| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-104426 | Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check | ZcashFoundation | zebra | Medium | 5.9 | 2026-10-02 11:38:07 | Deep Dive |
| CVE-2026-104425 | Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions | ZcashFoundation | zebra | Medium | 5.3 | 2026-10-02 11:38:07 | Deep Dive |
| CVE-2026-104424 | Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate | ZcashFoundation | zebra | Low | 3.7 | 2026-10-02 11:38:06 | Deep Dive |
| CVE-2026-104423 | Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification | ZcashFoundation | zebra | High | 7.5 | 2026-10-02 11:38:05 | Deep Dive |
| CVE-2026-104422 | Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite | ZcashFoundation | zebra | High | 7.5 | 2026-10-02 11:38:04 | Deep Dive |
| CVE-2026-104420 | Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks | ZcashFoundation | zebra | Medium | 5.3 | 2026-10-02 11:38:02 | Deep Dive |
| CVE-2026-104421 | Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout | ZcashFoundation | zebra | Medium | 5.3 | 2026-10-02 11:38:02 | Deep Dive |
| CVE-2026-104419 | Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes | ZcashFoundation | zebra | Medium | 4.8 | 2026-10-02 11:38:01 | Deep Dive |
| CVE-2026-104417 | Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting | TryGhost | Ghost | Medium | 4.9 | 2026-10-02 11:38:00 | Deep Dive |
| CVE-2026-104418 | Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files | TryGhost | Ghost | High | 7.2 | 2026-10-02 11:38:00 | Deep Dive |
| CVE-2026-104416 | Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API | TryGhost | Ghost | High | 7.5 | 2026-10-02 11:37:59 | Deep Dive |
| CVE-2026-104414 | Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses | TryGhost | Ghost | High | 8.1 | 2026-10-02 11:37:58 | Deep Dive |
| CVE-2026-104415 | Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API | TryGhost | Ghost | Low | 3.1 | 2026-10-02 11:37:58 | Deep Dive |
| CVE-2026-104413 | Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images | TryGhost | Ghost | High | 7.3 | 2026-10-02 11:37:57 | Deep Dive |
| CVE-2026-104412 | Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment | TryGhost | Ghost | Medium | 4.3 | 2026-10-02 11:37:56 | Deep Dive |
| CVE-2026-104411 | Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads | TryGhost | Ghost | High | 7.3 | 2026-10-02 11:37:56 | Deep Dive |
| CVE-2026-104410 | SiYuan before 3.8.5 Information Disclosure via /api/export/preview | siyuan-note | siyuan | High | 7.5 | 2026-10-02 11:37:55 | Deep Dive |
| CVE-2026-103762 | SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints | siyuan-note | siyuan | Medium | 5.3 | 2026-10-02 11:37:54 | Deep Dive |
| CVE-2026-103763 | SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo | siyuan-note | siyuan | Medium | 5.8 | 2026-10-02 11:37:54 | Deep Dive |
| CVE-2026-85088 | Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match | Apache Software Foundation | Apache Thrift | Medium | 6.9 | 2026-10-02 11:37:15 | Deep Dive |