| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-12241 | Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | mihail-barinov | Advanced Woo Labels – Product Labels & Badges for WooCommerce | Medium | 5.4 | 2026-10-01 04:27:34 | Deep Dive |
| CVE-2026-92966 | Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | Critical | 9.1 | 2026-10-01 04:27:34 | Deep Dive |
| CVE-2026-92548 | WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters | hcabrera | WP Popular Posts | Medium | 5.3 | 2026-10-01 04:27:33 | Deep Dive |
| CVE-2026-103536 | ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication | ZongXR | Supermarket | High | 7.3 | 2026-10-01 04:15:10 | Deep Dive |
| CVE-2026-103641 | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder | Red Hat | Red Hat Enterprise Linux 10 | Medium | 5.5 | 2026-10-01 03:43:07 | Deep Dive |
| CVE-2026-103534 | David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control | David-Crty | databasement | Medium | 6.3 | 2026-10-01 03:30:12 | Deep Dive |
| CVE-2026-91109 | Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter | croixhaug | Simply Schedule Appointments | Medium | 6.5 | 2026-10-01 03:28:23 | Deep Dive |
| CVE-2026-92245 | Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce | croixhaug | Simply Schedule Appointments | High | 7.5 | 2026-10-01 03:28:22 | Deep Dive |
| CVE-2026-96561 | AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection | tigroumeow | AI Engine – The Chatbot, AI Framework & MCP for WordPress | High | 7.2 | 2026-10-01 03:28:22 | Deep Dive |
| CVE-2026-103533 | David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal | David-Crty | databasement | Medium | 4.1 | 2026-10-01 02:45:11 | Deep Dive |
| CVE-2026-101887 | BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS | arkq | bluez-alsa | Low | 3.5 | 2026-10-01 02:28:18 | Deep Dive |
| CVE-2026-92537 | Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure) | satollo | Newsletter – Send awesome emails from WordPress | Medium | 5.3 | 2026-10-01 02:27:46 | Deep Dive |
| CVE-2026-13313 | 华硕路由器调试代码漏洞致Telnet开启及Root命令执行 | ASUS | Router | High | 8.9 | 2026-10-01 02:00:57 | Deep Dive |
| CVE-2026-14157 | 华硕路由器受控格式字符串致远程命令执行漏洞 | ASUS | Router | Critical | 9.4 | 2026-10-01 02:00:34 | Deep Dive |
| CVE-2026-93495 | 华硕特定主板物理内存读写漏洞 | ASUS | Motherboard(PRIME Z390-A ) | High | 7.0 | 2026-10-01 02:00:12 | Deep Dive |
| CVE-2026-103532 | immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization | immich-app | Immich | Medium | 5.3 | 2026-10-01 01:15:17 | Deep Dive |
| CVE-2026-103531 | OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow | - | OpenSC | Medium | 5.5 | 2026-10-01 00:45:16 | Deep Dive |
| CVE-2026-51883 | Langchain-Chatchat 0.3.x 知识库创建接口路径穿越漏洞 | - | - | - | - | 2026-10-01 00:00:00 | Deep Dive |
| CVE-2026-51894 | RAGFlow 0.24.0 任意文件读取漏洞 | - | - | - | - | 2026-10-01 00:00:00 | Deep Dive |
| CVE-2026-51874 | Devika v1.0路径穿越漏洞 | - | - | - | - | 2026-10-01 00:00:00 | Deep Dive |