| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103687 | rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist | rhukster | dom-sanitizer | High | 7.3 | 2026-10-01 14:30:13 | Deep Dive |
| CVE-2024-58388 | Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html | Sharp Corporation | Multiple Multifunction Printers | High | 7.5 | 2026-10-01 14:24:21 | Deep Dive |
| CVE-2026-79900 | Heap overflow in KSL checksum initialization | Fortra | BoKS Manager boks-server | Medium | 6.5 | 2026-10-01 14:11:55 | Deep Dive |
| CVE-2026-79901 | Predictable Active Directory service-account passwords in BoKS Manager | Fortra | BoKS Manager boks-server | Critical | 9.9 | 2026-10-01 13:52:27 | Deep Dive |
| CVE-2026-103686 | rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross site scripting | rhukster | dom-sanitizer | Low | 3.5 | 2026-10-01 13:45:12 | Deep Dive |
| CVE-2026-66253 | HCL iControl is affected by a Session Timeout vulnerability | HCL Software | iControl | Low | 3.1 | 2026-10-01 13:30:03 | Deep Dive |
| CVE-2026-66249 | HCL iControl is affected by a Missing Secure Attribute vulnerability | HCL Software | iControl | Low | 3.1 | 2026-10-01 13:29:22 | Deep Dive |
| CVE-2026-66248 | HCL iControl is affected by an Improper Error Handling vulnerability | HCL Software | iControl | Low | 3.1 | 2026-10-01 13:26:31 | Deep Dive |
| CVE-2026-66247 | iControl不安全CORS策略致敏感数据泄露漏洞 | HCL Software | iControl | Medium | 4.3 | 2026-10-01 13:25:14 | Deep Dive |
| CVE-2026-66246 | HCL iControl is affected by multiple security vulnerabilities | HCL Software | iControl | High | 8.8 | 2026-10-01 13:23:26 | Deep Dive |
| CVE-2026-102505 | Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp | - | - | - | - | 2026-10-01 13:11:52 | Deep Dive |
| CVE-2026-102504 | Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol | - | - | - | - | 2026-10-01 13:11:39 | Deep Dive |
| CVE-2026-62058 | WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability | WPExperts | CF7 Apps | Medium | 5.3 | 2026-10-01 12:40:18 | Deep Dive |
| CVE-2026-62059 | WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability | Ultimate Member | Ultimate Member | High | 7.6 | 2026-10-01 12:39:50 | Deep Dive |
| CVE-2026-62060 | WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability | captivateaudio | Captivate Sync | High | 7.6 | 2026-10-01 12:39:21 | Deep Dive |
| CVE-2026-62061 | WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (IDOR) vulnerability | Metagauss | ProfileGrid | Medium | 5.3 | 2026-10-01 12:38:51 | Deep Dive |
| CVE-2026-62063 | WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability | Magepeople inc. | WpTravelly | Medium | 5.4 | 2026-10-01 12:38:26 | Deep Dive |
| CVE-2026-102394 | WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripting (XSS) vulnerability | WPDeveloper | Essential Addons for Elementor | Medium | 6.5 | 2026-10-01 12:35:40 | Deep Dive |
| CVE-2026-103339 | WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability | Wpmet | Metform | Medium | 6.5 | 2026-10-01 12:34:57 | Deep Dive |
| CVE-2026-102379 | WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection vulnerability | VillaTheme | BuildKit – Product Builder for WooCommerce – Custom PC Builder | High | 8.5 | 2026-10-01 12:34:15 | Deep Dive |