| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-78471 | Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name | optimizingmatters | Autoptimize | Medium | 5.4 | 2026-10-02 05:30:18 | Deep Dive |
| CVE-2026-15897 | Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login | WebRehab | Super Forms – Drag & Drop Form Builder | High | 8.8 | 2026-10-02 05:30:17 | Deep Dive |
| CVE-2026-92820 | Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload | SaturdayDrive | Ninja Forms - File Uploads | High | 8.1 | 2026-10-02 05:30:16 | Deep Dive |
| CVE-2026-84925 | Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter | ThemeFusion | Avada | Website Builder For WordPress & WooCommerce | Medium | 6.1 | 2026-10-02 05:30:15 | Deep Dive |
| CVE-2026-10026 | CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution | CTX | CTX Feed Pro | High | 7.2 | 2026-10-02 04:27:12 | Deep Dive |
| CVE-2026-19660 | Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter | DiviEngine | Divi Membership | Critical | 9.8 | 2026-10-02 04:27:11 | Deep Dive |
| CVE-2026-93367 | Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title) | wp-buy | Visitor Traffic Real Time Statistics pro | High | 7.2 | 2026-10-02 03:38:47 | Deep Dive |
| CVE-2026-14378 | DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow | dplugins | DevKit Pro | Critical | 9.8 | 2026-10-02 03:38:46 | Deep Dive |
| CVE-2026-104123 | SourceCodester Online Reviewer Management System btn_functions.php activity sql injection | SourceCodester | Online Reviewer Management System | High | 7.3 | 2026-10-02 02:45:13 | Deep Dive |
| CVE-2026-104120 | modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery | modelcontextprotocol | mcp-server-fetch | High | 7.3 | 2026-10-02 02:15:19 | Deep Dive |
| CVE-2026-104054 | calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization | calcom | cal.diy | Medium | 6.3 | 2026-10-02 02:00:12 | Deep Dive |
| CVE-2026-104053 | itsourcecode Pet Shop Management System admin_reservefilter.php sql injection | itsourcecode | Pet Shop Management System | Medium | 6.3 | 2026-10-02 01:15:16 | Deep Dive |
| CVE-2026-21140 | ManagedProvisioning <SMR Sep-2026 R1 访问控制缺陷致任意应用安装 | Samsung Mobile | Samsung Mobile Devices | Medium | 6.9 | 2026-10-02 01:05:40 | Deep Dive |
| CVE-2026-104052 | itsourcecode Pet Shop Management System admin_reject_completed.php sql injection | itsourcecode | Pet Shop Management System | Medium | 6.3 | 2026-10-02 01:00:15 | Deep Dive |
| CVE-2026-104480 | Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership | Discord | libdave | Critical | 9.4 | 2026-10-02 00:57:56 | Deep Dive |
| CVE-2026-103098 | GV-Eye Sensitive information exposure in URL query parameter Vulnerability | GeoVision Inc. | GV-Eye | High | 7.5 | 2026-10-02 00:15:18 | Deep Dive |
| CVE-2026-103097 | GV-Eye Relay Payment API Key Vulnerability | GeoVision Inc. | GV-Eye | High | 7.5 | 2026-10-02 00:14:47 | Deep Dive |
| CVE-2026-103096 | GV-Eye Hardcoded API Key Vulnerability | GeoVision Inc. | GV-Eye | High | 7.5 | 2026-10-02 00:14:08 | Deep Dive |
| CVE-2026-51906 | TaskingAI v0.3.0 DALL-E 3目录遍历漏洞 | - | - | - | - | 2026-10-02 00:00:00 | Deep Dive |
| CVE-2026-51904 | SuperAGI≤v0.0.14越权漏洞 | - | - | - | - | 2026-10-02 00:00:00 | Deep Dive |