CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-79820 05.10.2026 9
CVE-2026-105285 Totolink A3002MU QoS Rule formIpQoS stack-based overflow 05.10.2026 10
CVE-2026-105284 Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization 05.10.2026 10
CVE-2026-100102 RCE via exposed JDWP debug agent in P4Search 05.10.2026 9.5
CVE-2026-100103 Authentication bypass via default auth token in P4Search 05.10.2026 10
CVE-2026-103510 Authentication bypass via blank auth token in P4Search 05.10.2026 9.5
CVE-2026-105223 maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105293 Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers 05.10.2026 9.2
CVE-2026-105294 Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig 05.10.2026 9.1
CVE-2026-105221 Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification 04.10.2026 9.1
CVE-2026-105222 alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer 05.10.2026 9.1
CVE-2026-105216 go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper 05.10.2026 9.1
CVE-2026-105218 gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client 05.10.2026 9.1
CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title 05.10.2026 9.3
CVE-2026-105089 WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates 04.10.2026 9.3
CVE-2026-105207 ZITADEL before 4.17.3 Account Takeover via External IdP Linking 04.10.2026 9.3
CVE-2026-105209 ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment 04.10.2026 9.3
CVE-2026-105211 ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode 05.10.2026 9.2
CVE-2026-105215 ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback 05.10.2026 9.3
CVE-2026-103355 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability 05.10.2026 9.3
CVE-2026-105134 Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection 05.10.2026 10
CVE-2026-105135 InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection 04.10.2026 10
CVE-2026-105105 Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration 03.10.2026 9.8
CVE-2026-71885 MLS X.509 credential not bound to the LeafNode signature key 03.10.2026 9.2
CVE-2026-92084 Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output 03.10.2026 9.1
CVE-2026-87115 VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter 03.10.2026 9.1
CVE-2026-105080 03.10.2026 9.4
CVE-2026-84411 MikroTik RouterOS Integer Underflow 03.10.2026 9.3
CVE-2026-95102 Monta monta.app Missing Authentication for Critical Function 03.10.2026 9.3
CVE-2026-75937 OS Command Injection in Digi Accelerated Linux (DAL OS) 03.10.2026 9.4
CVE-2026-82042 UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter 05.10.2026 9.3
CVE-2026-104019 OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio 02.10.2026 9.3
CVE-2026-103956 Missing authentication for critical function in Loom for AWS 02.10.2026 10
CVE-2023-54405 H3C CVM Unauthenticated File Upload via fileUpload/upload Token 05.10.2026 9.3
CVE-2026-104848 Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution 02.10.2026 9.5
CVE-2026-104849 Tinypool: Prototype Pollution Gadget to RCE in run() options 02.10.2026 9.5
CVE-2026-103648 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader 03.10.2026 9.1
CVE-2026-104846 Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940) 02.10.2026 9.8
CVE-2026-90970 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 02.10.2026 9.9
CVE-2026-19652 Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter 03.10.2026 9.8
CVE-2026-83632 Apache Thrift: C++ THttpTransport grows its line buffer without bound 02.10.2026 9.2
CVE-2026-104610 Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow 02.10.2026 10
CVE-2026-104611 Tenda AC9 POST Request fast_setting_internet_set stack-based overflow 02.10.2026 9.4
CVE-2026-104467 YesWiki before 4.6.7 Authorization Bypass via Public API Mode 02.10.2026 9.2
CVE-2026-91135 Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) 02.10.2026 9.2
CVE-2026-86325 02.10.2026 9.4
CVE-2026-94541 WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter 02.10.2026 9.8
CVE-2026-97637 JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response 03.10.2026 9.8
CVE-2026-63569 MTI/A0 DHAgreement does not validate the peer's ephemeral value 02.10.2026 9.1
CVE-2026-93029 02.10.2026 9
CVE-2026-93697 02.10.2026 9
CVE-2026-93698 02.10.2026 9.9
CVE-2026-15896 Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter 02.10.2026 9.1
CVE-2026-19660 Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter 03.10.2026 9.8
CVE-2026-14378 DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow 03.10.2026 9.8
CVE-2026-104480 Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership 02.10.2026 9.4
CVE-2026-86345 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result 02.10.2026 9
CVE-2026-103764 Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport 02.10.2026 9.3
CVE-2026-18397 SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability 02.10.2026 9.4
CVE-2026-71449 02.10.2026 9.3
CVE-2026-55393 Local File Inclusion in Teledyne FLIR Robots running Aware2 01.10.2026 10
CVE-2026-55395 Hardcoded Passwords in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-14984 Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2 01.10.2026 9.4
CVE-2026-102628 Cadmos LTI exposure of sensitive information via debug mode 01.10.2026 9.2
CVE-2026-102667 Joyland AI WebView command injection 02.10.2026 9
CVE-2026-53953 GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover 01.10.2026 9.1
CVE-2026-56660 GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction 01.10.2026 9.1
CVE-2026-56662 GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request 01.10.2026 9.6
CVE-2026-104286 05.10.2026 9.8
CVE-2026-55083 DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) 01.10.2026 9.1
CVE-2026-103922 Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path 01.10.2026 9.3
CVE-2026-13043 WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access 01.10.2026 9.3
CVE-2026-96658 Foreman: safemode bypass leading to rce 02.10.2026 9.9
CVE-2026-96659 Foreman: excessive permissions for viewer role on preview 02.10.2026 9.1
CVE-2026-94620 Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) 01.10.2026 9.4
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability 01.10.2026 9.8
CVE-2026-79898 Fortra BoKS Manager crlserver command injection vulnerability 01.10.2026 9.1
CVE-2026-103752 WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability 01.10.2026 9.8
CVE-2026-62071 WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability 01.10.2026 9.3
CVE-2026-79901 Predictable Active Directory service-account passwords in BoKS Manager 01.10.2026 9.9
CVE-2026-103244 ground-station before 0.8.0 Authentication Bypass via setup.restore 01.10.2026 9.3
CVE-2026-103264 Fleet before 4.87.0 Authentication Bypass via Device Identifiers 01.10.2026 9.3
CVE-2026-103655 MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period 01.10.2026 9.3
CVE-2026-15989 Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter 01.10.2026 9.8
CVE-2026-75957 Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter 01.10.2026 9.8
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects 01.10.2026 9.3
CVE-2026-82824 Path traversal may allow arbitrary files to be viewed, created, modified, or deleted 01.10.2026 9.3
CVE-2026-82825 Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed 01.10.2026 9.3
CVE-2026-82827 A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens 01.10.2026 9.3
CVE-2026-82829 Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process 01.10.2026 9.3
CVE-2026-76142 Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface 01.10.2026 9.3
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field 01.10.2026 9.1
CVE-2026-14157 02.10.2026 9.4
CVE-2026-101283 01.10.2026 9.2
CVE-2026-101276 01.10.2026 9.2
CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication 01.10.2026 9.1
CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery 01.10.2026 9.1
CVE-2026-102115 Kiteworks Core Authentication Bypass in the Password Reset Workflow 01.10.2026 9.8
CVE-2026-102147 Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) 01.10.2026 9.3
CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control 01.10.2026 9.4
CVE-2026-102992 piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env 30.09.2026 9.2
CVE-2026-103547 30.09.2026 9.2
CVE-2026-100512 WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-103473 Deno 2.7.0 through 2.9.7 Command Injection via node:child_process 02.10.2026 9.2
CVE-2026-103475 yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure 30.09.2026 9.3
CVE-2026-55107 Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) 30.09.2026 10
CVE-2026-55181 Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false 30.09.2026 9.4
CVE-2026-55494 Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset 30.09.2026 9.8
CVE-2026-62308 Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint 30.09.2026 9.1
CVE-2026-55176 Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token 02.10.2026 9
CVE-2026-102489 Undisclosed RCE in Zammad v6.3 and higher 05.10.2026 9.4
CVE-2026-102490 Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha 05.10.2026 9.4
CVE-2026-19445 Use-after-free of a server-side SSLContext when sni_callback switches contexts 03.10.2026 9.2
CVE-2026-75969 PTZOptics Missing Authentication in Firmware Upload 30.09.2026 9.1
CVE-2026-103470 30.09.2026 9.3
CVE-2026-102427 Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 30.09.2026 10
CVE-2026-103395 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service 30.09.2026 9.3
CVE-2026-76570 Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 30.09.2026 10
CVE-2026-18782 SQL Injection in Trex Digital Manufacturing's Trex MES 30.09.2026 9.8
CVE-2026-93903 30.09.2026 9.4
CVE-2026-82307 Multiple Vulnerabilities in Dolusoft Software's SOPLOG 30.09.2026 9.8
CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 02.10.2026 9.8
CVE-2026-94389 WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability 30.09.2026 9
CVE-2026-96349 WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability 30.09.2026 10
CVE-2026-96350 WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability 30.09.2026 9.8
CVE-2026-96822 WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability 30.09.2026 9.3
CVE-2026-97248 WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability 30.09.2026 9.8
CVE-2026-97274 WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability 30.09.2026 9.8
CVE-2026-74864 Authentication Bypass in sogo_yhn 30.09.2026 9.3
CVE-2026-74865 Authentication Bypass in sogo_yhn 30.09.2026 9.2
CVE-2026-77185 Apache MINA SSHD: Asynchronous authentication can bypass signature verification 30.09.2026 9.1
CVE-2026-94053 Apache MINA SSHD: LDAP injection in sshd-ldap 30.09.2026 9.1
CVE-2026-94052 Apache MINA SSHD: LDAP password authentication ineffective 30.09.2026 9.1
CVE-2026-102455 DigiWin|EasyFlow .NET - Insecure Deserialization 30.09.2026 9.3
CVE-2026-102458 DigiWin|EasyFlow .NET - Missing Authentication 30.09.2026 9.3
CVE-2026-102508 Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade 30.09.2026 9.2
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability 30.09.2026 9.1
CVE-2026-102911 zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection 30.09.2026 9.4
CVE-2026-103110 02.10.2026 9.8
CVE-2026-103056 AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR 30.09.2026 9.4
CVE-2026-102794 Ziroom ZHOME A0101 ping command injection 30.09.2026 9.4
CVE-2026-102793 Ziroom ZHOME A0101 set_time_zone command injection 01.10.2026 9.4
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution 01.10.2026 9.2
CVE-2026-103040 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service 30.09.2026 9.3
CVE-2026-103041 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service 30.09.2026 9.3
CVE-2026-102792 Ziroom ZHOME A0101 set_syslog command injection 02.10.2026 9.4
CVE-2026-70356 Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type 30.09.2026 9.4
CVE-2026-71379 Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties 30.09.2026 10
CVE-2026-96587 Use of Hard-coded Credentials in Viidure Dashcam Android Application 29.09.2026 10
CVE-2026-53988 Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints 02.10.2026 9.2
CVE-2026-100291 Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 29.09.2026 9.3
CVE-2026-76721 Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs 30.09.2026 9.8
CVE-2026-76722 Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs 01.10.2026 9.8
CVE-2026-76723 Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS 01.10.2026 9.6
CVE-2026-76724 Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol 01.10.2026 9.6
CVE-2026-76725 Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs 01.10.2026 9.6
CVE-2026-102829 simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 30.09.2026 9.2
CVE-2026-102828 simple-git unsafe-operation guard does not block trailer command configuration 30.09.2026 9.2
CVE-2026-84436 IBM Guardium Data Protection is affected by multiple vulnerabilities. 30.09.2026 9.1
CVE-2026-102710 30.09.2026 9.3
CVE-2026-102761 30.09.2026 9.3
CVE-2026-102425 Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 01.10.2026 9.5
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 30.09.2026 9.3
CVE-2026-22094 Weak root password in EVbee DC 80 30.09.2026 9.3
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026 9.3
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026 9.3
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026 9
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026 9.3
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 30.09.2026 9.2
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026 10
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026 9.4
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 01.10.2026 9.3
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 01.10.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-104891 mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control 05.10.2026 7.5
CVE-2026-88397 05.10.2026
CVE-2026-104890 Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution 05.10.2026 7.2
CVE-2026-88396 05.10.2026
CVE-2026-88395 05.10.2026
CVE-2026-105329 TallCMS PluginManager ThemeManager.php code injection 05.10.2026
CVE-2026-105397 LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation 05.10.2026
CVE-2026-37719 05.10.2026
CVE-2026-88393 05.10.2026
CVE-2026-79820 05.10.2026 9
CVE-2026-89039 CVE-2026-89039 CVE Record 05.10.2026 6.5
CVE-2026-88392 05.10.2026
CVE-2026-105421 WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.2.0 - Broken Access Control vulnerability 05.10.2026 5.3
CVE-2026-88391 05.10.2026
CVE-2026-88394 05.10.2026
CVE-2026-92931 CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK 05.10.2026 8.8
CVE-2026-105315 django-haystack more_like_this Template Tag elasticsearch_backend.py _to_python eval injection 05.10.2026
CVE-2026-77802 HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic 05.10.2026 6.3
CVE-2026-77803 Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic 05.10.2026 3.6
CVE-2026-77804 Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic 05.10.2026 6.6
CVE-2026-77805 Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classic 05.10.2026 7.9
CVE-2026-103684 WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability 05.10.2026 5.3
CVE-2026-39783 WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability 05.10.2026 4.3
CVE-2026-105073 WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability 05.10.2026 5.3
CVE-2026-105307 Casdoor API Endpoint authz_filter.go ApiFilter missing authentication 05.10.2026
CVE-2026-105396 Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header 05.10.2026
CVE-2026-63266 Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality 05.10.2026
CVE-2026-63267 LFI and GET SSRF via calcext:data-mappings and csv provider 05.10.2026
CVE-2026-63268 LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href 05.10.2026
CVE-2026-63269 LFI and GET SSRF via GStreamer and HLS playlists 05.10.2026
CVE-2026-63270 Environment/ini-file leaks 05.10.2026
CVE-2026-63277 RCE via calcext:data-mappings, sql provider and jdbc connector 05.10.2026
CVE-2026-94669 WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Broken Access Control vulnerability 05.10.2026 5.3
CVE-2026-105291 feelec-yishu feelcrm-os Department Search Endpoint GroupController.class.php index cross site scripting 05.10.2026
CVE-2026-105289 feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php htmlspecialchars_decode cross site scripting 05.10.2026
CVE-2026-105290 feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php server-side request forgery 05.10.2026
CVE-2026-39763 WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control vulnerability 05.10.2026 4.3
CVE-2026-59782 JavaScript preprocessing memory disclosure 05.10.2026
CVE-2026-59783 Server DoS via binary items 05.10.2026
CVE-2026-59785 Hidden host credentials inferable via multiselect.get filtering 05.10.2026
CVE-2026-59786 Active agent heartbeat missing TLS check 05.10.2026
CVE-2026-59787 SNMP trap injection in zabbix_trap_receiver.pl 05.10.2026
CVE-2026-59788 Stored XSS vulnerability in OAuth configuration form 05.10.2026
CVE-2026-105288 feelec-yishu feelcrm-os Crm Endpoint functions.php index cross site scripting 05.10.2026
CVE-2026-105287 feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql injection 05.10.2026
CVE-2026-105285 Totolink A3002MU QoS Rule formIpQoS stack-based overflow 05.10.2026
CVE-2026-105286 Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal 05.10.2026
CVE-2026-19395 An empty <img> attribute value in styled text triggers a parser error that halts the device. 05.10.2026
CVE-2026-102393 WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-103079 WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (IDOR) vulnerability 05.10.2026 5.4
CVE-2026-103351 WordPress Taxi Booking Manager for WooCommerce plugin <= 2.1.1 - Other vulnerability Type vulnerability 05.10.2026 5.3
CVE-2026-104388 WordPress PowerPress Podcasting plugin <= 11.17.9 - Sensitive Data Exposure vulnerability 05.10.2026 5.3
CVE-2026-104389 WordPress Sirv plugin <= 8.2.5 - SQL Injection vulnerability 05.10.2026 8.5
CVE-2026-105064 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.22 - Broken Access Control vulnerability 05.10.2026 6.5
CVE-2026-105284 Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization 05.10.2026
CVE-2026-39721 WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerability 05.10.2026 5.4
CVE-2026-100102 RCE via exposed JDWP debug agent in P4Search 05.10.2026
CVE-2026-100103 Authentication bypass via default auth token in P4Search 05.10.2026
CVE-2026-102914 WordPress Presto Player plugin <= 4.5.2 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-103078 WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (IDOR) vulnerability 05.10.2026 4.3
CVE-2026-103084 WordPress Premium Addons for Elementor plugin <= 4.11.109 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-103335 WordPress Video Conferencing with Zoom plugin <= 4.6.10 - Sensitive Data Exposure vulnerability 05.10.2026
CVE-2026-103507 Arbitrary file-write via log configuration path in P4Search 05.10.2026
CVE-2026-103510 Authentication bypass via blank auth token in P4Search 05.10.2026
CVE-2026-103511 Arbitrary file-write via extension installation in P4Search 05.10.2026
CVE-2026-103512 Ticket host-binding bypass via spoofed client IP in P4Search 05.10.2026
CVE-2026-104386 WordPress WP VR plugin <= 9.1.3 - Broken Access Control vulnerability 05.10.2026 6.5
CVE-2026-104396 WordPress Name Directory plugin <= 1.34.2 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-104397 WordPress Name Directory plugin <= 1.34.2 - Arbitrary Shortcode Execution vulnerability 05.10.2026 5.3
CVE-2026-104401 WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure vulnerability 05.10.2026 4.3
CVE-2026-104404 WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-104407 WordPress PowerPress Podcasting plugin <= 11.17.9 - Cross Site Request Forgery (CSRF) vulnerability 05.10.2026 7.1
CVE-2026-104408 WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability 05.10.2026 7.6
CVE-2026-104673 WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.14.2 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-104675 WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability 05.10.2026 4.3
CVE-2026-104805 Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Execution 05.10.2026
CVE-2026-104806 Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure 05.10.2026
CVE-2026-104807 Mitel MiVoice Office 400 stored Cross-Site Scripting 05.10.2026
CVE-2026-104808 Mitel MiVoice Office 400 stored Cross-Site Scripting 05.10.2026
CVE-2026-104809 Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution 05.10.2026
CVE-2026-104810 Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability 05.10.2026
CVE-2026-104811 Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution 05.10.2026
CVE-2026-105055 WordPress WP Mailster plugin <= 1.9.0.0 - Broken Access Control vulnerability 05.10.2026 5.3
CVE-2026-105056 WordPress eCommerce Product Catalog plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-105060 WordPress Logo Showcase plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-105062 WordPress WP Admin Audit plugin <= 1.2.17 - Broken Access Control vulnerability 05.10.2026 4.3
CVE-2026-105068 WordPress Events Manager plugin <= 7.4.5 - Sensitive Data Exposure vulnerability 05.10.2026 5.3
CVE-2026-105069 WordPress QR Redirector plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-105254 itsourcecode Online Admission System schoolyear.php sql injection 05.10.2026
CVE-2026-105263 Shaarli Admin Metadata Endpoint MetadataController.php MetadataController server-side request forgery 05.10.2026
CVE-2026-97071 WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability 05.10.2026 5.3
CVE-2026-104400 WordPress B Blocks plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-104409 WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.13 - Cross Site Scripting (XSS) vulnerability 05.10.2026 6.5
CVE-2026-104706 Mitel MiVoice Office 400 view system files path traversal 05.10.2026
CVE-2026-105251 vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds 05.10.2026
CVE-2026-105253 itsourcecode Online Admission System Project login1.php sql injection 05.10.2026
CVE-2026-19184 Out-of-bounds write in the NXP GAU ADC driver due to byte-versus-sample buffer size validation mismatch 05.10.2026 8.4
CVE-2026-19185 Unvalidated user-supplied buffer pointers in the I3C do_ccc system call handler allow kernel memory read/write from user mode 05.10.2026 7.8
CVE-2026-105249 vgmstream TXTP File txtp_process.c make_group_random use after free 05.10.2026
CVE-2026-105250 vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero 05.10.2026
CVE-2026-105314 05.10.2026 7.5
CVE-2026-105247 SourceCodester Online Reviewer Management System btn_functions.php course sql injection 05.10.2026
CVE-2026-105248 vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write 05.10.2026
CVE-2017-20285 YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes 05.10.2026
CVE-2019-25777 YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution 05.10.2026
CVE-2026-100727 05.10.2026
CVE-2026-105238 ChatGPTNextWeb NextChat Proxy Fallback proxy.ts proxyHandler server-side request forgery 05.10.2026
CVE-2026-105245 sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmission 05.10.2026
CVE-2026-105246 SourceCodester Online Reviewer Management System btn_functions.php update sql injection 05.10.2026
CVE-2026-19954 Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names 05.10.2026
CVE-2026-105237 linlinjava litemall Login Endpoint AdminAuthController.java excessive authentication 05.10.2026
CVE-2026-105302 Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access tokens 05.10.2026
CVE-2026-105306 Keycloak-services: keycloak-services: token introspection audience bypass via dynamic client registration 05.10.2026
CVE-2026-13607 File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access 05.10.2026
CVE-2026-78371 File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File Disclosure 05.10.2026
CVE-2026-84169 UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery 05.10.2026
CVE-2026-105232 kishor-23 food-waste-management-system Registration deliverysignup.php sql injection 05.10.2026
CVE-2026-105233 kishor-23 food-waste-management-system Login Flow login.php session fixiation 05.10.2026
CVE-2026-105301 Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker-controlled crl-dp/ocsp urls 05.10.2026
CVE-2026-105230 kishor-23 food-waste-management-system deliverymyord.php sql injection 05.10.2026
CVE-2026-105231 kishor-23 food-waste-management-system Admin Registration signup.php sql injection 05.10.2026
CVE-2026-105226 osCommerce osCommerce2 Newsletter Management newsletters.php include code injection 05.10.2026
CVE-2026-105229 kishor-23 food-waste-management-system User Registration Endpoint signup.php sql injection 05.10.2026
CVE-2026-105188 code-projects Human Resource Management System Live Event History liveEventHistory.php cross site scripting 05.10.2026
CVE-2026-105225 osCommerce osCommerce2 Payment payment.php include code injection 05.10.2026
CVE-2026-105187 itsourcecode Online Admission System key.php sql injection 05.10.2026
CVE-2026-105185 itsourcecode Online Admission System examinee.php sql injection 05.10.2026
CVE-2026-105186 itsourcecode Online Admission System new.php sql injection 05.10.2026
CVE-2026-105183 itsourcecode Online Admission System confirm.php sql injection 05.10.2026
CVE-2026-105184 itsourcecode Online Admission System creteria.php sql injection 05.10.2026
CVE-2026-105181 itsourcecode Online Admission System register1.php sql injection 05.10.2026
CVE-2026-105182 SourceCodester Online Reviewer Management System btn_functions.php update sql injection 05.10.2026
CVE-2026-105179 SourceCodester Drug Recommendation System Password add_user.php missing encryption 05.10.2026
CVE-2026-105180 Jeebase UserService info updateUser dynamically-determined object attributes 05.10.2026
CVE-2026-20519 05.10.2026
CVE-2026-20520 05.10.2026
CVE-2026-20521 05.10.2026
CVE-2026-20522 05.10.2026
CVE-2026-20523 05.10.2026
CVE-2026-20524 05.10.2026
CVE-2026-20525 05.10.2026
CVE-2026-20526 05.10.2026
CVE-2026-20527 05.10.2026
CVE-2026-20528 05.10.2026
CVE-2026-20529 05.10.2026
CVE-2026-20530 05.10.2026
CVE-2026-20531 05.10.2026
CVE-2026-20532 05.10.2026
CVE-2026-20533 05.10.2026
CVE-2026-20534 05.10.2026
CVE-2026-20535 05.10.2026
CVE-2026-20536 05.10.2026
CVE-2026-20537 05.10.2026
CVE-2026-20538 05.10.2026
CVE-2026-20539 05.10.2026
CVE-2026-20540 05.10.2026
CVE-2026-20541 05.10.2026
CVE-2026-20542 05.10.2026
CVE-2026-20543 05.10.2026
CVE-2026-20544 05.10.2026
CVE-2026-20579 05.10.2026
CVE-2026-20586 05.10.2026
CVE-2026-20587 05.10.2026
CVE-2026-20588 05.10.2026
CVE-2026-20589 05.10.2026
CVE-2026-105176 SourceCodester Drug Recommendation System edit_class.php sql injection 05.10.2026
CVE-2026-105177 SourceCodester Drug Recommendation System Drug Creation add_drug.php sql injection 05.10.2026
CVE-2026-105178 SourceCodester Drug Recommendation System Symptom Creation add_symptom.php mysqli_real_escape_string sql injection 05.10.2026
CVE-2026-105172 itsourcecode Online Admission System login1.php sql injection 05.10.2026
CVE-2026-105173 code-projects Human Resource Management Event Creation EventStore.php cross site scripting 05.10.2026
CVE-2026-105174 Gerapy Project Management views.py project_create path traversal 05.10.2026
CVE-2026-105175 SourceCodester Drug Recommendation System Student Registration add_student.php sql injection 05.10.2026
CVE-2026-105223 maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification 05.10.2026
CVE-2026-105292 Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback 05.10.2026
CVE-2026-105293 Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers 05.10.2026
CVE-2026-105294 Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig 05.10.2026
CVE-2026-105295 GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass 05.10.2026
CVE-2026-105171 kishor-23 food-waste-management-system Role Attribute admin.php authorization 05.10.2026
CVE-2026-105170 kishor-23 food-waste-management-system Admin Signup signup.php missing authentication 04.10.2026
CVE-2026-105168 kishor-23 food-waste-management-system Order Assignment Block admin.php sql injection 05.10.2026
CVE-2026-105169 kishor-23 food-waste-management-system Take Order delivery.php sql injection 05.10.2026