| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103338 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | High | 8.5 | 2026-10-01 12:24:11 | Deep Dive |
| CVE-2026-103067 | WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability | Memberful | Memberful - Membership Plugin | High | 8.0 | 2026-10-01 12:18:21 | Deep Dive |
| CVE-2026-103754 | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory | Red Hat | Red Hat Ansible Automation Platform 2 | Medium | 5.9 | 2026-10-01 11:57:08 | Deep Dive |
| CVE-2026-103336 | WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerability | Smackcoders Inc. | WP Ultimate CSV Importer | Medium | 5.3 | 2026-10-01 11:43:57 | Deep Dive |
| CVE-2026-103680 | Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation | - | - | Low | 3.1 | 2026-10-01 11:34:52 | Deep Dive |
| CVE-2026-103679 | Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction | - | - | Medium | 6.5 | 2026-10-01 11:34:50 | Deep Dive |
| CVE-2026-103678 | Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value | - | - | Medium | 5.4 | 2026-10-01 11:34:49 | Deep Dive |
| CVE-2026-103858 | MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions | MISP | MISP | Medium | 5.3 | 2026-10-01 11:31:33 | Deep Dive |
| CVE-2026-94276 | Apache APISIX: Openid-connect introspection validation issue | Apache Software Foundation | Apache APISIX | Medium | 5.1 | 2026-10-01 11:02:37 | Deep Dive |
| CVE-2026-94269 | Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch | Apache Software Foundation | Apache APISIX | Medium | 6.3 | 2026-10-01 11:02:20 | Deep Dive |
| CVE-2026-94250 | Apache APISIX: Batch response aggregation can exhaust worker memory | Apache Software Foundation | Apache APISIX | High | 8.2 | 2026-10-01 11:01:41 | Deep Dive |
| CVE-2026-94220 | Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin | Apache Software Foundation | Apache APISIX | Low | 2.1 | 2026-10-01 11:01:27 | Deep Dive |
| CVE-2026-94212 | Apache APISIX: unauthenticated impersonation issue in saml-auth | Apache Software Foundation | Apache APISIX | Medium | 6.4 | 2026-10-01 11:01:12 | Deep Dive |
| CVE-2026-82806 | Apache APISIX: cross-request permission pollution via static permission list mutation | Apache Software Foundation | Apache APISIX | Medium | 5.3 | 2026-10-01 10:58:33 | Deep Dive |
| CVE-2026-78242 | Apache APISIX: data-mask may fail to redact request headers in logger output | Apache Software Foundation | Apache APISIX | Medium | 5.7 | 2026-10-01 10:58:13 | Deep Dive |
| CVE-2026-88789 | Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening | Apache Software Foundation | Apache Camel Quarkus | High | 8.6 | 2026-10-01 10:51:23 | Deep Dive |
| CVE-2026-103353 | WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability | WP ManageNinja LLC | FluentForm | Medium | 5.3 | 2026-10-01 10:48:43 | Deep Dive |
| CVE-2026-103758 | Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ Route | obot-platform | obot | High | 8.1 | 2026-10-01 10:42:27 | Deep Dive |
| CVE-2026-103757 | Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation | Budibase | budibase | High | 7.7 | 2026-10-01 10:42:26 | Deep Dive |
| CVE-2026-103292 | Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head | TryGhost | Ghost | High | 8.0 | 2026-10-01 10:42:25 | Deep Dive |