| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-94405 | WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability | Shahjada | Download Manager | Medium | 5.3 | 2026-10-02 09:31:19 | Deep Dive |
| CVE-2026-97652 | WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key | veronalabs | WP Statistics – Simple, privacy-friendly Google Analytics alternative | Medium | 6.1 | 2026-10-02 09:25:58 | Deep Dive |
| CVE-2026-85492 | All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname | smub | All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) | Medium | 6.1 | 2026-10-02 09:25:57 | Deep Dive |
| CVE-2026-94541 | WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter | amauric | WPMobile.App – Android and iOS App Builder | Critical | 9.8 | 2026-10-02 09:25:56 | Deep Dive |
| CVE-2026-87920 | W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content | boldgrid | W3 Total Cache | High | 7.2 | 2026-10-02 09:25:56 | Deep Dive |
| CVE-2026-102731 | Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode | Apache Software Foundation | Apache Directory LDAP API | - | - | 2026-10-02 09:22:01 | Deep Dive |
| CVE-2026-59673 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:12:53 | Deep Dive |
| CVE-2026-59672 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:09:29 | Deep Dive |
| CVE-2026-94635 | Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name | Apache Software Foundation | Apache Thrift | High | 8.7 | 2026-10-02 09:07:57 | Deep Dive |
| CVE-2026-80298 | SQL Injection in HAVELSAN's Sef - AI Chatbot Platform | HAVELSAN Inc. | Sef - AI Chatbot Platform | High | 8.8 | 2026-10-02 09:07:53 | Deep Dive |
| CVE-2026-59671 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:06:30 | Deep Dive |
| CVE-2026-95512 | Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader | Red Hat | Red Hat build of OpenJDK 11 ELS | Medium | 5.5 | 2026-10-02 09:05:11 | Deep Dive |
| CVE-2026-80443 | Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform | HAVELSAN Inc. | Sef - AI Chatbot Platform | High | 7.4 | 2026-10-02 09:04:41 | Deep Dive |
| CVE-2026-59670 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 09:01:59 | Deep Dive |
| CVE-2026-80337 | Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform | HAVELSAN Inc. | Sef - AI Chatbot Platform | Medium | 5.3 | 2026-10-02 09:01:25 | Deep Dive |
| CVE-2026-80464 | API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform | HAVELSAN Inc. | Sef - AI Chatbot Platform | Medium | 4.9 | 2026-10-02 08:58:08 | Deep Dive |
| CVE-2026-59669 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 08:40:53 | Deep Dive |
| CVE-2026-91784 | Argument Injection leading to arbitrary process termination in gotop | cjbassi | gotop | Medium | 4.8 | 2026-10-02 08:38:43 | Deep Dive |
| CVE-2026-18036 | NTRU leaks private key information by reducing secret values with a non-constant-time integer division | Legion of the Bouncy Castle Inc. | BC-JAVA | High | 8.2 | 2026-10-02 07:54:16 | Deep Dive |
| CVE-2026-94432 | Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | Medium | 5.3 | 2026-10-02 07:39:29 | Deep Dive |