Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 42

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-89047 Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL inisev Social Media Share Buttons & Social Sharing Icons Medium 6.1 2026-10-01 07:40:22 Deep Dive
CVE-2026-103651 MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass MISP MISP High 7.6 2026-10-01 07:34:03 Deep Dive
CVE-2025-41753 Path traversal in dynamically created BACnet File Objects WAGO 0751-9x01 Critical 9.8 2026-10-01 06:42:01 Deep Dive
CVE-2026-103544 datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong session datadrivenconstruction OpenConstructionERP Medium 6.3 2026-10-01 06:15:12 Deep Dive
CVE-2026-96173 Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR Unknown Payments for Hubtel - - 2026-10-01 06:00:26 Deep Dive
CVE-2026-96200 Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback Unknown Payments for Hubtel - - 2026-10-01 06:00:26 Deep Dive
CVE-2026-96255 Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug Log Unknown Payments for Hubtel - - 2026-10-01 06:00:26 Deep Dive
CVE-2026-89296 Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter Unknown Pro Like Button - - 2026-10-01 06:00:25 Deep Dive
CVE-2026-87973 If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name Unknown If-So Dynamic Content - - 2026-10-01 06:00:25 Deep Dive
CVE-2026-87970 If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes Unknown If-So Dynamic Content - - 2026-10-01 06:00:25 Deep Dive
CVE-2026-92412 Five Star Restaurant Reviews < 2.3.14 - Reflected XSS Unknown Five Star Restaurant Reviews - - 2026-10-01 06:00:25 Deep Dive
CVE-2026-90972 WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion Unknown WP Fusion Lite - - 2026-10-01 06:00:25 Deep Dive
CVE-2026-90974 WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update Unknown WP Fusion Lite - - 2026-10-01 06:00:25 Deep Dive
CVE-2026-19253 Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url Unknown Cache Enabler - - 2026-10-01 06:00:24 Deep Dive
CVE-2026-81739 Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback Unknown Paytm Payment Gateway - - 2026-10-01 06:00:24 Deep Dive
CVE-2026-81809 Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback Unknown Paytm Payment Gateway - - 2026-10-01 06:00:24 Deep Dive
CVE-2026-86610 Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon Unknown Download Manager - - 2026-10-01 06:00:24 Deep Dive
CVE-2026-101148 BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key Unknown BackupSheep WordPress Backup Plugin - - 2026-10-01 06:00:23 Deep Dive
CVE-2026-101147 Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF Unknown Featured Image from URL (FIFU) - - 2026-10-01 06:00:23 Deep Dive
CVE-2026-103543 itsourcecode Leave Management System controller.php sql injection itsourcecode Leave Management System Medium 6.3 2026-10-01 06:00:12 Deep Dive