Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 8

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-94405 WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerability Shahjada Download Manager Medium 5.3 2026-10-02 09:31:19 Deep Dive
CVE-2026-97652 WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key veronalabs WP Statistics – Simple, privacy-friendly Google Analytics alternative Medium 6.1 2026-10-02 09:25:58 Deep Dive
CVE-2026-85492 All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname smub All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) Medium 6.1 2026-10-02 09:25:57 Deep Dive
CVE-2026-94541 WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter amauric WPMobile.App – Android and iOS App Builder Critical 9.8 2026-10-02 09:25:56 Deep Dive
CVE-2026-87920 W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content boldgrid W3 Total Cache High 7.2 2026-10-02 09:25:56 Deep Dive
CVE-2026-102731 Apache Directory LDAP API: Denial of service via excessive memory allocation in BER decode Apache Software Foundation Apache Directory LDAP API - - 2026-10-02 09:22:01 Deep Dive
CVE-2026-59673 Multiple vulnerabilities in the Repasat application Repasat Repasat application Medium 4.8 2026-10-02 09:12:53 Deep Dive
CVE-2026-59672 Multiple vulnerabilities in the Repasat application Repasat Repasat application Medium 4.8 2026-10-02 09:09:29 Deep Dive
CVE-2026-94635 Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name Apache Software Foundation Apache Thrift High 8.7 2026-10-02 09:07:57 Deep Dive
CVE-2026-80298 SQL Injection in HAVELSAN's Sef - AI Chatbot Platform HAVELSAN Inc. Sef - AI Chatbot Platform High 8.8 2026-10-02 09:07:53 Deep Dive
CVE-2026-59671 Multiple vulnerabilities in the Repasat application Repasat Repasat application Medium 4.8 2026-10-02 09:06:30 Deep Dive
CVE-2026-95512 Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader Red Hat Red Hat build of OpenJDK 11 ELS Medium 5.5 2026-10-02 09:05:11 Deep Dive
CVE-2026-80443 Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform HAVELSAN Inc. Sef - AI Chatbot Platform High 7.4 2026-10-02 09:04:41 Deep Dive
CVE-2026-59670 Multiple vulnerabilities in the Repasat application Repasat Repasat application Medium 4.8 2026-10-02 09:01:59 Deep Dive
CVE-2026-80337 Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform HAVELSAN Inc. Sef - AI Chatbot Platform Medium 5.3 2026-10-02 09:01:25 Deep Dive
CVE-2026-80464 API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform HAVELSAN Inc. Sef - AI Chatbot Platform Medium 4.9 2026-10-02 08:58:08 Deep Dive
CVE-2026-59669 Multiple vulnerabilities in the Repasat application Repasat Repasat application Medium 4.8 2026-10-02 08:40:53 Deep Dive
CVE-2026-91784 Argument Injection leading to arbitrary process termination in gotop cjbassi gotop Medium 4.8 2026-10-02 08:38:43 Deep Dive
CVE-2026-18036 NTRU leaks private key information by reducing secret values with a non-constant-time integer division Legion of the Bouncy Castle Inc. BC-JAVA High 8.2 2026-10-02 07:54:16 Deep Dive
CVE-2026-94432 Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Medium 5.3 2026-10-02 07:39:29 Deep Dive