| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-89047 | Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL | inisev | Social Media Share Buttons & Social Sharing Icons | Medium | 6.1 | 2026-10-01 07:40:22 | Deep Dive |
| CVE-2026-103651 | MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass | MISP | MISP | High | 7.6 | 2026-10-01 07:34:03 | Deep Dive |
| CVE-2025-41753 | Path traversal in dynamically created BACnet File Objects | WAGO | 0751-9x01 | Critical | 9.8 | 2026-10-01 06:42:01 | Deep Dive |
| CVE-2026-103544 | datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong session | datadrivenconstruction | OpenConstructionERP | Medium | 6.3 | 2026-10-01 06:15:12 | Deep Dive |
| CVE-2026-96173 | Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR | Unknown | Payments for Hubtel | - | - | 2026-10-01 06:00:26 | Deep Dive |
| CVE-2026-96200 | Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback | Unknown | Payments for Hubtel | - | - | 2026-10-01 06:00:26 | Deep Dive |
| CVE-2026-96255 | Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log | Unknown | Payments for Hubtel | - | - | 2026-10-01 06:00:26 | Deep Dive |
| CVE-2026-89296 | Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter | Unknown | Pro Like Button | - | - | 2026-10-01 06:00:25 | Deep Dive |
| CVE-2026-87973 | If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name | Unknown | If-So Dynamic Content | - | - | 2026-10-01 06:00:25 | Deep Dive |
| CVE-2026-87970 | If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes | Unknown | If-So Dynamic Content | - | - | 2026-10-01 06:00:25 | Deep Dive |
| CVE-2026-92412 | Five Star Restaurant Reviews < 2.3.14 - Reflected XSS | Unknown | Five Star Restaurant Reviews | - | - | 2026-10-01 06:00:25 | Deep Dive |
| CVE-2026-90972 | WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion | Unknown | WP Fusion Lite | - | - | 2026-10-01 06:00:25 | Deep Dive |
| CVE-2026-90974 | WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update | Unknown | WP Fusion Lite | - | - | 2026-10-01 06:00:25 | Deep Dive |
| CVE-2026-19253 | Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url | Unknown | Cache Enabler | - | - | 2026-10-01 06:00:24 | Deep Dive |
| CVE-2026-81739 | Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback | Unknown | Paytm Payment Gateway | - | - | 2026-10-01 06:00:24 | Deep Dive |
| CVE-2026-81809 | Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback | Unknown | Paytm Payment Gateway | - | - | 2026-10-01 06:00:24 | Deep Dive |
| CVE-2026-86610 | Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon | Unknown | Download Manager | - | - | 2026-10-01 06:00:24 | Deep Dive |
| CVE-2026-101148 | BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key | Unknown | BackupSheep WordPress Backup Plugin | - | - | 2026-10-01 06:00:23 | Deep Dive |
| CVE-2026-101147 | Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF | Unknown | Featured Image from URL (FIFU) | - | - | 2026-10-01 06:00:23 | Deep Dive |
| CVE-2026-103543 | itsourcecode Leave Management System controller.php sql injection | itsourcecode | Leave Management System | Medium | 6.3 | 2026-10-01 06:00:12 | Deep Dive |