| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-108555 | PairDrop through 1.11.2 IP Spoofing via cf-connecting-ip Header | schlagmichdoch | PairDrop | Medium | 4.2 | 2026-10-10 14:49:40 | Deep Dive |
| CVE-2026-108554 | PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input | PDFMathTranslate | PDFMathTranslate | Medium | 5.3 | 2026-10-10 14:49:39 | Deep Dive |
| CVE-2026-108553 | OpenRefine through 3.10.1 CSRF to RCE via get-rows Command | OpenRefine | OpenRefine | High | 7.5 | 2026-10-10 14:49:39 | Deep Dive |
| CVE-2026-108551 | openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates | ferdikoomen | openapi-typescript-codegen | Critical | 9.8 | 2026-10-10 14:35:06 | Deep Dive |
| CVE-2026-108550 | SkillHub before 0.2.22 Account Takeover via Account Merge Flow | iflytek | skillhub | High | 8.8 | 2026-10-10 14:35:05 | Deep Dive |
| CVE-2026-108549 | cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing | chenhg5 | cc-connect | High | 8.1 | 2026-10-10 14:35:04 | Deep Dive |
| CVE-2026-108548 | AstronRPA through 1.1.6 Authentication Bypass via Arbitrary Bearer Token | iflytek | astron-rpa | High | 7.3 | 2026-10-10 14:35:04 | Deep Dive |
| CVE-2026-108547 | AstronRPA through 1.1.6 Cross-Tenant Shared Variable Disclosure via get-batch-shared-var | iflytek | astron-rpa | Medium | 6.5 | 2026-10-10 14:35:03 | Deep Dive |
| CVE-2026-108546 | Spotweb through 1.5.8 OS Command Injection via Spot Title in Runcommand Integration | spotweb | spotweb | High | 7.5 | 2026-10-10 14:15:53 | Deep Dive |
| CVE-2026-108545 | SillyTavern 1.12.13 through 1.19.0 Pre-Authentication Denial of Service via Body Parsing | SillyTavern | SillyTavern | Medium | 5.9 | 2026-10-10 14:15:52 | Deep Dive |
| CVE-2026-108115 | Kortix Suna 0.10.7 before 0.13.52 SSRF Guard Bypass via IPv6 6to4 Addresses | kortix-ai | suna | Medium | 4.9 | 2026-10-10 14:15:52 | Deep Dive |
| CVE-2026-108114 | Strapi 5.47.0 through 5.57.0 Improper Authorization via Admin API Token Field Permissions | strapi | strapi | Medium | 4.3 | 2026-10-10 14:15:51 | Deep Dive |
| CVE-2026-94676 | WordPress Tainacan plugin <= 1.3.0 - PHP Object Injection vulnerability | Tainacan Community | Tainacan | High | 7.2 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-66435 | WordPress WP Rollback plugin <= 3.1.2 - Sensitive Data Exposure vulnerability | Devin Walker | WP Rollback | Medium | 5.9 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-97264 | WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability | Greg Winiarski | WPAdverts | High | 7.1 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-97263 | WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability | Greg Winiarski | WPAdverts | High | 7.1 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-105885 | WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability | 10Web | Slider by 10Web | High | 8.8 | 2026-10-10 14:00:11 | Deep Dive |
| CVE-2026-102388 | WordPress Forminator plugin <= 1.57.3 - Cross Site Scripting (XSS) vulnerability | WPMU DEV | Forminator | High | 7.1 | 2026-10-10 14:00:10 | Deep Dive |
| CVE-2026-108165 | Immich through 3.3.1 Missing Authorization in Partner Sync Exposes Locked Folder Metadata | immich-app | immich | Medium | 4.3 | 2026-10-10 13:55:16 | Deep Dive |
| CVE-2026-108164 | Open Source Social Network (OSSN) through 10.1 IDOR via Message Attachment Route | opensource-socialnetwork | opensource-socialnetwork | Medium | 6.5 | 2026-10-10 13:55:15 | Deep Dive |