| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102454 | DigiWin|EasyFlow .NET - Arbitrary File Upload | DigiWin | EasyFlow .NET | High | 7.2 | 2026-09-30 08:26:07 | Deep Dive |
| CVE-2026-102511 | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them | Apache Software Foundation | Apache PLC4X | High | 8.5 | 2026-09-30 08:03:04 | Deep Dive |
| CVE-2026-102510 | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths | Apache Software Foundation | Apache PLC4X | High | 8.7 | 2026-09-30 08:01:43 | Deep Dive |
| CVE-2026-102509 | Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser | Apache Software Foundation | Apache PLC4X | High | 8.7 | 2026-09-30 08:00:28 | Deep Dive |
| CVE-2026-92873 | Pgpool-II认证算法缺陷致未授权提升看门狗节点 | Pgpool Global Development Group | Pgpool-II | Medium | 6.9 | 2026-09-30 07:51:52 | Deep Dive |
| CVE-2026-92872 | Pgpool-II敏感信息泄露至日志文件漏洞 | Pgpool Global Development Group | Pgpool-II | Medium | 5.3 | 2026-09-30 07:47:50 | Deep Dive |
| CVE-2026-92871 | Pgpool-II空指针解引用致看门狗进程异常终止 | Pgpool Global Development Group | Pgpool-II | High | 8.7 | 2026-09-30 07:47:32 | Deep Dive |
| CVE-2026-102508 | Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade | Apache Software Foundation | Apache PLC4X | Critical | 9.2 | 2026-09-30 07:42:44 | Deep Dive |
| CVE-2026-93462 | baserCMS关键功能缺失认证致敏感信息泄露漏洞 | baserCMS User Community | baserCMS | Medium | 6.9 | 2026-09-30 07:42:32 | Deep Dive |
| CVE-2026-6170 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:07 | Deep Dive |
| CVE-2026-6173 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:07 | Deep Dive |
| CVE-2026-16596 | WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter | wpdirectorykit | WP Directory Kit | Medium | 6.5 | 2026-09-30 07:41:07 | Deep Dive |
| CVE-2026-6171 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:06 | Deep Dive |
| CVE-2026-6806 | Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters | stylemix | Motors – Car Dealership & Classified Listings Plugin | High | 7.5 | 2026-09-30 07:41:06 | Deep Dive |
| CVE-2026-14876 | Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block | nextendweb | Smart Slider 3 | Medium | 6.4 | 2026-09-30 07:41:06 | Deep Dive |
| CVE-2026-11895 | HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting | devitemsllc | HT Mega Addons for Elementor – Elementor Widgets & Template Builder | Medium | 6.4 | 2026-09-30 07:41:05 | Deep Dive |
| CVE-2026-88037 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:05 | Deep Dive |
| CVE-2026-6172 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'caption' Parameter | boldthemes | Bold Page Builder | Medium | 6.4 | 2026-09-30 07:41:04 | Deep Dive |
| CVE-2026-93464 | baserCMS存储型XSS漏洞:自定义内容描述 | baserCMS User Community | baserCMS | Medium | 5.1 | 2026-09-30 07:34:33 | Deep Dive |
| CVE-2026-93460 | baserCMS邮件表单存储型XSS漏洞 | baserCMS User Community | baserCMS | Medium | 5.1 | 2026-09-30 07:34:10 | Deep Dive |