| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103247 | n8n before 1.123.80 Credential Tampering via Duplicate Node IDs | n8n-io | n8n | High | 8.5 | 2026-10-01 10:41:54 | Deep Dive |
| CVE-2026-103245 | n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification | n8n-io | n8n | Medium | 5.3 | 2026-10-01 10:41:53 | Deep Dive |
| CVE-2026-103246 | n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspection | n8n-io | n8n | High | 7.7 | 2026-10-01 10:41:53 | Deep Dive |
| CVE-2026-103244 | ground-station before 0.8.0 Authentication Bypass via setup.restore | sgoudelis | ground-station | Critical | 9.8 | 2026-10-01 10:41:52 | Deep Dive |
| CVE-2026-103082 | WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability | LA-Studio | LA-Studio Element Kit for Elementor | High | 7.2 | 2026-10-01 10:40:12 | Deep Dive |
| CVE-2026-7176 | Multiple vulnerabilities in Entradium by Crocantickets | Crocantickets | Entradium | Medium | 4.8 | 2026-10-01 09:54:27 | Deep Dive |
| CVE-2026-7175 | Multiple vulnerabilities in Entradium by Crocantickets | Crocantickets | Entradium | Medium | 4.8 | 2026-10-01 09:54:19 | Deep Dive |
| CVE-2026-7174 | Multiple vulnerabilities in Entradium by Crocantickets | Crocantickets | Entradium | Medium | 4.8 | 2026-10-01 09:54:10 | Deep Dive |
| CVE-2026-7173 | Multiple vulnerabilities in Entradium by Crocantickets | Crocantickets | Entradium | Medium | 4.8 | 2026-10-01 09:54:02 | Deep Dive |
| CVE-2026-75786 | SQL Injection in Grafana Integration Endpoint (query.php) | Pandora FMS | Pandora FMS | High | 7.2 | 2026-10-01 09:30:49 | Deep Dive |
| CVE-2026-64950 | Stored Cross-Site Scripting via Directory Name in File Manager Create Directory | Pandora FMS | Pandora FMS | High | 8.4 | 2026-10-01 09:30:10 | Deep Dive |
| CVE-2026-64949 | Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File Manager | Pandora FMS | Pandora FMS | High | 8.6 | 2026-10-01 09:29:31 | Deep Dive |
| CVE-2026-64948 | Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group Module Data Disclosure | Pandora FMS | Pandora FMS | High | 7.1 | 2026-10-01 09:28:34 | Deep Dive |
| CVE-2026-64947 | CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in Plugin File Manager | Pandora FMS | Pandora FMS | High | 7.5 | 2026-10-01 09:27:47 | Deep Dive |
| CVE-2026-92144 | Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | High | 7.2 | 2026-10-01 09:26:58 | Deep Dive |
| CVE-2026-96256 | Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2026-10-01 09:26:58 | Deep Dive |
| CVE-2026-64946 | CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Upload in File Manager | Pandora FMS | Pandora FMS | High | 7.4 | 2026-10-01 09:26:53 | Deep Dive |
| CVE-2026-34190 | CSRF in Alert Command Deletion | Pandora FMS | Pandora FMS | Medium | 5.9 | 2026-10-01 09:26:01 | Deep Dive |
| CVE-2026-34189 | CSRF in Event Response Deletion | Pandora FMS | Pandora FMS | Medium | 5.9 | 2026-10-01 09:24:44 | Deep Dive |
| CVE-2026-96577 | Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled | Red Hat | Assisted Installer for Red Hat OpenShift Container Platform 2 | High | 7.1 | 2026-10-01 09:17:54 | Deep Dive |