| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103552 | Apache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoder | Apache Software Foundation | Apache Directory LDAP API | - | - | 2026-10-02 09:48:05 | Deep Dive |
| CVE-2026-59661 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:47:28 | Deep Dive |
| CVE-2026-59660 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:43:53 | Deep Dive |
| CVE-2026-59659 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:41:43 | Deep Dive |
| CVE-2026-94180 | WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability | Monetizemore | Advanced Ads | Medium | 4.3 | 2026-10-02 09:39:21 | Deep Dive |
| CVE-2026-94639 | Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget) | Apache Software Foundation | Apache Thrift | High | 8.2 | 2026-10-02 09:33:52 | Deep Dive |
| CVE-2026-94405 | WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability | Shahjada | Download Manager | Medium | 5.3 | 2026-10-02 09:31:19 | Deep Dive |
| CVE-2026-97652 | WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key | veronalabs | WP Statistics – Simple, privacy-friendly Google Analytics alternative | Medium | 6.1 | 2026-10-02 09:25:58 | Deep Dive |
| CVE-2026-85492 | All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname | smub | All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) | Medium | 6.1 | 2026-10-02 09:25:57 | Deep Dive |
| CVE-2026-94541 | WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter | amauric | WPMobile.App – Android and iOS App Builder | Critical | 9.8 | 2026-10-02 09:25:56 | Deep Dive |
| CVE-2026-87920 | W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content | boldgrid | W3 Total Cache | High | 7.2 | 2026-10-02 09:25:56 | Deep Dive |
| CVE-2026-102731 | Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode | Apache Software Foundation | Apache Directory LDAP API | - | - | 2026-10-02 09:22:01 | Deep Dive |
| CVE-2026-59673 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:12:53 | Deep Dive |
| CVE-2026-59672 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:09:29 | Deep Dive |
| CVE-2026-94635 | Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name | Apache Software Foundation | Apache Thrift | High | 8.7 | 2026-10-02 09:07:57 | Deep Dive |
| CVE-2026-80298 | SQL Injection in HAVELSAN's Sef - AI Chatbot Platform | HAVELSAN Inc. | Sef - AI Chatbot Platform | High | 8.8 | 2026-10-02 09:07:53 | Deep Dive |
| CVE-2026-59671 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:06:30 | Deep Dive |
| CVE-2026-95512 | Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader | Red Hat | Red Hat build of OpenJDK 11 ELS | Medium | 5.5 | 2026-10-02 09:05:11 | Deep Dive |
| CVE-2026-80443 | Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform | HAVELSAN Inc. | Sef - AI Chatbot Platform | High | 7.4 | 2026-10-02 09:04:41 | Deep Dive |
| CVE-2026-59670 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:01:59 | Deep Dive |