| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103276 | Ghost before 6.20.0 File Read via URL Encoding Bypass | TryGhost | Ghost | Medium | 5.3 | 2026-10-01 10:42:14 | Deep Dive |
| CVE-2026-103274 | Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read | TryGhost | Ghost | Medium | 5.3 | 2026-10-01 10:42:13 | Deep Dive |
| CVE-2026-103275 | Ghost 5.42.2 before 6.58.0 Password Hash Disclosure | TryGhost | Ghost | Medium | 4.3 | 2026-10-01 10:42:13 | Deep Dive |
| CVE-2026-103273 | Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token | TryGhost | Ghost | Medium | 4.3 | 2026-10-01 10:42:12 | Deep Dive |
| CVE-2026-103272 | Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API | TryGhost | Ghost | High | 7.5 | 2026-10-01 10:42:11 | Deep Dive |
| CVE-2026-103271 | Ghost 4.0.0 before 6.63.0 Restricted Content Bypass | TryGhost | Ghost | High | 7.5 | 2026-10-01 10:42:10 | Deep Dive |
| CVE-2026-103269 | Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts | TryGhost | Ghost | Medium | 5.3 | 2026-10-01 10:42:10 | Deep Dive |
| CVE-2026-103268 | Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset | TryGhost | Ghost | High | 8.8 | 2026-10-01 10:42:09 | Deep Dive |
| CVE-2026-103266 | Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification | TryGhost | Ghost | High | 7.1 | 2026-10-01 10:42:08 | Deep Dive |
| CVE-2026-103267 | Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite | TryGhost | Ghost | Medium | 4.3 | 2026-10-01 10:42:08 | Deep Dive |
| CVE-2026-103265 | Fleet before 4.89.0 Information Disclosure via MDM Command Results | fleetdm | fleet | Medium | 4.3 | 2026-10-01 10:42:07 | Deep Dive |
| CVE-2026-103264 | Fleet before 4.87.0 Authentication Bypass via Device Identifiers | fleetdm | fleet | Critical | 9.1 | 2026-10-01 10:42:06 | Deep Dive |
| CVE-2026-103263 | Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink | tornadoweb | tornado | Medium | 5.9 | 2026-10-01 10:42:06 | Deep Dive |
| CVE-2026-103262 | Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient | tornadoweb | tornado | High | 7.5 | 2026-10-01 10:42:05 | Deep Dive |
| CVE-2026-103260 | n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node | n8n-io | n8n | Medium | 4.0 | 2026-10-01 10:42:04 | Deep Dive |
| CVE-2026-103261 | Tornado before 6.5.9 Denial of Service via Query String | tornadoweb | tornado | Medium | 5.3 | 2026-10-01 10:42:04 | Deep Dive |
| CVE-2026-103259 | n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials | n8n-io | n8n | High | 7.6 | 2026-10-01 10:42:03 | Deep Dive |
| CVE-2026-103258 | n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation | n8n-io | n8n | Medium | 6.8 | 2026-10-01 10:42:02 | Deep Dive |
| CVE-2026-103257 | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node | n8n-io | n8n | High | 7.7 | 2026-10-01 10:42:01 | Deep Dive |
| CVE-2026-103256 | n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook | n8n-io | n8n | High | 7.1 | 2026-10-01 10:42:01 | Deep Dive |