| CVE-2026-104845 |
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization |
02.10.2026 |
7.5 |
| CVE-2026-104907 |
MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler |
02.10.2026 |
|
| CVE-2026-104908 |
MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging |
02.10.2026 |
|
| CVE-2026-104844 |
PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion |
02.10.2026 |
5.9 |
| CVE-2026-104906 |
MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output |
02.10.2026 |
|
| CVE-2026-51911 |
|
02.10.2026 |
|
| CVE-2026-51914 |
|
02.10.2026 |
|
| CVE-2026-51915 |
|
02.10.2026 |
|
| CVE-2026-51916 |
|
02.10.2026 |
|
| CVE-2026-51917 |
|
02.10.2026 |
|
| CVE-2026-51918 |
|
02.10.2026 |
|
| CVE-2026-51922 |
|
02.10.2026 |
|
| CVE-2026-104843 |
uv: Path traversal on Windows through wheel extraction |
02.10.2026 |
|
| CVE-2026-51898 |
|
02.10.2026 |
|
| CVE-2026-51899 |
|
02.10.2026 |
|
| CVE-2026-51901 |
|
02.10.2026 |
|
| CVE-2026-51904 |
|
02.10.2026 |
|
| CVE-2026-51906 |
|
02.10.2026 |
|
| CVE-2026-51907 |
|
02.10.2026 |
|
| CVE-2026-104900 |
MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index |
02.10.2026 |
|
| CVE-2026-104901 |
MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server |
02.10.2026 |
|
| CVE-2026-94483 |
Next.js: Server-Side Request Forgery in Image Optimization |
02.10.2026 |
|
| CVE-2026-94484 |
Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service |
02.10.2026 |
|
| CVE-2026-94485 |
Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass |
02.10.2026 |
|
| CVE-2026-94486 |
Next.js: Information disclosure in the Next.js development server's Model Context Protocol endpoint |
02.10.2026 |
|
| CVE-2026-94543 |
Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications |
02.10.2026 |
|
| CVE-2026-94544 |
Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages |
02.10.2026 |
|
| CVE-2026-104638 |
onetwothreeneth HospitalManagementSystem sessions.php improper authentication |
02.10.2026 |
|
| CVE-2026-104637 |
onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted upload |
02.10.2026 |
|
| CVE-2026-32584 |
WordPress Smart One Click Setup – Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure vulnerability |
02.10.2026 |
5.3 |
| CVE-2026-32585 |
WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerability |
02.10.2026 |
6.5 |
| CVE-2026-39439 |
WordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerability |
02.10.2026 |
6.5 |
| CVE-2026-39444 |
WordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object References (IDOR) vulnerability |
02.10.2026 |
5.4 |
| CVE-2026-39600 |
WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Forwards vulnerability |
02.10.2026 |
4.7 |
| CVE-2026-39601 |
WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability |
02.10.2026 |
3.7 |
| CVE-2026-39717 |
WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability |
02.10.2026 |
4.3 |
| CVE-2026-104625 |
CodeAstro Simple Loan Management System index.php sql injection |
02.10.2026 |
|
| CVE-2026-90970 |
Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway |
02.10.2026 |
9.9 |
| CVE-2026-104026 |
|
02.10.2026 |
|
| CVE-2026-5782 |
Reflected XSS in Loglama.NET's TurkHotspot |
02.10.2026 |
5.2 |
| CVE-2026-104614 |
CodeAstro Simple Pharmacy Management System delete.php sql injection |
02.10.2026 |
|
| CVE-2026-94422 |
xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape |
02.10.2026 |
|
| CVE-2026-19652 |
Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter |
02.10.2026 |
9.8 |
| CVE-2026-93875 |
JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter |
02.10.2026 |
7.2 |
| CVE-2026-104613 |
CodeAstro Simple Pharmacy Management System view.php sql injection |
02.10.2026 |
|
| CVE-2026-104721 |
Logback: Incomplete protection against CVE-2026-19880 |
02.10.2026 |
|
| CVE-2026-85215 |
SQL Injection in GG Soft's Paperwork |
02.10.2026 |
7.1 |
| CVE-2026-104612 |
SourceCodester Student Result Management System Announcement new_announcement.php cross site scripting |
02.10.2026 |
|
| CVE-2026-61374 |
Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit |
02.10.2026 |
|
| CVE-2026-63772 |
Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count |
02.10.2026 |
|
| CVE-2026-66054 |
Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize |
02.10.2026 |
|
| CVE-2026-66055 |
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TJSONProtocol accepts a single JSON string/number exceeding the configured size limit (multi-language) |
02.10.2026 |
|
| CVE-2026-102797 |
WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSRF) vulnerability |
02.10.2026 |
6.4 |
| CVE-2026-102798 |
WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulnerability |
02.10.2026 |
6.5 |
| CVE-2026-104733 |
User Impersonation/Authorization Bypass in XMPP Server ejabberd |
02.10.2026 |
|
| CVE-2026-11795 |
User Enumeration in Softtr's E-Commerce Pack |
02.10.2026 |
5.3 |
| CVE-2026-66081 |
Apache Thrift: c_glib read_message_begin leaves output parameters unset for non-versioned messages |
02.10.2026 |
|
| CVE-2026-66331 |
Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize |
02.10.2026 |
|
| CVE-2026-66837 |
Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length |
02.10.2026 |
|
| CVE-2026-66858 |
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml) |
02.10.2026 |
|
| CVE-2026-66859 |
Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route |
02.10.2026 |
|
| CVE-2026-83632 |
Apache Thrift: C++ THttpTransport grows its line buffer without bound |
02.10.2026 |
|
| CVE-2026-83663 |
Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go) |
02.10.2026 |
|
| CVE-2026-104610 |
Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow |
02.10.2026 |
|
| CVE-2026-104611 |
Tenda AC9 POST Request fast_setting_internet_set stack-based overflow |
02.10.2026 |
|
| CVE-2026-83745 |
Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from the declared length, not the bytes received (Node.js, D) |
02.10.2026 |
|
| CVE-2026-85209 |
IDOR in AVEZ Electronics's LMS |
02.10.2026 |
6.5 |
| CVE-2026-85476 |
Apache Thrift: c_glib `read_all` spins when the underlying read returns 0 |
02.10.2026 |
|
| CVE-2026-94654 |
Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all fds after an 8192-byte-boundary frame |
02.10.2026 |
|
| CVE-2026-94655 |
Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound and are quadratic |
02.10.2026 |
|
| CVE-2026-94656 |
Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound |
02.10.2026 |
|
| CVE-2026-94657 |
Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound |
02.10.2026 |
|
| CVE-2026-94658 |
Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on every read (quadratic) |
02.10.2026 |
|
| CVE-2026-96277 |
Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protocol exception |
02.10.2026 |
|
| CVE-2026-96286 |
Apache Thrift: Perl servers end `serve()` when serving one connection fails |
02.10.2026 |
|
| CVE-2026-96287 |
Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice the remaining buffer on every call (quadratic) |
02.10.2026 |
|
| CVE-2026-96289 |
Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBinary`) have no recursion-depth guard |
02.10.2026 |
|
| CVE-2026-94646 |
Apache Thrift: Node.js `server.js` ends the process on any per-connection error (+ two triggers) |
02.10.2026 |
|
| CVE-2026-94648 |
Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound |
02.10.2026 |
|
| CVE-2026-94652 |
Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the processor throws before calling back |
02.10.2026 |
|
| CVE-2026-94653 |
Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic) |
02.10.2026 |
|
| CVE-2026-104609 |
onetwothreeneth HospitalManagementSystem edit_accounts.php get sql injection |
02.10.2026 |
|
| CVE-2026-92834 |
Apache Thrift: C++ WebSocket server transport does not read a full request length |
02.10.2026 |
|
| CVE-2026-94636 |
Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size limit once the limit is exactly used up |
02.10.2026 |
|
| CVE-2026-94637 |
Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZLIB frame |
02.10.2026 |
|
| CVE-2026-94638 |
Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxStringSize` |
02.10.2026 |
|
| CVE-2026-103762 |
SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints |
02.10.2026 |
|
| CVE-2026-103763 |
SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo |
02.10.2026 |
|
| CVE-2026-104410 |
SiYuan before 3.8.5 Information Disclosure via /api/export/preview |
02.10.2026 |
|
| CVE-2026-104411 |
Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads |
02.10.2026 |
|
| CVE-2026-104412 |
Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment |
02.10.2026 |
|
| CVE-2026-104413 |
Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images |
02.10.2026 |
|
| CVE-2026-104414 |
Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses |
02.10.2026 |
|
| CVE-2026-104415 |
Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API |
02.10.2026 |
|
| CVE-2026-104416 |
Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API |
02.10.2026 |
|
| CVE-2026-104417 |
Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting |
02.10.2026 |
|
| CVE-2026-104418 |
Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files |
02.10.2026 |
|
| CVE-2026-104419 |
Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes |
02.10.2026 |
|
| CVE-2026-104420 |
Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks |
02.10.2026 |
|
| CVE-2026-104421 |
Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout |
02.10.2026 |
|
| CVE-2026-104422 |
Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite |
02.10.2026 |
|
| CVE-2026-104423 |
Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification |
02.10.2026 |
|
| CVE-2026-104424 |
Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate |
02.10.2026 |
|
| CVE-2026-104425 |
Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions |
02.10.2026 |
|
| CVE-2026-104426 |
Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check |
02.10.2026 |
|
| CVE-2026-104427 |
Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry |
02.10.2026 |
|
| CVE-2026-104428 |
Zebra before 11.0.0 Denial of Service via getblock Verbosity 2 |
02.10.2026 |
|
| CVE-2026-104429 |
Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages |
02.10.2026 |
|
| CVE-2026-104430 |
Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount |
02.10.2026 |
|
| CVE-2026-104431 |
Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification |
02.10.2026 |
|
| CVE-2026-104432 |
Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response |
02.10.2026 |
|
| CVE-2026-104434 |
Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC |
02.10.2026 |
|
| CVE-2026-104435 |
Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output |
02.10.2026 |
|
| CVE-2026-104436 |
Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length |
02.10.2026 |
|
| CVE-2026-104437 |
Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling |
02.10.2026 |
|
| CVE-2026-104438 |
YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages Actions |
02.10.2026 |
|
| CVE-2026-104439 |
YesWiki before 4.6.7 User Enumeration via Lost-Password Flow |
02.10.2026 |
|
| CVE-2026-104440 |
YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter |
02.10.2026 |
|
| CVE-2026-104441 |
YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action |
02.10.2026 |
|
| CVE-2026-104442 |
YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action |
02.10.2026 |
|
| CVE-2026-104443 |
YesWiki before 4.6.7 Scope Bypass via Triples Delete API |
02.10.2026 |
|
| CVE-2026-104444 |
YesWiki before 4.6.7 Authorization Bypass via Comments API editComment |
02.10.2026 |
|
| CVE-2026-104445 |
YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing |
02.10.2026 |
|
| CVE-2026-104446 |
YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler |
02.10.2026 |
|
| CVE-2026-104447 |
YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction |
02.10.2026 |
|
| CVE-2026-104448 |
YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler |
02.10.2026 |
|
| CVE-2026-104449 |
YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche |
02.10.2026 |
|
| CVE-2026-104450 |
YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action |
02.10.2026 |
|
| CVE-2026-104451 |
YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler |
02.10.2026 |
|
| CVE-2026-104452 |
YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler |
02.10.2026 |
|
| CVE-2026-104453 |
YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action |
02.10.2026 |
|
| CVE-2026-104454 |
YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint |
02.10.2026 |
|
| CVE-2026-104455 |
YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action |
02.10.2026 |
|
| CVE-2026-104456 |
YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username |
02.10.2026 |
|
| CVE-2026-104457 |
YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter |
02.10.2026 |
|
| CVE-2026-104458 |
YesWiki before 4.6.7 SSRF Guard Bypass via IPv6 Transition Addresses |
02.10.2026 |
|
| CVE-2026-104459 |
YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle |
02.10.2026 |
|
| CVE-2026-104460 |
YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch |
02.10.2026 |
|
| CVE-2026-104461 |
YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField |
02.10.2026 |
|
| CVE-2026-104462 |
YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter |
02.10.2026 |
|
| CVE-2026-104463 |
YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox |
02.10.2026 |
|
| CVE-2026-104464 |
YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter |
02.10.2026 |
|
| CVE-2026-104465 |
YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler |
02.10.2026 |
|
| CVE-2026-104466 |
YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute |
02.10.2026 |
|
| CVE-2026-104467 |
YesWiki before 4.6.7 Authorization Bypass via Public API Mode |
02.10.2026 |
|
| CVE-2026-104468 |
YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction |
02.10.2026 |
|
| CVE-2026-104469 |
YesWiki before 4.6.7 Session Fixation via Login in AuthController.php |
02.10.2026 |
|
| CVE-2026-104470 |
YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action |
02.10.2026 |
|
| CVE-2026-104471 |
YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import |
02.10.2026 |
|
| CVE-2026-104472 |
YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler |
02.10.2026 |
|
| CVE-2026-104473 |
YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages |
02.10.2026 |
|
| CVE-2026-85086 |
Apache Thrift: Perl TLS client disables certificate verification by default |
02.10.2026 |
|
| CVE-2026-85087 |
Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op |
02.10.2026 |
|
| CVE-2026-85088 |
Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match |
02.10.2026 |
|
| CVE-2026-86535 |
Apache Thrift: A JSON member name can stall the Node server's event loop indefinitely |
02.10.2026 |
|
| CVE-2026-86536 |
Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can replace a decoded object's prototype in generated JavaScript |
02.10.2026 |
|
| CVE-2026-86537 |
Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service |
02.10.2026 |
|
| CVE-2026-87117 |
Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing container-element spec |
02.10.2026 |
|
| CVE-2026-90440 |
Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service |
02.10.2026 |
|
| CVE-2026-82458 |
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available |
02.10.2026 |
|
| CVE-2026-82459 |
Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process |
02.10.2026 |
|
| CVE-2026-61373 |
Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation |
02.10.2026 |
|
| CVE-2026-96288 |
Apache Thrift: Erlang generated struct reads have no recursion-depth guard (unbounded memory) |
02.10.2026 |
|
| CVE-2026-96292 |
Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic) |
02.10.2026 |
|
| CVE-2026-96294 |
Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection |
02.10.2026 |
|
| CVE-2026-94642 |
Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception |
02.10.2026 |
|
| CVE-2026-96990 |
Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound |
02.10.2026 |
|
| CVE-2026-94644 |
Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound |
02.10.2026 |
|
| CVE-2026-94645 |
Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as an unbounded loop bound |
02.10.2026 |
|
| CVE-2026-94650 |
Apache Thrift: c_glib generated struct readers have no recursion-depth guard (native stack exhaustion) |
02.10.2026 |
|
| CVE-2026-85483 |
Apache Thrift: c_glib TZlibTransport reports a full read after a premature stream end |
02.10.2026 |
|
| CVE-2026-85493 |
Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting to any depth the stack allows (Dart, Java ME) |
02.10.2026 |
|
| CVE-2026-85494 |
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language) |
02.10.2026 |
|
| CVE-2026-94651 |
Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a connection on a pre-auth parse error |
02.10.2026 |
|
| CVE-2026-104606 |
itsourcecode Online Admission System Project confirm.php sql injection |
02.10.2026 |
|
| CVE-2026-91135 |
Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) |
02.10.2026 |
|
| CVE-2026-97876 |
Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address |
02.10.2026 |
6.4 |
| CVE-2026-59666 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59667 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59668 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-86325 |
|
02.10.2026 |
|
| CVE-2026-86326 |
|
02.10.2026 |
|
| CVE-2026-91137 |
Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements |
02.10.2026 |
|
| CVE-2026-93925 |
Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow on a negative protocol id |
02.10.2026 |
|
| CVE-2026-93926 |
Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on the error path |
02.10.2026 |
|
| CVE-2026-94633 |
Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned name length |
02.10.2026 |
|
| CVE-2026-103877 |
Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements |
02.10.2026 |
|
| CVE-2026-103878 |
Apache Directory LDAP API: Injection of plaintext responses during StartTLS |
02.10.2026 |
|
| CVE-2026-103880 |
Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwords |
02.10.2026 |
|
| CVE-2026-103885 |
Apache Directory LDAP API: Denial of service via crafted telephone number values |
02.10.2026 |
|
| CVE-2026-59662 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59663 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59664 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59665 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-94634 |
Apache Thrift: Python `TJSONProtocol` has a string length limit that is off by default |
02.10.2026 |
|
| CVE-2026-104403 |
WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability |
02.10.2026 |
5.3 |
| CVE-2026-103552 |
Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder |
02.10.2026 |
|
| CVE-2026-59659 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59660 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59661 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-95662 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-94180 |
WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability |
02.10.2026 |
4.3 |
| CVE-2026-94405 |
WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability |
02.10.2026 |
5.3 |
| CVE-2026-94639 |
Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget) |
02.10.2026 |
|
| CVE-2026-102731 |
Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode |
02.10.2026 |
|
| CVE-2026-59672 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59673 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-80298 |
SQL Injection in HAVELSAN's Sef - AI Chatbot Platform |
02.10.2026 |
8.8 |
| CVE-2026-85492 |
All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname |
02.10.2026 |
6.1 |
| CVE-2026-87920 |
W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
02.10.2026 |
7.2 |
| CVE-2026-94541 |
WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter |
02.10.2026 |
9.8 |
| CVE-2026-94635 |
Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name |
02.10.2026 |
|
| CVE-2026-97652 |
WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key |
02.10.2026 |
6.1 |
| CVE-2026-59670 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-59671 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-80337 |
Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform |
02.10.2026 |
5.3 |
| CVE-2026-80443 |
Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform |
02.10.2026 |
7.4 |
| CVE-2026-80464 |
API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform |
02.10.2026 |
4.9 |
| CVE-2026-95512 |
Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader |
02.10.2026 |
|
| CVE-2026-59669 |
Multiple vulnerabilities in the Repasat application |
02.10.2026 |
|
| CVE-2026-91784 |
Argument Injection leading to arbitrary process termination in gotop |
02.10.2026 |
|
| CVE-2026-18036 |
NTRU leaks private key information by reducing secret values with a non-constant-time integer division |
02.10.2026 |
|
| CVE-2026-100107 |
Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) |
02.10.2026 |
7.2 |
| CVE-2026-100182 |
Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor |
02.10.2026 |
7.2 |
| CVE-2026-102002 |
Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget |
02.10.2026 |
3.1 |
| CVE-2026-102772 |
CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field |
02.10.2026 |
7.2 |
| CVE-2026-103426 |
Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter |
02.10.2026 |
7.2 |
| CVE-2026-12951 |
MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter |
02.10.2026 |
6.5 |
| CVE-2026-17508 |
Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points |
02.10.2026 |
|
| CVE-2026-93756 |
Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview |
02.10.2026 |
7.2 |
| CVE-2026-93880 |
Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder |
02.10.2026 |
6.1 |
| CVE-2026-94432 |
Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter |
02.10.2026 |
5.3 |
| CVE-2026-95670 |
No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect |
02.10.2026 |
7.2 |
| CVE-2026-95817 |
DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
02.10.2026 |
7.2 |
| CVE-2026-96566 |
Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter |
02.10.2026 |
7.2 |
| CVE-2026-96567 |
MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta) |
02.10.2026 |
7.2 |
| CVE-2026-96578 |
GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
02.10.2026 |
7.2 |
| CVE-2026-96647 |
Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter |
02.10.2026 |
6.4 |
| CVE-2026-96871 |
Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter |
02.10.2026 |
7.2 |
| CVE-2026-97336 |
CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field Type |
02.10.2026 |
7.2 |
| CVE-2026-97338 |
Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name |
02.10.2026 |
6.4 |
| CVE-2026-97342 |
JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action |
02.10.2026 |
7.2 |
| CVE-2026-97634 |
Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter |
02.10.2026 |
6.5 |
| CVE-2026-97637 |
JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response |
02.10.2026 |
9.8 |
| CVE-2026-97641 |
Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
02.10.2026 |
7.2 |
| CVE-2026-97663 |
Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name |
02.10.2026 |
7.2 |
| CVE-2026-103600 |
Unbounded ASN.1 nesting depth causes process-terminating stack overflow |
02.10.2026 |
|
| CVE-2026-103601 |
CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag check |
02.10.2026 |
|
| CVE-2026-103602 |
Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts |
02.10.2026 |
|
| CVE-2026-103603 |
Unbounded HSS public key level count allows huge array allocation during signature verification |
02.10.2026 |
|
| CVE-2026-103604 |
Quadratic-time escaping when converting X.509 distinguished names to strings |
02.10.2026 |
|
| CVE-2026-17507 |
MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range sender |
02.10.2026 |
|
| CVE-2026-63570 |
Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links |
02.10.2026 |
|
| CVE-2026-63571 |
Attribute certificate path validation does not verify the attribute certificate's signature |
02.10.2026 |
|
| CVE-2026-63572 |
Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files |
02.10.2026 |
|
| CVE-2026-63573 |
Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap |
02.10.2026 |
|
| CVE-2026-63574 |
Unbounded allocation from OpenPGP signature and user attribute subpacket lengths |
02.10.2026 |
|
| CVE-2026-63575 |
PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count |
02.10.2026 |
|
| CVE-2026-63576 |
URI name constraints checked against a mis-parsed host |
02.10.2026 |
|
| CVE-2026-63577 |
Name Constraints bypass: directoryName constraint matched at any position in the DN instead of as a prefix |
02.10.2026 |
|
| CVE-2026-63578 |
Unbounded PBE iteration count when decrypting PKCS#8 private keys |
02.10.2026 |
|
| CVE-2026-102565 |
BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter |
02.10.2026 |
7.2 |
| CVE-2026-13413 |
CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL Match |
02.10.2026 |
5.3 |
| CVE-2026-15999 |
AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication |
02.10.2026 |
|
| CVE-2026-16000 |
KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used |
02.10.2026 |
|
| CVE-2026-16001 |
IesEngine stream-mode MAC forgery via length-dependent KDF split |
02.10.2026 |
|
| CVE-2026-1661 |
WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection |
02.10.2026 |
4.3 |
| CVE-2026-63566 |
DTLS handshake reassembler allocates buffer from unchecked 24-bit length |
02.10.2026 |
|
| CVE-2026-63567 |
IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) |
02.10.2026 |
|
| CVE-2026-63568 |
Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion |
02.10.2026 |
|
| CVE-2026-63569 |
MTI/A0 DHAgreement does not validate the peer's ephemeral value |
02.10.2026 |
|
| CVE-2026-79618 |
WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form |
02.10.2026 |
4.3 |
| CVE-2026-84740 |
The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter |
02.10.2026 |
6.5 |
| CVE-2026-85005 |
Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization |
02.10.2026 |
5.4 |
| CVE-2026-90952 |
WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API |
02.10.2026 |
5.3 |
| CVE-2026-90987 |
Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price |
02.10.2026 |
5.3 |
| CVE-2026-91020 |
WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount |
02.10.2026 |
5.3 |
| CVE-2026-92924 |
Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data |
02.10.2026 |
5.4 |
| CVE-2026-97219 |
MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter |
02.10.2026 |
4.3 |
| CVE-2026-93029 |
|
02.10.2026 |
|
| CVE-2026-93697 |
|
02.10.2026 |
|
| CVE-2026-93698 |
|
02.10.2026 |
|
| CVE-2026-13718 |
Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content |
02.10.2026 |
|
| CVE-2026-81740 |
Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback |
02.10.2026 |
|
| CVE-2026-85004 |
Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect |
02.10.2026 |
|
| CVE-2026-85016 |
Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter |
02.10.2026 |
|
| CVE-2026-90988 |
Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum |
02.10.2026 |
|
| CVE-2026-91022 |
Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color |
02.10.2026 |
|
| CVE-2026-91023 |
Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured |
02.10.2026 |
|
| CVE-2026-91828 |
OMGF < 6.3.11 - Unauthenticated DoS via do_optimize |
02.10.2026 |
|
| CVE-2026-94298 |
BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter |
02.10.2026 |
|
| CVE-2026-97317 |
Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page |
02.10.2026 |
|
| CVE-2026-97318 |
Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter |
02.10.2026 |
|
| CVE-2026-15896 |
Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter |
02.10.2026 |
9.1 |
| CVE-2026-15897 |
Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login |
02.10.2026 |
8.8 |
| CVE-2026-78471 |
Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name |
02.10.2026 |
5.4 |
| CVE-2026-84925 |
Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter |
02.10.2026 |
6.1 |
| CVE-2026-90438 |
Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission |
02.10.2026 |
7.2 |
| CVE-2026-92174 |
SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter |
02.10.2026 |
7.5 |
| CVE-2026-92820 |
Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload |
02.10.2026 |
8.1 |
| CVE-2026-10026 |
CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution |
02.10.2026 |
7.2 |
| CVE-2026-19660 |
Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter |
02.10.2026 |
9.8 |
| CVE-2026-14378 |
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow |
02.10.2026 |
9.8 |
| CVE-2026-93367 |
Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title) |
02.10.2026 |
7.2 |
| CVE-2026-104123 |
SourceCodester Online Reviewer Management System btn_functions.php activity sql injection |
02.10.2026 |
|
| CVE-2026-104120 |
modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery |
02.10.2026 |
|
| CVE-2026-104054 |
calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization |
02.10.2026 |
|