Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 46

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-12241 Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Improper Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting mihail-barinov Advanced Woo Labels – Product Labels & Badges for WooCommerce Medium 5.4 2026-10-01 04:27:34 Deep Dive
CVE-2026-92966 Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Critical 9.1 2026-10-01 04:27:34 Deep Dive
CVE-2026-92548 WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters hcabrera WP Popular Posts Medium 5.3 2026-10-01 04:27:33 Deep Dive
CVE-2026-103536 ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication ZongXR Supermarket High 7.3 2026-10-01 04:15:10 Deep Dive
CVE-2026-103641 Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder Red Hat Red Hat Enterprise Linux 10 Medium 5.5 2026-10-01 03:43:07 Deep Dive
CVE-2026-103534 David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access control David-Crty databasement Medium 6.3 2026-10-01 03:30:12 Deep Dive
CVE-2026-91109 Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'complete_group' Parameter croixhaug Simply Schedule Appointments Medium 6.5 2026-10-01 03:28:23 Deep Dive
CVE-2026-92245 Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce croixhaug Simply Schedule Appointments High 7.5 2026-10-01 03:28:22 Deep Dive
CVE-2026-96561 AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection tigroumeow AI Engine – The Chatbot, AI Framework & MCP for WordPress High 7.2 2026-10-01 03:28:22 Deep Dive
CVE-2026-103533 David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal David-Crty databasement Medium 4.1 2026-10-01 02:45:11 Deep Dive
CVE-2026-101887 BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS arkq bluez-alsa Low 3.5 2026-10-01 02:28:18 Deep Dive
CVE-2026-92537 Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure) satollo Newsletter – Send awesome emails from WordPress Medium 5.3 2026-10-01 02:27:46 Deep Dive
CVE-2026-13313 华硕路由器调试代码漏洞致Telnet开启及Root命令执行 ASUS Router High 8.9 2026-10-01 02:00:57 Deep Dive
CVE-2026-14157 华硕路由器受控格式字符串致远程命令执行漏洞 ASUS Router Critical 9.4 2026-10-01 02:00:34 Deep Dive
CVE-2026-93495 华硕特定主板物理内存读写漏洞 ASUS Motherboard(PRIME Z390-A ) High 7.0 2026-10-01 02:00:12 Deep Dive
CVE-2026-103532 immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization immich-app Immich Medium 5.3 2026-10-01 01:15:17 Deep Dive
CVE-2026-103531 OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow - OpenSC Medium 5.5 2026-10-01 00:45:16 Deep Dive
CVE-2026-51883 Langchain-Chatchat 0.3.x 知识库创建接口路径穿越漏洞 - - - - 2026-10-01 00:00:00 Deep Dive
CVE-2026-51894 RAGFlow 0.24.0 任意文件读取漏洞 - - - - 2026-10-01 00:00:00 Deep Dive
CVE-2026-51874 Devika v1.0路径穿越漏洞 - - - - 2026-10-01 00:00:00 Deep Dive