRM add-on to Ninja Forms <= 1.0.1 - Unauthenticated Stored XSS via post_notifications 11.10.2026
CVE-2026-84259 click5 CRM add-on to WPForms <= 1.0.3 - Unauthenticated Stored XSS via post_notifications 11.10.2026
CVE-2026-84260 click5 CRM add-on to Gravity Forms <= 1.0.3 - Unauthenticated Stored XSS via post_notifications 11.10.2026
CVE-2026-84261 click5 CRM add-on to Contact Form 7 <= 1.0.4 - Unauthenticated Stored XSS via post_notifications 11.10.2026
CVE-2026-84734 Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pass' Parameter 11.10.2026
CVE-2026-84737 Freeton WP <= 1.0.0 - Unauthenticated Account Takeover via 'secod' Parameter 11.10.2026
CVE-2026-85118 AI Content Generator Marketing <= 1.0.0 - Unauthenticated Privilege Escalation via Arbitrary Option Update and Deletion 11.10.2026
CVE-2026-85121 Insurify <= 1.0 - Unauthenticated Arbitrary Option Creation and Overwrite via saveemailtemplatedesign 11.10.2026
CVE-2026-85126 Crowdfundly <= 2.2.2 - Crowdfundly Manager+ Privilege Escalation 11.10.2026
CVE-2026-86706 Quick quotes <= 1.0.0 - Unauthenticated Integer-Value Option Update 11.10.2026
CVE-2026-86717 Insurify <= 1.0 - Unauthenticated Arbitrary Option Deletion via removeimg_popup 11.10.2026
CVE-2026-86798 HootBoard <= 3.1.4 - Unauthenticated Stored XSS via Board Configuration REST Endpoint 11.10.2026
CVE-2026-87760 Web Vitals Tracking <= 5.4.2 - Unauthenticated Stored XSS via Tracking Beacon Metric Name 11.10.2026
CVE-2026-87761 Adwised Web Push Notification <= 2.5.7 - Subscriber+ Stored XSS via Pop-up Settings 11.10.2026
CVE-2026-87762 Adwised Web Push Notification <= 2.5.7 - Unauthenticated Stored XSS via Secret Key Type Juggling 11.10.2026
CVE-2026-87764 BuddyPress Instant Chat <= 1.6 - Unauthenticated Stored XSS via Chat Message 11.10.2026
CVE-2026-88785 Simple Membership < 4.8.3 - Newly Registered Member Password Disclosure via URL Query String 11.10.2026
CVE-2026-88826 SmugMug Embed <= 3.13 - Unauthenticated Stored XSS via saveSelectedAlbums 11.10.2026
CVE-2026-88827 Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords 11.10.2026
CVE-2026-88903 Topcontent <= 1.2.1 - Unauthenticated Stored XSS via Content Webhook 11.10.2026
CVE-2026-88905 KeyWord Collector <= 1.4 - Unauthenticated Stored XSS and Settings Update via WPKeyWordSettings 11.10.2026
CVE-2026-88930 Social Web Suite <= 4.1.12 - Unauthenticated Blind SQLi via Unset Shared Secret 11.10.2026
CVE-2026-89195 Site Setup Wizard <= 1.5.8 - Unauthenticated SQLi via ssw_check_admin_email_exists 11.10.2026
CVE-2026-89213 Llavero.io <= 0.1.4 - Unauthenticated Blind SQLi via 'cill_login' Parameter 11.10.2026
CVE-2026-89214 WpCues Basic Quiz <= 1.6.5 - Unauthenticated SQLi via Quiz Result Submission 11.10.2026
CVE-2026-89232 RecordBrowser <= 1.1.7 - Unauthenticated SQLi via 'recordid' Parameter 11.10.2026
CVE-2026-89234 WP-Partner <= 1.2.1 - Unauthenticated SQLi via 'id' Parameter 11.10.2026
CVE-2026-89283 WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite 11.10.2026
CVE-2026-89285 Datalist it <= 0.0.3 - Unauthenticated SQLi via dli_fronted_action 11.10.2026
CVE-2026-89287 ASPL Product Quotation <= 1.1.0 - Unauthenticated SQLi via 'quote_id' Parameter 11.10.2026
CVE-2026-89297 Loja Automática <= 1.0.0 - Unauthenticated SQLi via 'id' Parameter 11.10.2026
CVE-2026-89299 WP Verify API <= 1.0.0 - Unauthenticated SQLi via 'verify' Parameter 11.10.2026
CVE-2026-89302 Post Voting System <= 1.0 - Unauthenticated SQLi via 'id' Parameter 11.10.2026
CVE-2026-89304 Paymendo Bank Transfer <= 1.1 - Unauthenticated Blind SQLi via 'paymendo_bank_transfer_completed_payment' Parameter 11.10.2026
CVE-2026-89305 Paymendo Bank Transfer <= 1.1 - Subscriber+ SQLi via 'orderBy' Parameter 11.10.2026
CVE-2026-91829 Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter 11.10.2026
CVE-2026-93550 Veeqo for WooCommerce <= 2.2.8 - Subscriber+ Arbitrary File Upload via start_veeqo_connection_process 11.10.2026
CVE-2026-94235 Simple User Registration <= 6.9 - Subscriber+ Arbitrary Email Sending via wpr_send_email_to_user 11.10.2026
CVE-2026-96227 Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload 11.10.2026
CVE-2026-97183 WP-Invoice <= 4.3.1 - Subscriber+ User PII Disclosure via Unprotected AJAX Handlers 11.10.2026
CVE-2026-108539 GPAC MP4Box filter_queue.c gf_fq_pop use after free 11.10.2026
CVE-2026-108538 GPAC MP4Box os_thread.c gf_mx_v use after free 11.10.2026
CVE-2026-108523 Studio-Saelix Sencho git-sources Browse API Endpoint outboundTarget.ts server-side request forgery 11.10.2026
CVE-2026-108522 Studio-Saelix Sencho Login Endpoint login improper authentication 11.10.2026
CVE-2026-108521 Studio-Saelix Sencho Add Remote Node API Endpoint validation.ts isValidRemoteUrl server-side request forgery 11.10.2026
CVE-2026-108688 Eladmin through 2.7 Missing Authorization via /api/localStorage/pictures Upload 11.10.2026
CVE-2026-108689 Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST /chat/send 11.10.2026
CVE-2026-108690 mall4j through 4.0 Operator Precedence Error Exposes Other Users' Cart Items via /p/shopCart/expiryProdList 11.10.2026
CVE-2026-108691 mall4j through 4.0 Operator Precedence Error Deletes Other Users' Cart Items via /p/shopCart/cleanExpiryProdList 11.10.2026
CVE-2026-108692 1Panel-dev CordysCRM 1.9.0 before 1.9.2 Missing Authorization via /field/source Endpoints 11.10.2026
CVE-2026-108693 ImageMagick through 7.1.2-33 and 6.9.13-58 Uncontrolled Search Path via Ghostscript Delegate 11.10.2026
CVE-2026-108694 ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter 11.10.2026
CVE-2026-108695 MultiVendorX through 5.0.19 Incorrect Authorization via Settings REST Endpoint 11.10.2026
CVE-2026-108696 CoreShop through 1.5.5 Authorization Bypass via OrderController OrderConfirm and SendReship 11.10.2026
CVE-2026-108700 1Panel-dev CordysCRM before 1.9.2 Missing Authorization via /field/source/business-title 11.10.2026
CVE-2026-108701 1Panel-dev CordysCRM before 1.9.2 Missing Authorization via POST /contract/sort 11.10.2026
CVE-2026-108702 CordysCRM through 1.9.3 Missing Authorization and Blind SSRF via Webhook Test 11.10.2026
CVE-2026-108703 CordysCRM through 1.9.3 Missing Authorization via /approval-resource/push 11.10.2026
CVE-2026-108704 CordysCRM through 1.9.3 Authorization Bypass via Follow-Up Record Add Endpoints 11.10.2026
CVE-2026-108705 CordysCRM through 1.9.3 Missing Authorization via /custom-form/data/import 11.10.2026
CVE-2026-108706 eladmin through commit 55fbf70 Missing Authorization via S3 Storage Download Endpoint 11.10.2026
CVE-2026-108707 Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect 11.10.2026
CVE-2026-108708 Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUtil 11.10.2026
CVE-2026-104841 10.10.2026
CVE-2026-108605 JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/edit Endpoint 10.10.2026
CVE-2026-108606 JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById 10.10.2026
CVE-2026-108607 JeecgBoot through 3.9.5 IDOR via deleteVideoRecord userId Parameter 10.10.2026
CVE-2026-108608 JeecgBoot through 3.9.5 IDOR via deleteVoiceRecord userId Parameter 10.10.2026
CVE-2026-108609 JeecgBoot through 3.9.5 IDOR via /airag/voice/listByUser userId Parameter 10.10.2026
CVE-2026-108610 JeecgBoot through 3.9.5 Missing Authorization via /airag/word/edit Endpoint 10.10.2026
CVE-2026-108611 JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint 10.10.2026
CVE-2026-108612 JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch 10.10.2026
CVE-2026-108613 JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint 10.10.2026
CVE-2026-108614 JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/exportXls 10.10.2026
CVE-2026-108615 JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete 10.10.2026
CVE-2026-108616 JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/deleteBatch 10.10.2026
CVE-2026-108617 JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate/add Endpoint 10.10.2026
CVE-2026-108618 JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Edit Endpoint 10.10.2026
CVE-2026-108619 JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint 10.10.2026
CVE-2026-108620 JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch 10.10.2026
CVE-2026-108621 JeecgBoot through 3.9.5 Missing Authorization via /sys/position/edit 10.10.2026
CVE-2026-108622 JeecgBoot through 3.9.5 Missing Authorization via /sys/log/delete Endpoint 10.10.2026
CVE-2026-108623 JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch 10.10.2026
CVE-2026-108624 JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint 10.10.2026
CVE-2026-108625 JeecgBoot through 3.9.5 Missing Authorization via sysMessage Edit Endpoint 10.10.2026
CVE-2026-108626 JeecgBoot through 3.9.5 Missing Authorization via sysMessage queryById Endpoint 10.10.2026
CVE-2026-108627 JeecgBoot through 3.9.5 Missing Authorization via /sys/role/datarule Endpoint 10.10.2026
CVE-2026-108628 JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint 10.10.2026
CVE-2026-108629 JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission datarule Endpoint 10.10.2026
CVE-2026-108630 JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/edit 10.10.2026
CVE-2026-108631 JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/delete 10.10.2026
CVE-2026-108632 JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission queryById Endpoint 10.10.2026
CVE-2026-108633 JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/add 10.10.2026
CVE-2026-108634 JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint 10.10.2026
CVE-2026-108635 JeecgBoot through 3.9.5 Missing Authorization via getDepartmentHead Endpoint 10.10.2026
CVE-2026-108636 JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepart/appImportExcel 10.10.2026
CVE-2026-108637 JeecgBoot through 3.9.5 Missing Authorization via deleteUserGroupBatch Endpoint 10.10.2026
CVE-2026-108638 JeecgBoot through 3.9.5 Missing Authorization via /sys/user/deleteGroupUser 10.10.2026
CVE-2026-108639 JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/deletePhysic/{id} 10.10.2026
CVE-2026-108640 JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/queryById 10.10.2026
CVE-2026-108641 JeecgBoot through 3.9.5 IDOR via /sys/sysAnnouncementSend/getOne 10.10.2026
CVE-2026-108642 JeecgBoot through 3.9.5 IDOR via PUT /sys/sysAnnouncementSend/edit 10.10.2026
CVE-2026-108643 JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch 10.10.2026
CVE-2026-108644 JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete 10.10.2026
CVE-2026-108645 JeecgBoot through 3.9.5 Missing Authorization via /sys/category/edit 10.10.2026
CVE-2026-108646 JeecgBoot through 3.9.5 Missing Authorization via /sys/category/importExcel 10.10.2026
CVE-2026-108647 JeecgBoot through 3.9.5 Missing Authorization via /sys/checkRule/importExcel 10.10.2026
CVE-2026-108648 JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint 10.10.2026
CVE-2026-108649 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRolesById 10.10.2026
CVE-2026-108650 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserPermissionSet 10.10.2026
CVE-2026-108651 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getRolesByUserId 10.10.2026
CVE-2026-108652 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/updateAvatar 10.10.2026
CVE-2026-108653 JeecgBoot through 3.9.5 Missing Authorization via GET /openapi/list 10.10.2026
CVE-2026-108654 JeecgBoot through 3.9.5 Missing Authorization via /sys/oss/file/queryById 10.10.2026
CVE-2026-108655 JeecgBoot through 3.9.5 Missing Authorization via /sys/quartzJob/queryById 10.10.2026
CVE-2026-108656 JeecgBoot through 3.9.5 Missing Authorization via getTenantPackApplyUsers Endpoint 10.10.2026
CVE-2026-108657 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply 10.10.2026
CVE-2026-108658 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/queryTenantAuthInfo 10.10.2026
CVE-2026-108659 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/listPackByTenantUserId 10.10.2026
CVE-2026-108660 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/updateApplyStatus 10.10.2026
CVE-2026-108661 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant 10.10.2026
CVE-2026-108662 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteTenantPackUser 10.10.2026
CVE-2026-108663 JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteApply 10.10.2026
CVE-2026-108664 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/queryById 10.10.2026
CVE-2026-108665 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/edit 10.10.2026
CVE-2026-108666 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch 10.10.2026
CVE-2026-108667 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/revertRecycleBin 10.10.2026
CVE-2026-108668 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin 10.10.2026
CVE-2026-108669 JeecgBoot through 3.9.5 Missing Authorization via /airag/knowledge/embedding/search 10.10.2026
CVE-2026-108670 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/experiment 10.10.2026
CVE-2026-108671 JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById 10.10.2026
CVE-2026-108672 JeecgBoot through 3.9.5 Authorization Bypass via /airag/video/listByUser 10.10.2026
CVE-2026-108673 JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/exportXls 10.10.2026
CVE-2026-108674 JeecgBoot through 3.9.5 Missing Authorization via /openapi/queryById 10.10.2026
CVE-2026-108675 JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/editIzTop 10.10.2026
CVE-2026-108676 JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/downLoadFiles 10.10.2026
CVE-2026-108677 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName 10.10.2026
CVE-2026-108678 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRoles 10.10.2026
CVE-2026-108679 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusAnnouncement 10.10.2026
CVE-2026-108680 JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendTemplateAnnouncement 10.10.2026