CVE-2026-105775
— vllm-project vLLM Completions Request mamba_mixer2.py conv_ssm_forward out-of-bounds
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component …
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-75962
— Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_emai…
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email…
Remote
|
Cross-Site Scripting
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to informati…
uptrace
|
Remote
|
Information Disclosure
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105706
— SourceCodester Drug Recommendation System cross-site request forgery
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be pe…
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105705
— SourceCodester Drug Recommendation System add_drug.php cross site scripting
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site …
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105704
— SourceCodester Drug Recommendation System Auth Guard improper authentication
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to impro…
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation…
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-97300
— WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-41563
— WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
Remote
|
Information Disclosure
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-41558
— WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA Bypass vulne…
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-39789
— WordPress Fluent Affiliate Pro plugin <= 1.6.4 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-39760
— WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
Remote
|
Cross-Site Scripting
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-39723
— WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-39599
— WordPress WDS MCP Content Manager plugin <= 3.10.4 - Broken Access Control vulnerability
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-32582
— WordPress IATO MCP plugin <= 1.11.0 - Broken Access Control vulnerability
Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-32576
— WordPress Faktur Pro for WooCommerce plugin <= 3.2.1 - Insecure Direct Object References …
Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105072
— WordPress FluentBooking Pro plugin < 2.5.0 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105703
— PHPGurukul User Registration & Login and User Management System Change Password change-pa…
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of…
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105621
— jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDe…
A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.ja…
jsherp
|
Remote
|
Authorization
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
CVE-2026-105611
— chillzhuang SpringBlade User Detail Endpoint RoleController.java improper authorization
A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleCont…
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Oct 06, 2026