| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-66435 | WordPress WP Rollback plugin <= 3.1.2 - Sensitive Data Exposure vulnerability | Devin Walker | WP Rollback | Medium | 5.9 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-97264 | WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability | Greg Winiarski | WPAdverts | High | 7.1 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-97263 | WordPress WPAdverts plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability | Greg Winiarski | WPAdverts | High | 7.1 | 2026-10-10 14:00:13 | Deep Dive |
| CVE-2026-105885 | WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability | 10Web | Slider by 10Web | High | 8.8 | 2026-10-10 14:00:11 | Deep Dive |
| CVE-2026-102388 | WordPress Forminator plugin <= 1.57.3 - Cross Site Scripting (XSS) vulnerability | WPMU DEV | Forminator | High | 7.1 | 2026-10-10 14:00:10 | Deep Dive |
| CVE-2026-108165 | Immich through 3.3.1 Missing Authorization in Partner Sync Exposes Locked Folder Metadata | immich-app | immich | Medium | 4.3 | 2026-10-10 13:55:16 | Deep Dive |
| CVE-2026-108164 | Open Source Social Network (OSSN) through 10.1 IDOR via Message Attachment Route | opensource-socialnetwork | opensource-socialnetwork | Medium | 6.5 | 2026-10-10 13:55:15 | Deep Dive |
| CVE-2026-108163 | Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL | smp46 | pingvin-share-x | Medium | 6.5 | 2026-10-10 13:55:14 | Deep Dive |
| CVE-2026-108161 | FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download | fusionpbx | fusionpbx | High | 7.5 | 2026-10-10 13:55:13 | Deep Dive |
| CVE-2026-108162 | Pingvin Share X before 1.22.0 Rate Limit Bypass via Spoofed X-Forwarded-For | smp46 | pingvin-share-x | Medium | 6.5 | 2026-10-10 13:55:13 | Deep Dive |
| CVE-2026-107794 | ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list | - | - | - | - | 2026-10-10 12:45:20 | Deep Dive |
| CVE-2013-10076 | ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list | - | - | - | - | 2026-10-10 12:44:48 | Deep Dive |
| CVE-2026-107373 | ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument | - | - | - | - | 2026-10-10 12:44:08 | Deep Dive |
| CVE-2026-103636 | Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization allows denial of service via a truncated sketch | Apache Software Foundation | Apache DataSketches | - | - | 2026-10-10 10:23:59 | Deep Dive |
| CVE-2026-103635 | Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deserialization allows denial of service via a crafted sketch | Apache Software Foundation | Apache DataSketches | - | - | 2026-10-10 10:23:49 | Deep Dive |
| CVE-2026-103513 | Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch deserialization allows memory corruption via a crafted sketch | Apache Software Foundation | Apache DataSketches | - | - | 2026-10-10 10:23:21 | Deep Dive |
| CVE-2026-103501 | Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow allows memory corruption via a crafted sketch | Apache Software Foundation | Apache DataSketches | - | - | 2026-10-10 10:22:56 | Deep Dive |
| CVE-2026-106139 | Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue | Progress Software | Kendo UI for Vue | Medium | 5.4 | 2026-10-10 09:23:49 | Deep Dive |
| CVE-2026-106138 | Cross-Site Scripting via Chart Tooltip in KendoReact | Progress Software | KendoReact | Medium | 5.4 | 2026-10-10 09:23:06 | Deep Dive |
| CVE-2026-108506 | Unauthorized access vulnerability in ZTE Z80 Ultra product | ZTE | Z80 Ultra | Medium | 5.5 | 2026-10-10 09:08:04 | Deep Dive |