| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102458 | DigiWin|EasyFlow .NET - Missing Authentication | DigiWin | EasyFlow .NET | Critical | 9.8 | 2026-09-30 08:34:10 | Deep Dive |
| CVE-2026-102457 | DigiWin|EasyFlow .NET - Arbitrary File Read | DigiWin | EasyFlow .NET | Medium | 6.5 | 2026-09-30 08:32:38 | Deep Dive |
| CVE-2026-102456 | DigiWin|EasyFlow .NET - SQL Injection | DigiWin | EasyFlow .NET | Medium | 6.5 | 2026-09-30 08:30:48 | Deep Dive |
| CVE-2026-102455 | DigiWin|EasyFlow .NET - Insecure Deserialization | DigiWin | EasyFlow .NET | Critical | 9.8 | 2026-09-30 08:29:30 | Deep Dive |
| CVE-2026-75098 | Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design | productdesignerapp | Product Designer App | High | 7.5 | 2026-09-30 08:28:05 | Deep Dive |
| CVE-2026-92712 | ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter | rockiger | ReactPress – Create React App for WordPress | Medium | 6.4 | 2026-09-30 08:28:05 | Deep Dive |
| CVE-2026-93908 | Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'before_price_text' Parameter | rameez_iqbal | Real Estate Manager – Property Listing and Agent Management | Medium | 6.4 | 2026-09-30 08:28:04 | Deep Dive |
| CVE-2025-14564 | Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | ahsangadit | Viable URL Media Uploader | Medium | 6.4 | 2026-09-30 08:28:04 | Deep Dive |
| CVE-2026-97347 | Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header | kazukiyanamoto | Post Views Stats Counter | High | 7.2 | 2026-09-30 08:28:03 | Deep Dive |
| CVE-2026-102454 | DigiWin|EasyFlow .NET - Arbitrary File Upload | DigiWin | EasyFlow .NET | High | 7.2 | 2026-09-30 08:26:07 | Deep Dive |
| CVE-2026-102511 | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them | Apache Software Foundation | Apache PLC4X | High | 8.5 | 2026-09-30 08:03:04 | Deep Dive |
| CVE-2026-102510 | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths | Apache Software Foundation | Apache PLC4X | High | 8.7 | 2026-09-30 08:01:43 | Deep Dive |
| CVE-2026-102509 | Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser | Apache Software Foundation | Apache PLC4X | High | 8.7 | 2026-09-30 08:00:28 | Deep Dive |
| CVE-2026-92873 | Pgpool-II认证算法缺陷致未授权提升看门狗节点 | Pgpool Global Development Group | Pgpool-II | Medium | 6.9 | 2026-09-30 07:51:52 | Deep Dive |
| CVE-2026-92872 | Pgpool-II敏感信息泄露至日志文件漏洞 | Pgpool Global Development Group | Pgpool-II | Medium | 5.3 | 2026-09-30 07:47:50 | Deep Dive |
| CVE-2026-92871 | Pgpool-II空指针解引用致看门狗进程异常终止 | Pgpool Global Development Group | Pgpool-II | High | 8.7 | 2026-09-30 07:47:32 | Deep Dive |
| CVE-2026-102508 | Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade | Apache Software Foundation | Apache PLC4X | Critical | 9.2 | 2026-09-30 07:42:44 | Deep Dive |
| CVE-2026-93462 | baserCMS关键功能缺失认证致敏感信息泄露漏洞 | baserCMS User Community | baserCMS | Medium | 6.9 | 2026-09-30 07:42:32 | Deep Dive |
| CVE-2026-6170 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:07 | Deep Dive |
| CVE-2026-6173 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:07 | Deep Dive |