| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-62085 | WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability | Melapress | WP Activity Log | High | 7.6 | 2026-09-30 12:26:51 | Deep Dive |
| CVE-2026-62083 | WordPress Creator LMS plugin <= 1.2.19 - Other vulnerability Type vulnerability | WPFunnels | Creator LMS | Medium | 5.4 | 2026-09-30 12:26:50 | Deep Dive |
| CVE-2026-62081 | WordPress Flexible PDF Coupons plugin <= 1.14.11 - Insecure Direct Object References (IDOR) vulnerability | wpdesk | Flexible PDF Coupons | Medium | 5.4 | 2026-09-30 12:26:49 | Deep Dive |
| CVE-2026-62080 | WordPress Happy Addons for Elementor plugin <= 3.23.1 - Cross Site Scripting (XSS) vulnerability | Leevio | Happy Addons for Elementor | Medium | 6.5 | 2026-09-30 12:26:48 | Deep Dive |
| CVE-2026-62079 | WordPress Qi Addons For Elementor plugin <= 1.11 - Cross Site Scripting (XSS) vulnerability | Qode | Qi Addons For Elementor | Medium | 6.5 | 2026-09-30 12:26:48 | Deep Dive |
| CVE-2026-62078 | WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability | Leap13 | Premium Addons for Elementor | Medium | 6.5 | 2026-09-30 12:26:47 | Deep Dive |
| CVE-2026-27371 | WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) vulnerability | WPFunnels | WPFunnels | High | 7.1 | 2026-09-30 12:26:46 | Deep Dive |
| CVE-2026-27085 | WordPress Astra WordPress theme theme <= 4.13.12 - Content Injection vulnerability | Brainstorm Force | Astra WordPress Theme | Low | 2.7 | 2026-09-30 12:26:45 | Deep Dive |
| CVE-2026-95616 | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 12:25:28 | Deep Dive |
| CVE-2026-103321 | MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image | MISP | MISP | High | 8.3 | 2026-09-30 12:19:02 | Deep Dive |
| CVE-2026-103115 | OS4ED openSIS-Classic Student Search CustomFieldsFnc.php sql injection | OS4ED | openSIS-Classic | Medium | 6.3 | 2026-09-30 12:15:12 | Deep Dive |
| CVE-2026-74865 | Authentication Bypass in sogo_yhn | YunoHost-Apps | sogo_yhn | Critical | 9.2 | 2026-09-30 12:02:41 | Deep Dive |
| CVE-2026-92899 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 12:02:41 | Deep Dive |
| CVE-2026-74864 | Authentication Bypass in sogo_yhn | YunoHost-Apps | sogo_yhn | Critical | 9.3 | 2026-09-30 12:02:29 | Deep Dive |
| CVE-2026-92121 | Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 12:01:56 | Deep Dive |
| CVE-2026-89238 | Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 11:59:10 | Deep Dive |
| CVE-2026-88920 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 11:58:00 | Deep Dive |
| CVE-2026-87830 | Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 11:57:01 | Deep Dive |
| CVE-2026-85532 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters | Apache Software Foundation | Apache WSS4J | - | - | 2026-09-30 11:55:53 | Deep Dive |
| CVE-2026-103242 | Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag | Red Hat | Red Hat Enterprise Linux 10 | High | 7.1 | 2026-09-30 11:50:32 | Deep Dive |