CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-107806 Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite 09.10.2026 9.4
CVE-2026-15340 Savannah lwIP SMTP client Classic Buffer Overflow 09.10.2026 9.3
CVE-2026-108107 PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php 09.10.2026 9.3
CVE-2026-108109 PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code 09.10.2026 9.3
CVE-2026-28745 Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format 09.10.2026 9.3
CVE-2026-33367 Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function 09.10.2026 9.3
CVE-2026-39460 Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials 09.10.2026 9.3
CVE-2026-105278 Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials 09.10.2026 9.3
CVE-2026-32645 Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials 09.10.2026 9.2
CVE-2026-100730 Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data 09.10.2026 9.3
CVE-2026-86405 Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop 09.10.2026 9.8
CVE-2026-85531 Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x 09.10.2026 9.8
CVE-2026-93947 WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-94503 WordPress Zombify plugin <= 1.7.7 - Arbitrary File Upload vulnerability 09.10.2026 10
CVE-2026-96327 WordPress WPLMS plugin < 1.9.9.8.2 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96328 WordPress JNews - Pay Writer plugin <= 12.0.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96330 WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96331 WordPress Ajax Search Pro plugin <= 4.29.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96809 WordPress EduAdmin Booking plugin < 6.0.0 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-107935 Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose 09.10.2026 9.3
CVE-2026-107908 Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message 09.10.2026 9.3
CVE-2026-107910 Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling 09.10.2026 9.2
CVE-2026-5759 Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB 09.10.2026 9.3
CVE-2026-7827 Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB 09.10.2026 9.2
CVE-2026-69435 Azure SRE Agent Elevation of Privilege Vulnerability 09.10.2026 9.6
CVE-2026-77900 Azure App Service Remote Code Execution Vulnerability 09.10.2026 9.8
CVE-2026-88131 Microsoft Dataverse Remote Code Execution Vulnerability 09.10.2026 9.8
CVE-2026-94510 Microsoft Bookings Elevation of Privilege Vulnerability 09.10.2026 9.9
CVE-2026-96207 Microsoft Partner Center Elevation of Privilege Vulnerability 09.10.2026 10
CVE-2026-107726 Hazelcast: Arbitrary member memory access by low-privileged client 09.10.2026 9.3
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion 08.10.2026 9.8
CVE-2026-75875 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 9.8
CVE-2026-80381 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 9.8
CVE-2026-84249 IBM Guardium Data Protection is affected by vulnerability 09.10.2026 9.8
CVE-2026-107406 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 09.10.2026 9.5
CVE-2026-16823 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 09.10.2026 9.1
CVE-2026-16916 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 08.10.2026 9.1
CVE-2026-19491 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 08.10.2026 9.1
CVE-2026-78401 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 08.10.2026 9.8
CVE-2026-78406 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access 09.10.2026 9.8
CVE-2026-79842 09.10.2026 9.1
CVE-2026-107779 Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE 08.10.2026 9.3
CVE-2026-107780 Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter 08.10.2026 9.3
CVE-2026-107781 Dromara Skyeye Unauthenticated SSRF and File Overwrite via editUploadOfficeFileById 09.10.2026 9.1
CVE-2026-106126 Command Injection 08.10.2026 9.4
CVE-2026-104075 TVU Networks Receiver/Transceiver Authentication Bypass via /tvu/Login 08.10.2026 9.3
CVE-2026-104076 TVU Networks Receiver/Transceiver Missing Authentication via REST API 09.10.2026 9.3
CVE-2026-84244 IBM Guardium Data Protection Cross-Site Scripting 08.10.2026 9.3
CVE-2026-84272 IBM Guardium Data Protection Missing Authentication 08.10.2026 9.8
CVE-2026-107699 ppt2png through 0.0.6 OS Command Injection via input and output paths 08.10.2026 9.3
CVE-2026-107700 dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument 09.10.2026 9.3
CVE-2026-107703 @enmaso/node-convert through 1.0.0 OS Command Injection via filepath and convertTo 08.10.2026 9.3
CVE-2026-107704 image_optimizer 1.3.0 through 1.9.0 OS Command Injection via identify_format 09.10.2026 9.3
CVE-2026-9209 mJobTime 15.7.3.32 Unauthenticated SQL Execution RCE via Login.aspx 08.10.2026 9.3
CVE-2026-14269 IBM DataPower Gateway Buffer Overflow 09.10.2026 9.8
CVE-2026-107640 Integrics Enswitch 3.13 through 4.4 Authentication Bypass via Password Reset API 08.10.2026 9.3
CVE-2026-14502 IBM DataPower Gateway Improper Authentication 09.10.2026 9.8
CVE-2026-14992 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-14990 IBM DataPower Gateway affected by cross-site scripting 08.10.2026 9.3
CVE-2026-14991 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-103663 Path Traversal leading to Remote Code Execution in Ollama 08.10.2026 9.4
CVE-2026-15762 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-16340 IBM DataPower Gateway Out-of-bounds Write 09.10.2026 9.8
CVE-2026-19218 Password Reset Code Brute Force Leading to Account Takeover in AKIN Software's MyRezzta 08.10.2026 9.1
CVE-2026-92555 Database Credentials Disclosure in AKIN Software's AKINSOFT WOLVOX Control Panel 08.10.2026 9.8
CVE-2026-107510 Authenticated argument injection in NIOS command line leading to privilege escalation 09.10.2026 9.1
CVE-2026-105110 Iskratel Innbox Unauthenticated Remote Code Execution via login.xgi CLI Parameter 08.10.2026 9.3
CVE-2026-12260 SQL injection in the NetBoard CRM demo platform 08.10.2026 10
CVE-2026-85097 Bricksforge <= 3.1.8.9 - Unauthenticated Arbitrary File Upload via 'temporaryFileUploads' Parameter 08.10.2026 9.8
CVE-2026-107459 Openfind|SecuShare Pro - OS Command Injection 08.10.2026 9.3
CVE-2026-17609 Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter 08.10.2026 9.1
CVE-2026-107282 AsyncHttpClient: Replay to a different host sends the original host request and credentials to the new host 07.10.2026 9.4
CVE-2026-76268 Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise 09.10.2026 9.8
CVE-2026-95605 WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability 07.10.2026 9.3
CVE-2026-95606 WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnerability 07.10.2026 9.8
CVE-2026-20328 Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnerability 08.10.2026 9.1
CVE-2026-62176 PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation 07.10.2026 9.1
CVE-2026-62252 Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login 07.10.2026 9.8
CVE-2026-62253 Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default) 07.10.2026 9.8
CVE-2026-76454 Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability 07.10.2026 9.1
CVE-2026-76455 Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities 08.10.2026 9.8
CVE-2026-76459 Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Write Vulnerabilities 09.10.2026 9.8
CVE-2026-76464 Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities 07.10.2026 9.6
CVE-2026-76465 Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76471 Cisco NX-OS Software NX-API Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76480 Cisco License On-Prem Security Hardening Release 08.10.2026 9.8
CVE-2026-76482 Cisco License On-Prem Security Hardening Release 08.10.2026 10
CVE-2026-76483 Cisco License On-Prem Security Hardening Release 08.10.2026 9.1
CVE-2026-76485 Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76486 Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-76498 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Access Control Vulnerabilities 07.10.2026 9.8
CVE-2026-76499 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization Vulnerabilities 07.10.2026 9.8
CVE-2026-76500 Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime Vulnerabilities 08.10.2026 9.8
CVE-2026-76501 Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability 08.10.2026 9.8
CVE-2026-92414 Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens 07.10.2026 9.3
CVE-2026-107204 LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint 07.10.2026 9.3
CVE-2026-107194 07.10.2026 9.2
CVE-2026-107183 llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser 07.10.2026 9.2
CVE-2026-96408 07.10.2026 9.3
CVE-2026-105192 LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization 07.10.2026 9.8
CVE-2026-103416 07.10.2026 9.3
CVE-2025-64393 08.10.2026 9.4
CVE-2026-102782 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 08.10.2026 9.3
CVE-2026-107102 Account Takeover Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107103 SQL Injection Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-107104 Unsafe Deserialization Vulnerability in Manacle Technologies ERP System 07.10.2026 9.3
CVE-2026-59346 VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability 07.10.2026 9.3
CVE-2026-19572 FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability 07.10.2026 9.3
CVE-2026-14911 07.10.2026 9.3
CVE-2026-16516 wolfSSH ECDSA host key curve not validated against negotiated algorithm 07.10.2026 9
CVE-2026-19386 08.10.2026 9.3
CVE-2026-105324 An HTTP header injection vulnerability was found in the ADM 07.10.2026 9.2
CVE-2026-104334 Langflow OSS is affected by multiple vulnerabilities 08.10.2026 9.8
CVE-2026-93674 Langflow OSS is affected by multiple vulnerabilities 08.10.2026 9.8
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder 07.10.2026 9.6
CVE-2026-101157 Security Advisory 0192 06.10.2026 9.3
CVE-2026-102159 Security Advisory 0190 06.10.2026 9.3
CVE-2026-102162 Security Advisory 0193 06.10.2026 9.4
CVE-2026-102167 Security Advisory 0197 06.10.2026 9
CVE-2026-106445 Handlebars: JavaScript Injection via Own Property Check Bypass 09.10.2026 9.2
CVE-2026-106446 Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.blockParams) 07.10.2026 9.8
CVE-2026-101158 Security Advisory 0185 06.10.2026 9.3
CVE-2026-76750 Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76751 Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution 08.10.2026 9.8
CVE-2026-76752 Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access 08.10.2026 9.8
CVE-2026-76753 Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76754 Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-79794 Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface 08.10.2026 9.1
CVE-2026-79796 Authentication Bypass Vulnerabilities in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-79798 Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface 08.10.2026 9.9
CVE-2026-79801 Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent 08.10.2026 9.8
CVE-2026-79805 Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager 08.10.2026 9.8
CVE-2026-76742 Authentication Bypass in the Web Management Interface of AOS-S 08.10.2026 9.8
CVE-2026-76743 Authentication Bypass Vulnerability in the Management Interface of AOS-S 08.10.2026 9.8
CVE-2026-76744 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S 08.10.2026 9.8
CVE-2026-76745 Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Execution in AOS-S 08.10.2026 9.6
CVE-2026-76746 Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure in AOS-S 07.10.2026 9.3
CVE-2026-76747 Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S 07.10.2026 9.1
CVE-2026-86360 06.10.2026 9.6
CVE-2026-106102 Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() 06.10.2026 10
CVE-2026-105863 Payload authentication token field handling issue 09.10.2026 9.2
CVE-2026-105857 Payload: RCE in Payload Form Builder 06.10.2026 10
CVE-2026-105859 Payload: Unauthorized update to collection documents 06.10.2026 9.8
CVE-2026-104070 SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE 09.10.2026 9.3
CVE-2026-105851 Payload: Field access control bypass on auth collections 06.10.2026 9.3
CVE-2026-105844 Payload: Prototype pollution in Payload Import Export plugin 09.10.2026 9.3
CVE-2026-105845 Payload: SQL Injection in SQLite and Postgres 06.10.2026 9.8
CVE-2026-67273 08.10.2026 9.6
CVE-2026-54472 06.10.2026 9.8
CVE-2026-61421 06.10.2026 9.8
CVE-2026-67269 08.10.2026 9.9
CVE-2026-63688 06.10.2026 10
CVE-2026-63692 09.10.2026 10
CVE-2026-105793 Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` 06.10.2026 9.1
CVE-2026-105794 MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL 06.10.2026 9.1
CVE-2026-106037 Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service 06.10.2026 9.3
CVE-2026-91140 OS command injection in Progress Software Autonomous REST Connector GenAI Agents 07.10.2026 9.6
CVE-2026-105835 PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint 09.10.2026 9.1
CVE-2026-82531 Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache 06.10.2026 9.2
CVE-2026-32557 WordPress WooCommerce Appointments plugin <= 5.3.2 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-32568 WordPress WooCommerce Designer Pro plugin <= 1.9.33 - Remote Code Execution (RCE) vulnerability 06.10.2026 9.9
CVE-2026-32579 WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39746 WordPress Booknetic plugin <= 4.8.5 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39753 WordPress Taskbot plugin <= 6.6 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39755 WordPress WP Duplicate plugin <= 1.1.11 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39757 WordPress Taskbot plugin <= 6.6 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39759 WordPress Workreap Core plugin <= 3.4.5 - Arbitrary File Upload vulnerability 06.10.2026 9.9
CVE-2026-39761 WordPress Meta Box AIO plugin <= 3.7.1 - Privilege Escalation vulnerability 06.10.2026 9.8
CVE-2026-39764 WordPress Radius Booking — Booking Calendar for Appointments & Services plugin <= 1.0.19 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39770 WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability 06.10.2026 10
CVE-2026-39773 WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability 06.10.2026 10
CVE-2026-39785 WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39795 WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-39797 WordPress GDPR Framework By Data443 plugin <= 2.5.0 - PHP Object Injection vulnerability 06.10.2026 9.8
CVE-2026-41555 WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <= 1.5.9 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42415 WordPress Porto Theme - Functionality plugin <= 3.9.3 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-42417 WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-98323 RDMA/siw: Bound fragmented header copies by the remaining length 07.10.2026 9.8
CVE-2026-98365 RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access 07.10.2026 9.8
CVE-2026-85153 Information Disclosure Vulnerability in Schmooze dating mobile Application 06.10.2026 9.3
CVE-2026-105778 Tenda AC5 Wifi setWifi stack-based overflow 06.10.2026 9.4
CVE-2026-94293 Missing authentication for critical function in the aas-edge-client REST API 06.10.2026 9.3
CVE-2026-105484 TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection 06.10.2026 10
CVE-2026-105763 Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL 08.10.2026 9.6
CVE-2026-21589 07.10.2026 9.3
CVE-2026-91107 openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) 06.10.2026 9.3
CVE-2026-105697 Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration 06.10.2026 9.9
CVE-2026-105740 Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server 06.10.2026 9.9
CVE-2026-77226 Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint 07.10.2026 9.2
CVE-2026-105691 Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color 06.10.2026 9.9
CVE-2026-103352 WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability 05.10.2026 9.3
CVE-2026-105636 Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 07.10.2026 9.9
CVE-2026-105637 Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558) 05.10.2026 9.6
CVE-2026-105638 Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force 05.10.2026 9.1
CVE-2026-105639 Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane 06.10.2026 9.8
CVE-2026-105640 Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) 05.10.2026 9.1
CVE-2026-105641 Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass 07.10.2026 9.8
CVE-2026-97283 WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulnerability 05.10.2026 9.8
CVE-2026-102428 Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 05.10.2026 9.3
CVE-2026-79820 05.10.2026 9
CVE-2026-105285 Totolink A3002MU QoS Rule formIpQoS stack-based overflow 05.10.2026 10
CVE-2026-105284 Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization 05.10.2026 10
CVE-2026-100102 RCE via exposed JDWP debug agent in P4Search 05.10.2026 9.5
CVE-2026-100103 Authentication bypass via default auth token in P4Search 05.10.2026 10
CVE-2026-103510 Authentication bypass via blank auth token in P4Search 05.10.2026 9.5
CVE-2026-105223 maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105293 Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers 05.10.2026 9.2
CVE-2026-105294 Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig 05.10.2026 9.1
CVE-2026-105221 Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification 05.10.2026 9.1
CVE-2026-105222 alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer 05.10.2026 9.1
CVE-2026-105216 go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper 05.10.2026 9.1
CVE-2026-105218 gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client 05.10.2026 9.1
CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title 05.10.2026 9.3
CVE-2026-105089 WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates 06.10.2026 9.3
CVE-2026-105207 ZITADEL before 4.17.3 Account Takeover via External IdP Linking 06.10.2026 9.3
CVE-2026-105209 ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment 05.10.2026 9.3
CVE-2026-105211 ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode 05.10.2026 9.2
CVE-2026-105215 ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback 05.10.2026 9.3
CVE-2026-103355 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability 06.10.2026 9.3
CVE-2026-105134 Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection 05.10.2026 10
CVE-2026-105135 InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection 06.10.2026 10
CVE-2026-105105 Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration 05.10.2026 9.8
CVE-2026-71885 MLS X.509 credential not bound to the LeafNode signature key 05.10.2026 9.2
CVE-2026-92084 Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output 03.10.2026 9.1
CVE-2026-87115 VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter 03.10.2026 9.1
CVE-2026-105080 06.10.2026 9.4
CVE-2026-84411 MikroTik RouterOS Integer Underflow 03.10.2026 9.3
CVE-2026-95102 Monta monta.app Missing Authentication for Critical Function 03.10.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-107813 Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up 09.10.2026 8.8
CVE-2026-75346 09.10.2026
CVE-2026-107783 Insertion of sensitive information into log file in AWS Tools for PowerShell 09.10.2026 5.9
CVE-2026-107811 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser 09.10.2026 8.8
CVE-2026-107812 Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM 09.10.2026 7.5
CVE-2026-75345 09.10.2026 7.5
CVE-2026-75349 09.10.2026 7.5
CVE-2026-107809 Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs 09.10.2026 8.8
CVE-2026-107810 Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied 09.10.2026 8.1
CVE-2026-90983 OTP Code Exposure in Hayat Hospital's Hayat Mobile 09.10.2026 8.2
CVE-2026-102554 Denial of Service via Eager Array Allocation During Deserialization in Guava 09.10.2026
CVE-2026-104082 SmarterMail < Build 9777 SysAdmin Remote Code Execution via Volume Mount 09.10.2026
CVE-2026-104083 SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content 09.10.2026
CVE-2026-104084 SmarterMail < Build 9777 Stale JWT Role Claim Privilege Escalation via Refresh Token 09.10.2026
CVE-2026-107807 Nginx UI: Node Secret Credential Exposure via URL Query Parameter 09.10.2026 8.8
CVE-2026-107808 Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass) 09.10.2026 8.1
CVE-2026-108110 MOVO through 0.2.3 Authorization Bypass via Document Endpoints 09.10.2026
CVE-2026-108111 ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via /workflow/search 09.10.2026
CVE-2026-108112 ruoyi-ai 3.0.0 through 3.1.0 Missing Authorization via Workflow Delete Endpoint 09.10.2026
CVE-2026-108113 ILIAS before 9.24, 10.12, and 11.5 Unrestricted File Upload via QTI Import 09.10.2026
CVE-2026-107806 Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite 09.10.2026
CVE-2026-108125 WordPress Post Author Authenticated SQLi 09.10.2026
CVE-2026-78796 09.10.2026
CVE-2026-107804 Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout 09.10.2026 5.3
CVE-2026-107805 Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage 09.10.2026 7.5
CVE-2026-108124 WordPress Post Author Authenticated SQLi 09.10.2026 4.9
CVE-2026-15340 Savannah lwIP SMTP client Classic Buffer Overflow 09.10.2026 9.8
CVE-2026-33272 Red Lion Controls N-Tron 700 Series Authentication Bypass Using an Alternate Path or Channel 09.10.2026 4.9
CVE-2026-39453 Red Lion Controls N-Tron 700 Series Reachable Assertion 09.10.2026 8.3
CVE-2026-95702 Code Execution in Host Sentry Process via Double Free in gVisor VFS MemoryFile 09.10.2026
CVE-2026-104115 Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon 09.10.2026
CVE-2026-108104 Xerial snappy-java 1.1.7.4 before 1.1.10.10 Double Release of Pooled Buffers in SnappyFramedInputStream 09.10.2026
CVE-2026-108106 Xerial snappy-java before 1.1.10.9 Unbounded Memory Allocation Denial of Service 09.10.2026
CVE-2026-108107 PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php 09.10.2026
CVE-2026-108108 PHPNuxBill through 2025.3.20 CHAP Authentication Bypass via Password::chap_verify() 09.10.2026
CVE-2026-108109 PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code 09.10.2026
CVE-2026-28745 Red Lion Controls N-Tron 700 Series Storing Passwords in a Recoverable Format 09.10.2026 7.5
CVE-2026-29797 Red Lion Controls N-Tron 700 Series Download of Code Without Integrity Check 09.10.2026 7.1
CVE-2026-33367 Red Lion Controls N-Tron 700 Series Missing Authentication for Critical Function 09.10.2026 8.1
CVE-2026-39460 Red Lion Controls N-Tron 700 Series Insufficiently Protected Credentials 09.10.2026 8.1
CVE-2026-78795 09.10.2026
CVE-2026-102916 Reachable assertion in illumos bhyve REP string instruction emulation allows guest to panic host 09.10.2026
CVE-2026-104081 KodExplorer < 4.55 Path Traversal via unzip_pre_name() ZIP Extraction 09.10.2026
CVE-2026-104112 Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory 09.10.2026
CVE-2026-104113 Double free in OmniOS and SmartOS ipmgmtd allows local users to crash the daemon 09.10.2026
CVE-2026-104114 NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon 09.10.2026
CVE-2026-104116 Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enumerate running zones 09.10.2026
CVE-2026-104117 Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership 09.10.2026
CVE-2026-105278 Grid Protection Alliance openPDC (Docker image) Use of Hard-coded Credentials 09.10.2026 9.8
CVE-2026-108100 HortusFox before 6.2 SQL Injection via /api/locations/list include_info Parameter 09.10.2026
CVE-2026-108101 HortusFox through 6.3 Unrestricted File Upload via Plant Attachments 09.10.2026
CVE-2026-108102 Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Volume Measurement IE 09.10.2026
CVE-2026-108103 Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE 09.10.2026
CVE-2026-108105 Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request 09.10.2026
CVE-2026-32645 Red Lion Controls N-Tron 700 Series Use of Hard-Coded Credentials 09.10.2026 6
CVE-2026-101022 Grid Protection Alliance openPDC and openHistorian Server-Side Request Forgery (SSRF) 09.10.2026 4.3
CVE-2026-104629 Grid Protection Alliance openPDC and openHistorian Use of Externally-Controlled Input to Select Classes or Code 09.10.2026 8.8
CVE-2026-79363 09.10.2026
CVE-2026-94063 WordPress Education Center theme <= 3.6.12 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94064 WordPress Neo | Barber Shop WordPress Theme theme <= 3.5 - PHP Object Injection vulnerability 09.10.2026 8.8
CVE-2026-94065 WordPress ColorFolio theme <= 1.3 - PHP Object Injection vulnerability 09.10.2026 8.8
CVE-2026-94066 WordPress Pond theme <= 2.6.1 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94067 WordPress The Voux theme <= 6.9.5 - Local File Inclusion vulnerability 09.10.2026 8.1
CVE-2026-100730 Grid Protection Alliance openPDC and openHistorian Deserialization of Untrusted Data 09.10.2026 9.8
CVE-2026-105281 Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function 09.10.2026 7.5
CVE-2026-106581 Docker Desktop for Windows installer failed to verify external packages 09.10.2026
CVE-2026-107803 ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter 09.10.2026 6.5
CVE-2026-85479 Grid Protection Alliance openPDC and openHistorian Missing Authentication for Critical Function 09.10.2026 5.3
CVE-2026-108063 Libhangul: null pointer dereference in hanja_new() when looking up a malformed hanja dictionary entry 09.10.2026
CVE-2026-107785 Crux Agent silently fails SKA preshared key rotation when SHA-512 peering is negotiated 09.10.2026
CVE-2026-62026 WordPress Dashboard Notes plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability 09.10.2026 7.1
CVE-2026-92085 Stored XSS in TMT Machine's Talassoft Industrial Management Software 09.10.2026 5.4
CVE-2026-101130 09.10.2026 3.6
CVE-2026-103220 09.10.2026 4.5
CVE-2026-103412 Apache Camel Karavan: project file name path traversal when committing a project to Git 09.10.2026 8.8
CVE-2026-103413 Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes.yaml 09.10.2026 8.8
CVE-2026-86405 Payment Validation Bypass in Sipay Electronic Money's SanalPos PrestaShop 09.10.2026 9.8
CVE-2026-94058 WordPress Treck theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94059 WordPress Ogency theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94060 WordPress Voldor theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94061 WordPress Whistle - Sports Club theme <= 4.2 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94062 WordPress Werkstatt theme <= 4.8.3 - Local File Inclusion vulnerability 09.10.2026 8.1
CVE-2026-101094 09.10.2026 3.6
CVE-2026-85531 Payment Validation Bypass in Sipay Electronic Money's OpenCart 3.x 09.10.2026 9.8
CVE-2026-96393 09.10.2026 3.6
CVE-2026-96394 09.10.2026 2.9
CVE-2026-96395 09.10.2026 3.6
CVE-2026-96396 09.10.2026 4.9
CVE-2026-104079 Envira Gallery Lite < 1.16.2 Missing Authorization via Gallery Conversion REST Endpoint 09.10.2026
CVE-2026-104392 WordPress Quiz And Survey Master plugin <= 11.2.7 - PHP Object Injection vulnerability 09.10.2026 8.8
CVE-2026-105318 WordPress AcyMailing SMTP Newsletter plugin <= 11.1.0 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-105870 WordPress WP Associate Post R2 plugin <= 5.0.1 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-105872 WordPress Product Configurator for WooCommerce plugin <= 1.7.5 - PHP Object Injection vulnerability 09.10.2026 7.2
CVE-2026-105877 WordPress QA Analytics plugin <= 5.3.0.0 - Sensitive Data Exposure vulnerability 09.10.2026
CVE-2026-105883 WordPress Th Shop Mania theme <= 1.9.1 - Broken Access Control vulnerability 09.10.2026 7.1
CVE-2026-106601 WordPress Jetpack plugin <= 16.2 - Broken Authentication vulnerability 09.10.2026 5.4
CVE-2026-106602 WordPress Jetpack plugin <= 16.2 - Broken Authentication vulnerability 09.10.2026 4.8
CVE-2026-62028 WordPress Before After Image Comparison – Image comparison for WP plugin <= 1.1.21 - Broken Access Control vulnerability 09.10.2026 5.4
CVE-2026-62029 WordPress WPFunnels plugin <= 3.13.3 - Cross Site Scripting (XSS) vulnerability 09.10.2026 6.5
CVE-2026-8374 Misuse and Misconfiguration of Cryptographic Algorithm in Bluetooth Communication 09.10.2026
CVE-2026-39779 WordPress Asgaros Forum plugin <= 3.4.0 - Broken Access Control vulnerability 09.10.2026 4.3
CVE-2026-62036 WordPress All Bootstrap Blocks plugin <= 1.3.31 - Sensitive Data Exposure vulnerability 09.10.2026 4.3
CVE-2026-62039 WordPress Html5 Audio Player plugin <= 2.8.8 - Cross Site Scripting (XSS) vulnerability 09.10.2026 6.5
CVE-2026-62040 WordPress Restrict User Access – Membership plugin with Force plugin <= 2.8.1 - Broken Access Control vulnerability 09.10.2026 5.3
CVE-2026-62041 WordPress WP Event Manager plugin <= 3.4.1 - Broken Access Control vulnerability 09.10.2026 5.4
CVE-2026-62042 WordPress Scripts n Styles plugin <= 3.5.8 - Broken Access Control vulnerability 09.10.2026 5.3
CVE-2026-107419 WordPress AI Translation for Polylang plugin <= 1.6.2 - Broken Access Control vulnerability 09.10.2026 5.4
CVE-2026-103329 Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signature 09.10.2026 5.3
CVE-2026-85348 GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF 09.10.2026 4.3
CVE-2026-86851 Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & Order Key Disclosure 09.10.2026 6.5
CVE-2026-87846 Shipping for Nova Poshta 1.18.7 - 1.19.8 - Unauthenticated Order Shipment Record Deletion 09.10.2026 5.3
CVE-2026-89235 Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter 09.10.2026 6.8
CVE-2026-100227 Apache CXF: XML Signature wrapping in JAX-RS XML Security 09.10.2026
CVE-2026-107937 Apache CXF: The attachment header size and count limits can be bypassed, which allows denial of service through memory exhaustion. 09.10.2026
CVE-2026-107938 Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification. 09.10.2026
CVE-2026-108039 Apache CXF: Prevent unbounded XML document size in StaxUtils by adding default element and character limits 09.10.2026
CVE-2026-71575 Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFilter 09.10.2026
CVE-2026-73179 Apache CXF: JPA authorization-code consume is non-atomic 09.10.2026
CVE-2026-78384 Apache CXF: Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing (Decompression Bomb) 09.10.2026
CVE-2026-79650 Apache CXF: OIDC RP Open Redirect 09.10.2026
CVE-2026-86463 Apache CXF: FIQL Query Parser Denial of Service 09.10.2026
CVE-2026-97468 Apache CXF: Authentication bypass via weak cache keys for validated STS tokens 09.10.2026
CVE-2026-97791 Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares validation state between requests 09.10.2026
CVE-2026-93947 WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-94158 WordPress Gloria Admin Panel plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94159 WordPress Total Donations plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94161 WordPress Grand Restaurant theme < 7.0.11 - Reflected Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94166 WordPress UpSolution Core plugin <= 8.44 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94167 WordPress Kubio AI Page Builder plugin <= 2.9.3 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94170 WordPress Sassy Social Share plugin <= 3.3.79 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94415 WordPress Betheme theme <= 28.5.8 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94503 WordPress Zombify plugin <= 1.7.7 - Arbitrary File Upload vulnerability 09.10.2026 10
CVE-2026-94568 WordPress Pay with Vipps for WooCommerce plugin <= 6.2.0 - PHP Object Injection vulnerability 09.10.2026 7.2
CVE-2026-94632 WordPress BlockStrap Page Builder - Bootstrap Blocks plugin <= 0.1.58 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94641 WordPress UsersWP plugin <= 1.2.73 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94661 WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-94663 WordPress ProfileGrid plugin <= 6.0.0.2 - SQL Injection vulnerability 09.10.2026 8.5
CVE-2026-94664 WordPress PDF for Contact Form 7 plugin <= 7.1.0 - Arbitrary File Download vulnerability 09.10.2026 7.5
CVE-2026-94665 WordPress Classified Listing plugin <= 6.1.2 - Cross Site Scripting (XSS) vulnerability 09.10.2026 6.5
CVE-2026-94666 WordPress Generate PDF using Contact Form 7 plugin <= 4.2.1 - Arbitrary File Download vulnerability 09.10.2026 7.5
CVE-2026-94667 WordPress JetReviews plugin <= 3.1.2 - Cross Site Scripting (XSS) vulnerability 09.10.2026 6.5
CVE-2026-94668 WordPress Salon booking system plugin <= 10.31.5 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-95589 WordPress Deposits and Partial Payments for WooCommerce plugin <= 4.0.1 - Broken Access Control vulnerability 09.10.2026 6.5
CVE-2026-95591 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.14 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-95596 WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin <= 3.4.1 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-95597 WordPress 워드프레스 결제 심플페이 plugin <= 5.5.17 - Settings Change vulnerability 09.10.2026 6.5
CVE-2026-95598 WordPress Search in Place plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-95599 WordPress Taskbuilder plugin <= 6.0.5 - SQL Injection vulnerability 09.10.2026 8.5
CVE-2026-95607 WordPress WPLMS theme <= 4.973 - SQL Injection vulnerability 09.10.2026 8.5
CVE-2026-95608 WordPress HUSKY plugin <= 1.4.3.2 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-95609 WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-95610 WordPress UpSolution Core plugin <= 9.3 - SQL Injection vulnerability 09.10.2026 8.5
CVE-2026-96327 WordPress WPLMS plugin < 1.9.9.8.2 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96328 WordPress JNews - Pay Writer plugin <= 12.0.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96329 WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability 09.10.2026 8.5
CVE-2026-96330 WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96331 WordPress Ajax Search Pro plugin <= 4.29.1 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-96332 WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-96333 WordPress GiveWP plugin <= 4.16.8.1 - Payment Bypass vulnerability 09.10.2026 7.5
CVE-2026-96334 WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability 09.10.2026 5.6
CVE-2026-96336 WordPress Forminator plugin <= 1.57.2 - Payment Bypass vulnerability 09.10.2026 7.5
CVE-2026-96337 WordPress ProfilePress plugin <= 4.17.3 - Broken Access Control vulnerability 09.10.2026 6.5
CVE-2026-96461 WordPress Amelia plugin <= 2.4.10 - Broken Access Control vulnerability 09.10.2026 7.5
CVE-2026-96518 WordPress ProfilePress plugin <= 4.17.3 - Broken Access Control vulnerability 09.10.2026 5.9
CVE-2026-96539 WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability 09.10.2026 5.6
CVE-2026-96553 WordPress FiboSearch plugin <= 1.34.1 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-96607 WordPress NEX-Forms plugin <= 9.3.1 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-96671 WordPress Featured Image from URL plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability 09.10.2026 8.8
CVE-2026-96761 WordPress Welcart e-Commerce plugin <= 2.12.3 - Cross Site Scripting (XSS) vulnerability 09.10.2026 7.1
CVE-2026-96809 WordPress EduAdmin Booking plugin < 6.0.0 - SQL Injection vulnerability 09.10.2026 9.3
CVE-2026-71884 Packet CTR reports a full success length after the counter is exhausted 09.10.2026
CVE-2026-78339 09.10.2026 6.3
CVE-2026-78340 09.10.2026 6.3
CVE-2026-78341 09.10.2026 6.5
CVE-2026-107935 Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose 09.10.2026
CVE-2026-62049 WordPress JetBlocks For Elementor plugin <= 1.5.2.1 - Cross Site Scripting (XSS) vulnerability 09.10.2026 6.5
CVE-2026-78023 09.10.2026 7.1
CVE-2026-78024 09.10.2026 7.7
CVE-2026-78025 09.10.2026 7.5
CVE-2026-78026 09.10.2026 4.3
CVE-2026-78027 09.10.2026 5.8
CVE-2026-107655 Cups: null pointer dereference via embedded job ticket comments allows remote denial of service 09.10.2026
CVE-2026-78021 09.10.2026 3.7
CVE-2026-78022 09.10.2026 6.8
CVE-2026-78016 09.10.2026 3.1
CVE-2026-78017 09.10.2026 3.8
CVE-2026-78018 09.10.2026 6.3
CVE-2026-78019 09.10.2026 7.5
CVE-2026-78020 09.10.2026 7.5
CVE-2026-104635 Uncontrolled recursion in elixir-protobuf/protobuf JSON decoding of self-referential messages 09.10.2026
CVE-2026-76769 09.10.2026 4.3
CVE-2026-76779 09.10.2026 7.4
CVE-2026-78013 09.10.2026 5.2
CVE-2026-78015 09.10.2026 3.7
CVE-2026-84220 Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection 09.10.2026 4.8
CVE-2026-84224 Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL 09.10.2026 4.1
CVE-2026-97075 WordPress WP Rocket plugin < 3.23.5 - Broken Access Control vulnerability 09.10.2026 6.5
CVE-2025-14123 Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation via Users Extension 09.10.2026 6.8
CVE-2026-4264 Reflected Cross-Site Scripting in BeeTienda eCommerce platform 09.10.2026
CVE-2026-98376 bpf: Use array_map_meta_equal for percpu array inner map replacement 09.10.2026
CVE-2026-98377 vlan: require the MAC header to be present in __vlan_insert_inner_tag() 09.10.2026
CVE-2026-98378 bpf: Skip unsettled links in link iterator 09.10.2026
CVE-2026-98379 netfilter: ip6t_rpfilter: reject routes without inet6_dev 09.10.2026
CVE-2026-98380 net/sched: reject IDR error pointers when deleting actions 09.10.2026
CVE-2026-98381 veth: manage XDP program pointers during channel resize 09.10.2026
CVE-2026-98382 bpf: Reject dev-bound-only programs on other devices 09.10.2026
CVE-2026-98383 bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL 09.10.2026
CVE-2026-98384 bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() 09.10.2026
CVE-2026-106145 Privilege Escalation in Telerik Report Server Service-Agent Hub 09.10.2026 7.1
CVE-2026-106155 Stored Cross-site Scripting (XSS) in Telerik Report Server Web Report Viewers 09.10.2026 8.9
CVE-2026-19569 Integer overflow in dynamic kernel object allocation allows user-mode threads to corrupt the kernel heap 09.10.2026 8.8
CVE-2026-19570 Out-of-bounds write in LE Audio Broadcast Sink when copying BASE subgroup metadata into the BASS receive state 09.10.2026 8.8
CVE-2026-19571 Race condition in ITE IT8xxx2 SHI host-command backend lets a second SPI request write an unvalidated length into the in-flight request buffer 09.10.2026 6.7
CVE-2026-19574 ARM64 MMU can assign an in-use ASID to a new memory domain, breaking user-mode memory isolation 09.10.2026 7
CVE-2026-19575 Type confusion in the device_deinit system call allows user-mode threads to execute arbitrary kernel code 09.10.2026 7.8
CVE-2026-98375 xen/netfront: drop RX packets with a short Ethernet header 09.10.2026
CVE-2026-101028 Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts 09.10.2026
CVE-2026-81929 Ocean Pro Demos <= 1.5.4 and Ocean eComm Treasure Box <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via 'content' Parameter 09.10.2026 7.2
CVE-2026-97076 WordPress WP Rocket plugin < 3.23.5 - Denial of Service Attack vulnerability 09.10.2026 7.5
CVE-2025-15700 AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import 09.10.2026
CVE-2026-106095 Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via update_code_snippet 09.10.2026
CVE-2026-106097 Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Credential Disclosure (Multisite) 09.10.2026
CVE-2026-86850 SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deletion 09.10.2026
CVE-2026-87841 UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook 09.10.2026
CVE-2026-88931 Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update 09.10.2026
CVE-2026-92989 SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing 09.10.2026
CVE-2026-92990 SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded Token 09.10.2026
CVE-2026-93548 FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation 09.10.2026
CVE-2026-87108 Ops Manager Improper Authorization in Daily Host Monitoring Retrieval 09.10.2026
CVE-2026-87109 Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings 09.10.2026
CVE-2026-87110 Ops Manager Uncontrolled Resource Consumption in Monitoring Endpoints 09.10.2026
CVE-2026-107908 Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET message 09.10.2026
CVE-2026-107909 Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via unbounded payload length 09.10.2026
CVE-2026-107910 Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling 09.10.2026
CVE-2026-107911 Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument 09.10.2026
CVE-2026-107914 09.10.2026 7.8
CVE-2026-107889 Keycloak-services: keycloak-services: stored xss on login page via kcsanitize bypass 09.10.2026
CVE-2026-107888 09.10.2026 5.1
CVE-2026-107890 09.10.2026 3.3
CVE-2026-5759 Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDB 09.10.2026
CVE-2026-7826 Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB 09.10.2026
CVE-2026-7827 Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDB 09.10.2026
CVE-2026-107885 09.10.2026 3.3
CVE-2026-107886 09.10.2026 2.3
CVE-2026-56857 Root.Mkdir(All) can follow junctions out of the root on Windows in os 09.10.2026
CVE-2026-56866 HTTP/1 client connection desynchronization after CONNECT rejection in net/http 09.10.2026
CVE-2026-78659 HTTP/2 server memory exhaustion due to Trailer headers in net/http 09.10.2026
CVE-2026-78660 HTTP/2 transport accepts malformed framing-related headers in net/http 08.10.2026
CVE-2026-78663 Double flow control refund on HTTP/2 server streams in net/http 08.10.2026
CVE-2026-78667 Lack of limit on size of parsed Range headers in net/http 08.10.2026
CVE-2026-78669 Excessive CPU consumption from repeated initial window changes in net/http 08.10.2026
CVE-2026-94439 HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http 08.10.2026
CVE-2026-94440 Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart 08.10.2026
CVE-2026-94444 Checksum bypass for golang.org/fips140 in cmd/go 08.10.2026
CVE-2026-94447 Checksum database bypass for golang.org/toolchain in cmd/go 08.10.2026
CVE-2026-94448 Reset context tracking on consecutive template expressions in html/template 08.10.2026
CVE-2026-97030 Recognize yield as regexp preceder keyword in html/template 08.10.2026
CVE-2026-97031 Reject malformed ECH outer extension references in crypto/tls 08.10.2026
CVE-2026-97032 HTTP/2 server crash due to HPACK encoder race in net/http 08.10.2026
CVE-2026-107735 SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initialization) 09.10.2026
CVE-2026-107736 SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata 09.10.2026
CVE-2026-107737 SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup 08.10.2026
CVE-2026-107738 SumatraPDF: Untrusted binary record offset used without lower-bound validation 08.10.2026
CVE-2026-107802 SumatraPDF — Windows command-line argument injection in AI selection-translate 08.10.2026
CVE-2026-100197 08.10.2026
CVE-2026-105672 Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB 08.10.2026
CVE-2026-105673 Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB 09.10.2026
CVE-2026-105674 Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB 08.10.2026
CVE-2026-107651 Eog: eog: arbitrary code execution via heap buffer overflow in png metadata reader 08.10.2026
CVE-2026-107727 Strawberry legacy graphql-ws retains naturally completed subscription slots 08.10.2026 3.7
CVE-2026-107728 Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy 08.10.2026 7.5
CVE-2026-107729 SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes out-of-bounds read 09.10.2026 5.5
CVE-2026-107730 SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read 09.10.2026 5.5
CVE-2026-107731 SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of service 09.10.2026 5.5
CVE-2026-107732 SumatraPDF: Markup/command-link injection into UI notification text 08.10.2026
CVE-2026-107733 SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open 08.10.2026
CVE-2026-107734 SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Execution via External Editors 09.10.2026
CVE-2026-69435 Azure SRE Agent Elevation of Privilege Vulnerability 09.10.2026 9.6
CVE-2026-77900 Azure App Service Remote Code Execution Vulnerability 09.10.2026 9.8
CVE-2026-83943 Azure API Center Information Disclosure Vulnerability 09.10.2026 8.7
CVE-2026-83947 Azure Event Grid Spoofing Vulnerability 09.10.2026 7.7
CVE-2026-88131 Microsoft Dataverse Remote Code Execution Vulnerability 09.10.2026 9.8
CVE-2026-94510 Microsoft Bookings Elevation of Privilege Vulnerability 09.10.2026 9.9
CVE-2026-96207 Microsoft Partner Center Elevation of Privilege Vulnerability 09.10.2026 10
CVE-2026-107725 Hazelcast: Authorization bypass in IMap Predicates API 09.10.2026
CVE-2026-107726 Hazelcast: Arbitrary member memory access by low-privileged client 09.10.2026
CVE-2025-71428 Jivejdon through 5.0 SQL Injection via username in userListAction 08.10.2026
CVE-2026-107723 fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array 08.10.2026 8.1
CVE-2026-107724 fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery 09.10.2026 7.4
CVE-2026-107792 Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Thread Move 08.10.2026
CVE-2026-107793 Jivejdon through 5.0 IDOR via subSaveAction Subscription Delete 09.10.2026
CVE-2026-107796 Jivejdon through commit ee67a65e Reflected XSS via taggedThreadList.jsp tagID and count Parameters 08.10.2026
CVE-2026-107797 Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters 09.10.2026
CVE-2026-107798 Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter 08.10.2026
CVE-2026-107799 Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering 08.10.2026
CVE-2026-107800 Jivejdon through 5.0 Stored XSS via Private Short Messages 09.10.2026
CVE-2026-107801 Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type 08.10.2026
CVE-2026-107828 Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login 09.10.2026
CVE-2026-107829 Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql 08.10.2026
CVE-2026-107830 Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint 08.10.2026
CVE-2026-107831 Jivejdon through 5.0 CSRF via GET-based Account and Thread Actions 09.10.2026
CVE-2026-107719 fast-jwt: Verifier cache accepts expired JWTs without iat. 09.10.2026 4.2
CVE-2026-107720 fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set 09.10.2026 7.4
CVE-2026-107721 fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache) 09.10.2026 5.9
CVE-2026-107722 fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion 08.10.2026 9.8
CVE-2026-89091 Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitrary file write / code execution 09.10.2026
CVE-2026-105269 Satel Netco Design Cross-site Scripting 09.10.2026
CVE-2026-107716 Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry 09.10.2026
CVE-2026-107717 Banks: User-controlled prompt input can be parsed as privileged chat messages 08.10.2026 6.5
CVE-2026-107718 AdonisJS: Unencoded route parameters can produce open redirects 08.10.2026 6.1
CVE-2026-75875 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 9.8
CVE-2026-80381 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 9.8
CVE-2026-81932 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 08.10.2026 8.6
CVE-2026-82895 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 8.1
CVE-2026-82900 IBM Guardium Data Protection is affected by multiple vulnerabilities. 08.10.2026 8.1
CVE-2026-84032 IBM Guardium Data Protection is affected by multiple vulnerabilities 09.10.2026 5.6
CVE-2026-84035 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 8.1
CVE-2026-84057 IBM Guardium Data Protection is affected by multiple vulnerabilities. 09.10.2026 8.1
CVE-2026-84058 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 8.1
CVE-2026-84198 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 8.1
CVE-2026-84209 IBM Guardium Data Protection is affected by multiple vulnerabilities. 09.10.2026 8.1
CVE-2026-84230 IBM Guardium Data Protection is affected by multiple vulnerabilities 09.10.2026 7.5
CVE-2026-84246 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 8.1
CVE-2026-84247 IBM Guardium Data Protection is affected by multiple vulnerabilities. 09.10.2026 8.1
CVE-2026-84249 IBM Guardium Data Protection is affected by vulnerability 09.10.2026 9.8
CVE-2026-107715 Mechanize sends credential headers to another host after an HTTP redirect 09.10.2026 6.8
CVE-2026-84875 Multiple vulnerabilities affect the Sniffer component as part of IBM Guardium Data Protection 09.10.2026 7.5
CVE-2026-84891 Security vulnerability affects the Windows GIM component as part of IBM Guardium Data Protection 09.10.2026 5.9