Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 36

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-103338 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) High 8.5 2026-10-01 12:24:11 Deep Dive
CVE-2026-103067 WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability Memberful Memberful - Membership Plugin High 8.0 2026-10-01 12:18:21 Deep Dive
CVE-2026-103754 Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory Red Hat Red Hat Ansible Automation Platform 2 Medium 5.9 2026-10-01 11:57:08 Deep Dive
CVE-2026-103336 WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability Smackcoders Inc. WP Ultimate CSV Importer Medium 5.3 2026-10-01 11:43:57 Deep Dive
CVE-2026-103680 Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation - - Low 3.1 2026-10-01 11:34:52 Deep Dive
CVE-2026-103679 Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction - - Medium 6.5 2026-10-01 11:34:50 Deep Dive
CVE-2026-103678 Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value - - Medium 5.4 2026-10-01 11:34:49 Deep Dive
CVE-2026-103858 MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions MISP MISP Medium 5.3 2026-10-01 11:31:33 Deep Dive
CVE-2026-94276 Apache APISIX: Openid-connect introspection validation issue Apache Software Foundation Apache APISIX Medium 5.1 2026-10-01 11:02:37 Deep Dive
CVE-2026-94269 Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch Apache Software Foundation Apache APISIX Medium 6.3 2026-10-01 11:02:20 Deep Dive
CVE-2026-94250 Apache APISIX: Batch response aggregation can exhaust worker memory Apache Software Foundation Apache APISIX High 8.2 2026-10-01 11:01:41 Deep Dive
CVE-2026-94220 Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin Apache Software Foundation Apache APISIX Low 2.1 2026-10-01 11:01:27 Deep Dive
CVE-2026-94212 Apache APISIX: unauthenticated impersonation issue in saml-auth Apache Software Foundation Apache APISIX Medium 6.4 2026-10-01 11:01:12 Deep Dive
CVE-2026-82806 Apache APISIX: cross-request permission pollution via static permission list mutation Apache Software Foundation Apache APISIX Medium 5.3 2026-10-01 10:58:33 Deep Dive
CVE-2026-78242 Apache APISIX: data-mask may fail to redact request headers in logger output Apache Software Foundation Apache APISIX Medium 5.7 2026-10-01 10:58:13 Deep Dive
CVE-2026-88789 Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening Apache Software Foundation Apache Camel Quarkus High 8.6 2026-10-01 10:51:23 Deep Dive
CVE-2026-103353 WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability WP ManageNinja LLC FluentForm Medium 5.3 2026-10-01 10:48:43 Deep Dive
CVE-2026-103758 Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route obot-platform obot High 8.1 2026-10-01 10:42:27 Deep Dive
CVE-2026-103757 Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation Budibase budibase High 7.7 2026-10-01 10:42:26 Deep Dive
CVE-2026-103292 Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head TryGhost Ghost High 8.0 2026-10-01 10:42:25 Deep Dive