| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67105 | HCL BigFix Service Management is affected by multiple security vulnerabilities. | HCL Software | HCL BigFix Service Management | High | 7.4 | 2026-10-01 14:57:45 | Deep Dive |
| CVE-2026-79898 | Fortra BoKS Manager crlserver command injection vulnerability | Fortra | BoKS Manager | Critical | 9.1 | 2026-10-01 14:57:28 | Deep Dive |
| CVE-2026-56589 | HCL BigFix Service Management is affected by multiple security vulnerabilities. | HCL Software | HCL BigFix Service Management | High | 7.2 | 2026-10-01 14:55:42 | Deep Dive |
| CVE-2026-97280 | WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability | Mamunur Rashid | Review Schema | Medium | 6.5 | 2026-10-01 14:52:03 | Deep Dive |
| CVE-2026-103004 | next.js cache leak on warm `use cache` handlers accessing root param | vercel | next.js | Medium | 6.3 | 2026-10-01 14:50:27 | Deep Dive |
| CVE-2026-79899 | Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability | Fortra | BoKS Manager | High | 7.9 | 2026-10-01 14:37:24 | Deep Dive |
| CVE-2026-103347 | WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability | hcaptcha | hCaptcha for WP | Medium | 5.3 | 2026-10-01 14:34:08 | Deep Dive |
| CVE-2026-103068 | WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation vulnerability | ByteCore Stack | ByteCoreStack – MCP Connector for AI Tools | High | 8.8 | 2026-10-01 14:34:07 | Deep Dive |
| CVE-2026-102378 | WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability | bPlugins | Parallax Section block | High | 7.1 | 2026-10-01 14:34:06 | Deep Dive |
| CVE-2026-100517 | WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object References (IDOR) vulnerability | VillaTheme | Photo Reviews for WooCommerce | High | 7.5 | 2026-10-01 14:34:05 | Deep Dive |
| CVE-2026-100514 | WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnerability | Pete Nelson | REST API Log | High | 7.5 | 2026-10-01 14:34:05 | Deep Dive |
| CVE-2026-97297 | WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability | Apps Mav | Gratisfaction | High | 7.6 | 2026-10-01 14:34:04 | Deep Dive |
| CVE-2026-97284 | WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability | Icegram | Icegram | High | 8.8 | 2026-10-01 14:34:03 | Deep Dive |
| CVE-2026-97281 | WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerability | weDevs | WP Project Manager | Medium | 6.3 | 2026-10-01 14:34:03 | Deep Dive |
| CVE-2026-97277 | WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability | Apps Mav | Social Boost | High | 7.6 | 2026-10-01 14:34:01 | Deep Dive |
| CVE-2026-97269 | WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDOR) vulnerability | WPFunnels | WPFunnels | Medium | 6.5 | 2026-10-01 14:34:00 | Deep Dive |
| CVE-2026-97273 | WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability | Premmerce | Premmerce Wishlist for WooCommerce | High | 7.1 | 2026-10-01 14:34:00 | Deep Dive |
| CVE-2026-97268 | WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Scripting (XSS) vulnerability | Premmerce | Premmerce Wishlist for WooCommerce | High | 7.1 | 2026-10-01 14:33:59 | Deep Dive |
| CVE-2026-97260 | WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability | maxfoundry | MaxGalleria | High | 7.1 | 2026-10-01 14:33:58 | Deep Dive |
| CVE-2026-97258 | WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability | Aruba.it | Aruba Migration Tool | Medium | 6.5 | 2026-10-01 14:33:57 | Deep Dive |