CVE-2026-39721 - WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerability
CVE ID :CVE-2026-39721
Published : Oct. 5, 2026, 9:17 a.m. | 54 minutes ago
Description :Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39721
Published : Oct. 5, 2026, 9:17 a.m. | 54 minutes ago
Description :Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97071 - WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability
CVE ID :CVE-2026-97071
Published : Oct. 5, 2026, 9:17 a.m. | 54 minutes ago
Description :Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97071
Published : Oct. 5, 2026, 9:17 a.m. | 54 minutes ago
Description :Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19395 - An empty attribute value in styled text triggers a parser error that halts the device.
CVE ID :CVE-2026-19395
Published : Oct. 5, 2026, 9:18 a.m. | 53 minutes ago
Description :In Qt for MCUs, a Text element that displays styled text halts the device if an tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19395
Published : Oct. 5, 2026, 9:18 a.m. | 53 minutes ago
Description :In Qt for MCUs, a Text element that displays styled text halts the device if an tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105286 - Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal
CVE ID :CVE-2026-105286
Published : Oct. 5, 2026, 9:30 a.m. | 41 minutes ago
Description :A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105286
Published : Oct. 5, 2026, 9:30 a.m. | 41 minutes ago
Description :A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105287 - feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql injection
CVE ID :CVE-2026-105287
Published : Oct. 5, 2026, 9:45 a.m. | 26 minutes ago
Description :A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105287
Published : Oct. 5, 2026, 9:45 a.m. | 26 minutes ago
Description :A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39763 - WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control vulnerability
CVE ID :CVE-2026-39763
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39763
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59782 - JavaScript preprocessing memory disclosure
CVE ID :CVE-2026-59782
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59782
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59783 - Server DoS via binary items
CVE ID :CVE-2026-59783
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59783
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59785 - Hidden host credentials inferable via multiselect.get filtering
CVE ID :CVE-2026-59785
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59785
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59786 - Active agent heartbeat missing TLS check
CVE ID :CVE-2026-59786
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59786
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59787 - SNMP trap injection in zabbix_trap_receiver.pl
CVE ID :CVE-2026-59787
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59787
Published : Oct. 5, 2026, 11:16 a.m. | 2 hours, 56 minutes ago
Description :The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59788 - Stored XSS vulnerability in OAuth configuration form
CVE ID :CVE-2026-59788
Published : Oct. 5, 2026, 11:17 a.m. | 2 hours, 56 minutes ago
Description :The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-59788
Published : Oct. 5, 2026, 11:17 a.m. | 2 hours, 56 minutes ago
Description :The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94669 - WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Broken Access Control vulnerability
CVE ID :CVE-2026-94669
Published : Oct. 5, 2026, 11:17 a.m. | 2 hours, 56 minutes ago
Description :Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-94669
Published : Oct. 5, 2026, 11:17 a.m. | 2 hours, 56 minutes ago
Description :Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103684 - WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability
CVE ID :CVE-2026-103684
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103684
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105073 - WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-105073
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105073
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105307 - Casdoor API Endpoint authz_filter.go ApiFilter missing authentication
CVE ID :CVE-2026-105307
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105307
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105396 - Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header
CVE ID :CVE-2026-105396
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-105396
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains, capturing capability tokens to submit decisions executed with owner credentials.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-39783 - WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-39783
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-39783
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63266 - Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality
CVE ID :CVE-2026-63266
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-63266
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63267 - LFI and GET SSRF via calcext:data-mappings and csv provider
CVE ID :CVE-2026-63267
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-63267
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-63268 - LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href
CVE ID :CVE-2026-63268
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are restored when a document is loaded.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-63268
Published : Oct. 5, 2026, 12:17 p.m. | 1 hour, 56 minutes ago
Description :LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are restored when a document is loaded.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...