| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103357 | WordPress GIFT4U plugin <= 1.1.3 - Broken Access Control vulnerability | VillaTheme | GIFT4U | Medium | 6.9 | 2026-10-10 17:00:11 | Deep Dive |
| CVE-2026-103071 | WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.3 - Content Injection vulnerability | VillaTheme | Thank You Page Customizer for WooCommerce | High | 7.5 | 2026-10-10 17:00:11 | Deep Dive |
| CVE-2026-105889 | WordPress Tickera plugin <= 3.6.0.6 - SQL Injection vulnerability | Tickera | Tickera | Critical | 9.3 | 2026-10-10 17:00:11 | Deep Dive |
| CVE-2026-104398 | WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.10 - PHP Object Injection vulnerability | VillaTheme | AFFI – Affiliate Marketing for WooCommerce | Critical | 9.8 | 2026-10-10 17:00:11 | Deep Dive |
| CVE-2026-94160 | WordPress ThemeStek Extras for LabtechCO Theme plugin <= 8.4 - Reflected Cross Site Scripting (XSS) vulnerability | themeStek | ThemeStek Extras for LabtechCO Theme | High | 7.1 | 2026-10-10 17:00:10 | Deep Dive |
| CVE-2026-106609 | WordPress Bayarcash WooCommerce plugin <= 4.4.2 - Broken Access Control vulnerability | Web Impian | Bayarcash WooCommerce | High | 7.5 | 2026-10-10 17:00:10 | Deep Dive |
| CVE-2026-106608 | WordPress WooCommerce plugin 9.8.0-11.1.2 - Shop Manager+ Privilege Escalation vulnerability | Automattic | WooCommerce | High | 7.2 | 2026-10-10 17:00:10 | Deep Dive |
| CVE-2026-62044 | WordPress Super Video Player plugin <= 1.8.13 - PHP Object Injection vulnerability | bPlugins | Super Video Player | High | 7.2 | 2026-10-10 17:00:10 | Deep Dive |
| CVE-2026-108585 | argocd-mcp through 0.9.0 Path Traversal via delete_application Tool | argoproj-labs | argocd-mcp | Medium | 5.4 | 2026-10-10 16:14:10 | Deep Dive |
| CVE-2026-108586 | 1MCP Agent 0.20.0 through 0.39.0 OAuth Tag-Scope Bypass via Negated Tag Filter | 1mcp-app | @1mcp/agent | Medium | 5.4 | 2026-10-10 16:14:10 | Deep Dive |
| CVE-2026-108583 | zotero-mcp 0.10.0 through 0.14.1 SSRF via zotero_add_by_url Tool | 54yyyu | zotero-mcp | Medium | 4.2 | 2026-10-10 15:57:51 | Deep Dive |
| CVE-2026-108582 | GenOffice through 0.11.505 Insecure Permissions in HTTP MCP Server File Store | genspark-ai | GenOffice | Medium | 5.5 | 2026-10-10 15:57:51 | Deep Dive |
| CVE-2026-108581 | Octop through 1.0.2b6 Missing Authorization Exposes Provider API Keys via /api/providers | TencentCloud | Octop | Medium | 6.5 | 2026-10-10 15:57:50 | Deep Dive |
| CVE-2026-108580 | AniWorld Downloader before 5.3.0 WebUI Login Brute Force via /login | phoenixthrush | AniWorld Downloader | Medium | 6.5 | 2026-10-10 15:57:49 | Deep Dive |
| CVE-2026-108579 | OpenPanel through 2.3.0 CSV Formula Injection via Cohort Member Export | Openpanel-dev | openpanel | Medium | 4.2 | 2026-10-10 15:57:49 | Deep Dive |
| CVE-2026-108555 | PairDrop through 1.11.2 IP Spoofing via cf-connecting-ip Header | schlagmichdoch | PairDrop | Medium | 4.2 | 2026-10-10 14:49:40 | Deep Dive |
| CVE-2026-108554 | PDFMathTranslate through 1.9.11 SSRF via Gradio Web GUI Link Input | PDFMathTranslate | PDFMathTranslate | Medium | 5.3 | 2026-10-10 14:49:39 | Deep Dive |
| CVE-2026-108553 | OpenRefine through 3.10.1 CSRF to RCE via get-rows Command | OpenRefine | OpenRefine | High | 7.5 | 2026-10-10 14:49:39 | Deep Dive |
| CVE-2026-108551 | openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates | ferdikoomen | openapi-typescript-codegen | Critical | 9.8 | 2026-10-10 14:35:06 | Deep Dive |
| CVE-2026-108550 | SkillHub before 0.2.22 Account Takeover via Account Merge Flow | iflytek | skillhub | High | 8.8 | 2026-10-10 14:35:05 | Deep Dive |