| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63576 | URI name constraints checked against a mis-parsed host | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.2 | 2026-10-02 07:07:03 | Deep Dive |
| CVE-2026-63575 | PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration count | Legion of the Bouncy Castle Inc. | bc-csharp | High | 7.1 | 2026-10-02 07:06:32 | Deep Dive |
| CVE-2026-63574 | Unbounded allocation from OpenPGP signature and user attribute subpacket lengths | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.7 | 2026-10-02 07:06:01 | Deep Dive |
| CVE-2026-63573 | Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.2 | 2026-10-02 07:05:30 | Deep Dive |
| CVE-2026-63572 | Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files | Legion of the Bouncy Castle Inc. | bc-csharp | High | 7.1 | 2026-10-02 07:04:38 | Deep Dive |
| CVE-2026-63571 | Attribute certificate path validation does not verify the attribute certificate's signature | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.7 | 2026-10-02 07:04:17 | Deep Dive |
| CVE-2026-63570 | Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links | Legion of the Bouncy Castle Inc. | bc-csharp | High | 7.1 | 2026-10-02 07:01:18 | Deep Dive |
| CVE-2026-63569 | MTI/A0 DHAgreement does not validate the peer's ephemeral value | Legion of the Bouncy Castle Inc. | bc-csharp | Critical | 9.1 | 2026-10-02 07:00:24 | Deep Dive |
| CVE-2026-63568 | Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.7 | 2026-10-02 06:59:31 | Deep Dive |
| CVE-2026-63567 | IesEngine block-cipher mode checks padding before MAC (CBC padding oracle) | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.2 | 2026-10-02 06:58:32 | Deep Dive |
| CVE-2026-63566 | DTLS handshake reassembler allocates buffer from unchecked 24-bit length | Legion of the Bouncy Castle Inc. | bc-csharp | High | 8.7 | 2026-10-02 06:57:22 | Deep Dive |
| CVE-2026-92924 | Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data | Unknown | Unlimited Elements for Elementor | Medium | 5.4 | 2026-10-02 06:56:54 | Deep Dive |
| CVE-2026-97219 | MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter | Unknown | MStore API | Medium | 4.3 | 2026-10-02 06:56:54 | Deep Dive |
| CVE-2026-91020 | WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount | Unknown | WebToffee Gift Cards for WooCommerce | Medium | 5.3 | 2026-10-02 06:56:53 | Deep Dive |
| CVE-2026-90987 | Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price | Unknown | Easy PayPal & Stripe Buy Now Button | Medium | 5.3 | 2026-10-02 06:56:52 | Deep Dive |
| CVE-2026-90952 | WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API | Unknown | WP Edit Password Protected | Medium | 5.3 | 2026-10-02 06:56:52 | Deep Dive |
| CVE-2026-85005 | Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization | Unknown | Popup Maker WP | Medium | 5.4 | 2026-10-02 06:56:51 | Deep Dive |
| CVE-2026-79618 | WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form | Unknown | WP User Frontend | Medium | 4.3 | 2026-10-02 06:56:50 | Deep Dive |
| CVE-2026-84740 | The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' Parameter | Unknown | The Events Calendar | Medium | 6.5 | 2026-10-02 06:56:50 | Deep Dive |
| CVE-2026-1661 | WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection | Unknown | WP Mail Logging | Medium | 4.3 | 2026-10-02 06:56:49 | Deep Dive |