CVE-2026-67104
— HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the disco…
Remote
|
Information Disclosure
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-62073
— WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-62071
— WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Remote
|
Injection
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-56599
— HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly,…
|
Cross-Site Request Forgery
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-56589
— HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute…
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103752
— WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103687
— rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation l…
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103347
— WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Remote
|
Authentication
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103068
— WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalati…
Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-103004
— next.js cache leak on warm `use cache` handlers accessing root param
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComp…
next.js
|
Remote
|
Misconfiguration
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-102378
— WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerabili…
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
Remote
|
Cross-Site Scripting
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-100517
— WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Object Referen…
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-100514
— WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (IDOR) vulnera…
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
Remote
|
Authorization
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2024-58388
— Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.html
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path pa…
Remote
|
Path Traversal
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-79896
— Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and te…
Remote
|
Denial of Service
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-17053
— SMBus callback-removal syscalls accept an unvalidated user pointer, letting user threads …
The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_…
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-79901
— Predictable Active Directory service-account passwords in BoKS Manager
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current U…
Remote
|
Cryptography
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-66253
— HCL iControl is affected by a Session Timeout vulnerability
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ab…
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-66249
— HCL iControl is affected by a Missing Secure Attribute vulnerability
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extractio…
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
CVE-2026-66248
— HCL iControl is affected by an Improper Error Handling vulnerability
iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive int…
icontrol
|
Remote
|
Information Disclosure
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Oct 01, 2026