🔍 جارٍ البحث...
يتم الاستعلام من 70+ مصدر أمني في نفس الوقت
CISA KEV • NVD • MITRE • Exploit-DB • BleepingComputer • ...
📅 اليوم 📊 تقارير
Threat Intelligence
🕐 2026-10-03 10:53 👥 62 اليوم  |  13,151 إجمالي
97
📅 2026-10-03
6
🔴 Critical
24
🟠 High
45
🟡 Medium
22
🟢 Low
1
🔥 Exploited
0
⚡ KEV
97 results
🔍 Search
اختر يوم محدد
/ /
رقم الثغرة
اسم الشركة أو المنتج
الشركة أو المنتج
من تاريخ
/ /
إلى تاريخ
/ /
المجالالحدث / CVEالمصدرالوصف الاستغلالالخطورةالأنظمة المتأثرة نوع التهديدالحلول📅 تاريخ النشر
Open Source CVE-2026-90970 CVSS 9.9
Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks 📄 التفاصيل ←
Cyber Security News GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow… No 🔴 Critical GitLab AI Attack Update to v19.2.4
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-97363
CVE-2026-97363 - Monta monta.app Improper Restriction of Excessive Authenticatio… 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-97363 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… No 🔴 Critical Vulnerability Refer to CVE-2026-97363 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-82042
CVE-2026-82042 - UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyF… 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-82042 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Descrip… No 🔴 Critical Vulnerability Refer to CVE-2026-82042 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
NVIDIA CVE-2026-105080 CVSS 9.9
CVE-2026-105080 — In ConvertX before 0.19.0, converters/calibre.ts does not bloc… 📄 التفاصيل ←
NVD In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes the… No 🔴 Critical Vulnerability Refer to CVE-2026-105080 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-73802 CVSS 9.9
CVE-2026-73802 — gitea-runner: workflow container.options passes host namespaces… 📄 التفاصيل ←
GHSA ### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker… No 🔴 Critical Ubuntu Linux | Docker Vulnerability Refer to CVE-2026-73802 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-10032 CVSS 9.3
CVE-2026-10032 — @a2ui/web_core: `openUrl` permits `javascript:` URI execution v… 📄 التفاصيل ←
GHSA ### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `… No 🔴 Critical Vulnerability Update to v0.10.2
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit CVE-2026-3483
Security Advisory Ivanti DSM (CVE-2026-3483) 📄 التفاصيل ←
Vulners Security Advisory Ivanti DSM CVE-2026-3483 Summary Ivanti has released an update for Ivanti Desktop … No 🟠 High Exploit Refer to CVE-2026-3483 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91879 📄 التفاصيل ← Vulners The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPre… No 🟠 High WordPress AI Attack Update to v3.5.3
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91875 📄 التفاصيل ← Vulners The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t… No 🟠 High WordPress Vulnerability Update to v2.11.0
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web EUVD-2026-91874 📄 التفاصيل ← Vulners Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts f… No 🟠 High Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91893 📄 التفاصيل ← Vulners The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr… No 🟠 High WordPress Vulnerability Update to v4.9
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91891 📄 التفاصيل ← Vulners The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Re… No 🟠 High WordPress Vulnerability Update to v4.17.4
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91890 📄 التفاصيل ← Vulners The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Re… No 🟠 High WordPress Vulnerability Update to v4.17.4
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Network Citrix NetScaler Keeps Rebooting Following the 0-Day Patch 📄 التفاصيل ← Cyber Security News Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.3… Yes 🟠 High Citrix Zero-Day Update to v14.1
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Linux Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Es… 📄 التفاصيل ← Cyber Security News Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaw… No 🟠 High Linux Kernel | Debian Linux Vulnerability Update to v6.12.111
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Network CVE-2026-84411
CVE-2026-84411 - MikroTik RouterOS Integer Underflow 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-84411 Published : 2 octobre 2026 23:16 | 4 heures, 37 minutes ago Descrip… No 🟠 High Vulnerability Refer to CVE-2026-84411 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Linux CVE-2026-75937
CVE-2026-75937 - OS Command Injection in Digi Accelerated Linux (DAL OS) 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-75937 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Descrip… No 🟠 High Vulnerability Refer to CVE-2026-75937 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Cloud CVE-2026-18140 CVSS 7.5
CVE-2026-18140 — aws-smithy-json: Uncontrolled recursion in the aws-smithy-json … 📄 التفاصيل ←
GHSA ### Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients an… No 🟠 High Vulnerability Update to v0.62.6
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-96780
CVE-2026-96780 — figlet is vulnerable to denial of service via unbounded loop wh… 📄 التفاصيل ←
GHSA ### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: -… No 🟠 High Node.js Vulnerability Update to v1.11.3
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-104433 CVSS 7.5
CVE-2026-104433 — Mooncake transfer engine before 0.3.12 contains an out-of-boun… 📄 التفاصيل ←
NVD Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readStrin… No 🟠 High Vulnerability Refer to CVE-2026-104433 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-104478 CVSS 7.1
CVE-2026-104478 — Formwork before 2.3.13 contains a path traversal vulnerability… 📄 التفاصيل ←
NVD Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authe… No 🟠 High PHP Vulnerability Refer to CVE-2026-104478 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-105090
CVE-2026-105090 — Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. … 📄 التفاصيل ←
NVD Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts f… No 🟠 High Vulnerability Refer to CVE-2026-105090 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-93428 CVSS 7.5
CVE-2026-93428 — The Ultimate Member – User Profile, Registration, Login, Member… 📄 التفاصيل ←
NVD The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… No 🟠 High WordPress Vulnerability Update to v2.13.1
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-96270 CVSS 7.2
CVE-2026-96270 — The Ultimate Member – User Profile, Registration, Login, Member… 📄 التفاصيل ←
NVD The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… No 🟠 High WordPress Vulnerability Update to v2.13.1
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92536 CVSS 8.8
CVE-2026-92536 — The Paid Membership Plugin, Ecommerce, User Registration Form, … 📄 التفاصيل ←
NVD The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… No 🟠 High WordPress Exploit Update to v4.17.4
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92977 CVSS 7.2
CVE-2026-92977 — The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plug… 📄 التفاصيل ←
NVD The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Sto… No 🟠 High WordPress Exploit Update to v5.3.5
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-97644 CVSS 8.8
CVE-2026-97644 — The Groundhogg — CRM, Newsletters, and Marketing Automation plu… 📄 التفاصيل ←
NVD The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr… No 🟠 High WordPress Vulnerability Update to v4.9
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-105050
CVE-2026-105050 | PeaZip up to 11.2.x os command injection 📄 التفاصيل ←
VulDB A vulnerability was found in PeaZip up to 11.2.x. It has been classified as problematic. The affecte… No 🟠 High Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-104861 CVSS 7.5
CVE-2026-104861 — probe-image-size: Quadratic-time Denial of Service in the SVG … 📄 التفاصيل ←
GHSA ## Overview `probe-image-size` scans the SVG header with a searching regular expression, `/]*>/`… No 🟠 High Vulnerability Refer to CVE-2026-104861 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Linux CVE-2026-71416 CVSS 8.8
CVE-2026-71416 — Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) 📄 التفاصيل ←
GHSA ### Summary The Headroom WebSocket server does not validate the `Origin` header of incoming client W… PoC Only 🟠 High AI Attack Refer to CVE-2026-71416 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit ctf2ktoo6 exploit 📄 التفاصيل ← Sploitus Proof-of-concept exploit. PoC Only 🟡 Medium PoC Research Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit ps5-pihost exploit 📄 التفاصيل ← Sploitus Proof-of-concept exploit. PoC Only 🟡 Medium PoC Research Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91876 📄 التفاصيل ← Vulners The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… No 🟡 Medium WordPress Vulnerability Update to v2.13.1
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91878 📄 التفاصيل ← Vulners The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPre… No 🟡 Medium WordPress AI Attack Update to v3.5.3
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91880 📄 التفاصيل ← Vulners The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit… No 🟡 Medium WordPress Vulnerability Update to v5.5.18
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91877 📄 التفاصيل ← Vulners The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress… No 🟡 Medium WordPress Vulnerability Update to v3.2.19
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Open Source EUVD-2026-91870 📄 التفاصيل ← Vulners ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache … No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91895 📄 التفاصيل ← Vulners The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul… No 🟡 Medium WordPress Vulnerability Update to v4.4.7
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91896 📄 التفاصيل ← Vulners The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Emb… No 🟡 Medium WordPress Vulnerability Update to v4.6.6
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91894 📄 التفاصيل ← Vulners The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via RE… No 🟡 Medium WordPress Vulnerability Update to v8.7.7
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91892 📄 التفاصيل ← Vulners The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to… No 🟡 Medium WordPress Vulnerability Update to v5.3.5
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit relapse exploit 📄 التفاصيل ← Sploitus Proof-of-concept exploit. PoC Only 🟡 Medium PoC Research Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit cheesy-p4u-decomp exploit 📄 التفاصيل ← Sploitus Proof-of-concept exploit. PoC Only 🟡 Medium PoC Research Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web Recruit-SSRF-LFI-SQL-Injection-Admin-Takeover-THM- exploit 📄 التفاصيل ← Sploitus Proof-of-concept exploit. PoC Only 🟡 Medium PoC Research Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web Recruit-SSRF-LFI-SQL-Injection-Admin-Takeover-THM exploit 📄 التفاصيل ← Sploitus Proof-of-concept exploit. PoC Only 🟡 Medium PoC Research Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit CVE-2026-95102
CVE-2026-95102 - Monta monta.app Missing Authentication for Critical Function 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-95102 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… No 🟡 Medium Exploit Refer to CVE-2026-95102 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-94593
CVE-2026-94593 - Armatura LLC Armatura One Insertion of Sensitive Information in… 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-94593 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… No 🟡 Medium Vulnerability Refer to CVE-2026-94593 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-94592
CVE-2026-94592 - Armatura LLC Armatura One Use of Hard-coded Credentials 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-94592 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… No 🟡 Medium Vulnerability Refer to CVE-2026-94592 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-94591
CVE-2026-94591 - Armatura LLC Armatura One Use of Hard-coded Cryptographic Key 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-94591 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… No 🟡 Medium Vulnerability Refer to CVE-2026-94591 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-82041
CVE-2026-82041 - UTMStack < 11.2.16 Missing Authorization via Command WebSock… 📄 التفاصيل ←
MITRE CVE High CVE ID :CVE-2026-82041 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Descrip… No 🟡 Medium Vulnerability Refer to CVE-2026-82041 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-104474 CVSS 6.7
CVE-2026-104474 — OpenLiteSpeed before 1.9.3 contains a local privilege escalati… 📄 التفاصيل ←
NVD OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh… No 🟡 Medium Vulnerability Refer to CVE-2026-104474 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-104475 CVSS 5.4
CVE-2026-104475 — IDURAR ERP CRM through 4.1.1 contains a stored cross-site scri… 📄 التفاصيل ←
NVD IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authen… No 🟡 Medium Vulnerability Refer to CVE-2026-104475 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-104476 CVSS 5.9
CVE-2026-104476 — Backdrop CMS before 1.35.1 contains an information disclosure … 📄 التفاصيل ←
NVD Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthentica… No 🟡 Medium Vulnerability Refer to CVE-2026-104476 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-104477 CVSS 6.1
CVE-2026-104477 — Showdown through 2.1.0 contains a cross-site scripting vulnera… 📄 التفاصيل ←
NVD Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image … No 🟡 Medium Vulnerability Refer to CVE-2026-104477 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-104479 CVSS 5.4
CVE-2026-104479 — Shopclass before 6.2.0 contains a stored cross-site scripting … 📄 التفاصيل ←
NVD Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registe… No 🟡 Medium PHP Vulnerability Refer to CVE-2026-104479 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Web CVE-2026-105029 CVSS 4.3
CVE-2026-105029 — UVdesk support-center-bundle before 1.1.3.3 contains an insecu… 📄 التفاصيل ←
NVD UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerabili… No 🟡 Medium PHP Vulnerability Refer to CVE-2026-105029 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-105030 CVSS 5.3
CVE-2026-105030 — Kener 4.0.0 before 4.1.6 contains an information disclosure vu… 📄 التفاصيل ←
NVD Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticate… No 🟡 Medium Vulnerability Refer to CVE-2026-105030 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-100180 CVSS 5.4
CVE-2026-100180 — The Jeg Kit for Elementor – Powerful Addons for Elementor, Wid… 📄 التفاصيل ←
NVD The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plu… No 🟡 Medium WordPress Vulnerability Update to v3.2.19
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92243 CVSS 6.1
CVE-2026-92243 — The Ivory Search – WordPress Search Plugin plugin for WordPress… 📄 التفاصيل ←
NVD The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit… No 🟡 Medium WordPress Exploit Update to v5.5.18
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-94378 CVSS 6.4
CVE-2026-94378 — The SupportCandy – AI Customer Support Ticket System & Live… 📄 التفاصيل ←
NVD The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress i… No 🟡 Medium WordPress AI Attack Update to v3.5.3
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-94539 CVSS 6.5
CVE-2026-94539 — The SupportCandy – AI Customer Support Ticket System & Live… 📄 التفاصيل ←
NVD The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress i… No 🟡 Medium WordPress AI Attack Update to v3.5.3
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-95865 CVSS 6.5
CVE-2026-95865 — The Beaver Builder Page Builder – Drag and Drop Website Builder… 📄 التفاصيل ←
NVD The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t… No 🟡 Medium WordPress Vulnerability Update to v2.11.0
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92538 CVSS 6.1
CVE-2026-92538 — The LearnPress – WordPress LMS Plugin for Create and Sell Onlin… 📄 التفاصيل ←
NVD The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul… No 🟡 Medium WordPress Vulnerability Update to v4.4.7
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92551 CVSS 6.1
CVE-2026-92551 — The Paid Membership Plugin, Ecommerce, User Registration Form, … 📄 التفاصيل ←
NVD The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… No 🟡 Medium WordPress Exploit Update to v4.17.4
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92727 CVSS 6.4
CVE-2026-92727 — The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews,… 📄 التفاصيل ←
NVD The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed P… No 🟡 Medium WordPress Vulnerability Update to v4.6.6
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress CVE-2026-92826 CVSS 6.1
CVE-2026-92826 — The EWWW Image Optimizer plugin for WordPress is vulnerable to … 📄 التفاصيل ←
NVD The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via RE… No 🟡 Medium WordPress Exploit Update to v8.7.7
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-105051
CVE-2026-105051 | Irdeto Denuvo Anti-Tamper up to 2026-03-04 Hypervisor SimpleSv… 📄 التفاصيل ←
VulDB A vulnerability was found in Irdeto Denuvo Anti-Tamper up to 2026-03-04. It has been declared as pro… No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-105049
CVE-2026-105049 | Zilliz Attu up to 2.6.4/2.x Playground Feature missing authent… 📄 التفاصيل ←
VulDB A vulnerability was found in Zilliz Attu up to 2.6.4/2.x and classified as critical. Impacted is an … No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Exploit CVE-2026-105048
CVE-2026-105048 | Zilliz Attu up to 2.6.4 Playground server-side request forgery 📄 التفاصيل ←
VulDB A vulnerability has been found in Zilliz Attu up to 2.6.4 and classified as critical. This issue aff… No 🟡 Medium Exploit Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-105046
CVE-2026-105046 | Kentico Xperience up to 13.0.215 Administration API Endpoints … 📄 التفاصيل ←
VulDB A vulnerability, which was classified as problematic, has been found in Kentico Xperience up to 13.0… No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-105043
CVE-2026-105043 | MathWorks Simulink prior R2026b code injection 📄 التفاصيل ←
VulDB A vulnerability marked as problematic has been reported in MathWorks Simulink. This impacts an unkno… No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-97212
CVE-2026-97212 | Monta monta.app WebSocket backend improper authorization 📄 التفاصيل ←
VulDB A vulnerability labeled as critical has been found in Monta monta.app. This affects an unknown funct… No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-94594
CVE-2026-94594 | Armatura One Message Broker cleartext storage 📄 التفاصيل ←
VulDB A vulnerability identified as problematic has been detected in Armatura One. The impacted element is… No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-93474
CVE-2026-93474 | Monta App information disclosure 📄 التفاصيل ←
VulDB A vulnerability was found in Monta App. It has been declared as problematic. This issue affects some… No 🟡 Medium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-77387 CVSS 4
CVE-2026-77387 — geopy: Regular Expression Denial of Service (ReDoS) in geopy.Po… 📄 التفاصيل ←
GHSA ### Impact `geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, m… No 🟡 Medium Vulnerability Update to v2.5.0
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Ransomware 🏴‍☠️ Akira has just published a new victim : The Official Collegeof Architects o… 📄 التفاصيل ← Ransomware.live The Official College of Architects of León (COAL) was established on July 12, 1931, encompassi ng th… No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Cloud Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Ad… 📄 التفاصيل ← Cyber Security News Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its C… No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General ps5-pihost 📄 التفاصيل ← Vulners PS5 Pi Host Use Raspberry Pi OS Lite 64-bit, Bookworm or newer with NetworkManager. A 64 GB SD card … No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
WordPress EUVD-2026-91881 📄 التفاصيل ← Vulners The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… No 🟢 Low WordPress Vulnerability Update to v2.13.1
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General EUVD-2026-91869 📄 التفاصيل ← Vulners OpenAPV before 1.1.1.0 has a readbitstream heap-based buffer overflow... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
NVIDIA EUVD-2026-91868 📄 التفاصيل ← Vulners In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes the… No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General GHSA-P58F-9548-MPM2 vulnerabilities 📄 التفاصيل ← Vulners Vulnerabilities for packages: py3-cassandra-medusa... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General GHSA-X78J-V8H9-3J2Q vulnerabilities 📄 التفاصيل ← Vulners Vulnerabilities for packages: py3-cassandra-medusa... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General GHSA-C475-QRG2-PJ4R vulnerabilities 📄 التفاصيل ← Vulners Vulnerabilities for packages: code-server... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General GHSA-WHH4-5Q6C-9V3X vulnerabilities 📄 التفاصيل ← Vulners Vulnerabilities for packages: awx... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General GHSA-QPF5-3WFW-FH7Q vulnerabilities 📄 التفاصيل ← Vulners Vulnerabilities for packages: awx... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General GHSA-G5VV-9GXW-82HX vulnerabilities 📄 التفاصيل ← Vulners Vulnerabilities for packages: awx... No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
OT/ICS 🏴‍☠️ Nightspire has just published a new victim : Forma Therapeutics Holdings, I… 📄 التفاصيل ← Ransomware.live - Clinical Trial & Statistical Data- Electronic Lab Notebooks & Research IP- Drug Di… No 🟢 Low ICS/OT Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Browser Chrome Dev for Desktop Update 📄 التفاصيل ← Chrome Releases The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux.A partial list of change… No 🟢 Low Microsoft Windows | Google Chrome Vulnerability Update to v157.0.8081
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General 🏴‍☠️ Spirals has just published a new victim : seven seas group 📄 التفاصيل ← Ransomware.live Seven Seas is a global maritime services group that specializes in providing general ship supplies, … No 🟢 Low Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Browser Chrome Dev for Android Update 📄 التفاصيل ← Chrome Releases Hi everyone! We've just released Chrome Dev 157 (157.0.8080.0) for Android. It's now avail… No 🟢 Low Android | Google Chrome | Chromium Vulnerability Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
General 🏴‍☠️ Qilin has just published a new victim : Thai Lion Air 📄 التفاصيل ← Ransomware.live N/A No 🟢 Low AI Attack Apply vendor security patch
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-79113
CVE-2026-79113 — OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer o… 📄 التفاصيل ←
NVD OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. No 🟢 Low Vulnerability Refer to CVE-2026-79113 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Open Source CVE-2026-105083 CVSS 3.9
CVE-2026-105083 — ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy by… 📄 التفاصيل ←
NVD ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache … No 🟢 Low Vulnerability Refer to CVE-2026-105083 NVD advisory
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Browser Chrome Dev for Desktop Update 📄 التفاصيل ← Chrome Releases The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux.A partial list of change… No 🟢 Low Google Chrome / ChromeOS Vulnerability Update Chrome to latest version
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Browser Chrome Dev for Android Update 📄 التفاصيل ← Chrome Releases Hi everyone! We've just released Chrome Dev 157 (157.0.8080.0) for Android. It's now avail… No 🟢 Low Google Chrome / ChromeOS Vulnerability Update Chrome to latest version
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Vulnerability CVE-2026-104855
CVE-2026-104855 — Wasmtime: Preemption and traps during bulk operations enable b… 📄 التفاصيل ←
GHSA ### Impact Wasmtime's implementation of bulk-data-transfer WebAssembly instructions, such as `… PoC Only 🟢 Low PoC Research Update to v46.0.2
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
Rows:
CVE-2026-90970 CVSS 9.9
Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution…
🔴 Critical
Cyber Security News 🔥 No Open Source 📅 2026-10-03
GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attac…
📄 التفاصيل ←
CVE-2026-97363
CVE-2026-97363 - Monta monta.app Improper Restriction of Excessive Aut…
🔴 Critical
MITRE CVE High 🔥 No Vulnerability 📅 2026-10-03
CVE ID :CVE-2026-97363 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Description :The WebSocket …
📄 التفاصيل ←
CVE-2026-82042
CVE-2026-82042 - UTMStack < 11.2.16 Authentication Bypass via Inter…
🔴 Critical
MITRE CVE High 🔥 No Vulnerability 📅 2026-10-03
CVE ID :CVE-2026-82042 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Description :UTMStack befor…
📄 التفاصيل ←
CVE-2026-105080 CVSS 9.9
CVE-2026-105080 — In ConvertX before 0.19.0, converters/calibre.ts doe…
🔴 Critical
NVD 🔥 No NVIDIA 📅 2026-10-03
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-conve…
📄 التفاصيل ←
CVE-2026-73802 CVSS 9.9
CVE-2026-73802 — gitea-runner: workflow container.options passes host …
🔴 Critical
GHSA 🔥 No Vulnerability 📅 2026-10-03
### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the …
📄 التفاصيل ←
CVE-2026-10032 CVSS 9.3
CVE-2026-10032 — @a2ui/web_core: `openUrl` permits `javascript:` URI e…
🔴 Critical
GHSA 🔥 No Web 📅 2026-10-03
### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` witho…
📄 التفاصيل ←
CVE-2026-3483
Security Advisory Ivanti DSM (CVE-2026-3483)
🟠 High
Vulners 🔥 No Exploit 📅 2026-10-03
Security Advisory Ivanti DSM CVE-2026-3483 Summary Ivanti has released an update for Ivanti Desktop and Server Managemen…
📄 التفاصيل ←
EUVD-2026-91879
🟠 High
Vulners 🔥 No WordPress 📅 2026-10-03
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to …
📄 التفاصيل ←
EUVD-2026-91875
🟠 High
Vulners 🔥 No WordPress 📅 2026-10-03
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injectio…
📄 التفاصيل ←
EUVD-2026-91874
🟠 High
Vulners 🔥 No Web 📅 2026-10-03
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enfor…
📄 التفاصيل ←
EUVD-2026-91893
🟠 High
Vulners 🔥 No WordPress 📅 2026-10-03
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation v…
📄 التفاصيل ←
EUVD-2026-91891
🟠 High
Vulners 🔥 No WordPress 📅 2026-10-03
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Pro…
📄 التفاصيل ←
EUVD-2026-91890
🟠 High
Vulners 🔥 No WordPress 📅 2026-10-03
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Pro…
📄 التفاصيل ←
Citrix NetScaler Keeps Rebooting Following the 0-Day Patch
🟠 High
Cyber Security News 🔥 Yes Network 📅 2026-10-03
Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency upd…
📄 التفاصيل ←
Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Pr…
🟠 High
Cyber Security News 🔥 No Linux 📅 2026-10-03
Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaws that could allow p…
📄 التفاصيل ←
CVE-2026-84411
CVE-2026-84411 - MikroTik RouterOS Integer Underflow
🟠 High
MITRE CVE High 🔥 No Network 📅 2026-10-03
CVE ID :CVE-2026-84411 Published : 2 octobre 2026 23:16 | 4 heures, 37 minutes ago Description :The web manage…
📄 التفاصيل ←
CVE-2026-75937
CVE-2026-75937 - OS Command Injection in Digi Accelerated Linux (DAL O…
🟠 High
MITRE CVE High 🔥 No Linux 📅 2026-10-03
CVE ID :CVE-2026-75937 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Description :A specially cr…
📄 التفاصيل ←
CVE-2026-18140 CVSS 7.5
CVE-2026-18140 — aws-smithy-json: Uncontrolled recursion in the aws-sm…
🟠 High
GHSA 🔥 No Cloud 📅 2026-10-03
### Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smith…
📄 التفاصيل ←
CVE-2026-96780
CVE-2026-96780 — figlet is vulnerable to denial of service via unbound…
🟠 High
GHSA 🔥 No Vulnerability 📅 2026-10-03
### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: - `whitespaceBreak: t…
📄 التفاصيل ←
CVE-2026-104433 CVSS 7.5
CVE-2026-104433 — Mooncake transfer engine before 0.3.12 contains an o…
🟠 High
NVD 🔥 No Vulnerability 📅 2026-10-03
Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of includ…
📄 التفاصيل ←
CVE-2026-104478 CVSS 7.1
CVE-2026-104478 — Formwork before 2.3.13 contains a path traversal vul…
🟠 High
NVD 🔥 No Web 📅 2026-10-03
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users…
📄 التفاصيل ←
CVE-2026-105090
CVE-2026-105090 — Formbricks before 5.4.4 and 6 before 6.0.1 allows st…
🟠 High
NVD 🔥 No Web 📅 2026-10-03
Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enfor…
📄 التفاصيل ←
CVE-2026-93428 CVSS 7.5
CVE-2026-93428 — The Ultimate Member – User Profile, Registration, Log…
🟠 High
NVD 🔥 No WordPress 📅 2026-10-03
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin p…
📄 التفاصيل ←
CVE-2026-96270 CVSS 7.2
CVE-2026-96270 — The Ultimate Member – User Profile, Registration, Log…
🟠 High
NVD 🔥 No WordPress 📅 2026-10-03
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin p…
📄 التفاصيل ←
CVE-2026-92536 CVSS 8.8
CVE-2026-92536 — The Paid Membership Plugin, Ecommerce, User Registrat…
🟠 High
NVD 🔥 No WordPress 📅 2026-10-03
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profile…
📄 التفاصيل ←
CVE-2026-92977 CVSS 7.2
CVE-2026-92977 — The Real Cookie Banner: GDPR & ePrivacy Cookie Co…
🟠 High
NVD 🔥 No WordPress 📅 2026-10-03
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scrip…
📄 التفاصيل ←
CVE-2026-97644 CVSS 8.8
CVE-2026-97644 — The Groundhogg — CRM, Newsletters, and Marketing Auto…
🟠 High
NVD 🔥 No WordPress 📅 2026-10-03
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation v…
📄 التفاصيل ←
CVE-2026-105050
CVE-2026-105050 | PeaZip up to 11.2.x os command injection
🟠 High
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability was found in PeaZip up to 11.2.x. It has been classified as problematic. The affected element is an unkn…
📄 التفاصيل ←
CVE-2026-104861 CVSS 7.5
CVE-2026-104861 — probe-image-size: Quadratic-time Denial of Service i…
🟠 High
GHSA 🔥 No Vulnerability 📅 2026-10-03
## Overview `probe-image-size` scans the SVG header with a searching regular expression, `/]*>/`. On input that cont…
📄 التفاصيل ←
CVE-2026-71416 CVSS 8.8
CVE-2026-71416 — Headroom vulnerable to Cross-Site WebSocket Hijacking…
🟠 High
GHSA 🔥 PoC Only Linux 📅 2026-10-03
### Summary The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests be…
📄 التفاصيل ←
ctf2ktoo6 exploit
🟡 Medium
Sploitus 🔥 PoC Only Exploit 📅 2026-10-03
Proof-of-concept exploit.…
📄 التفاصيل ←
ps5-pihost exploit
🟡 Medium
Sploitus 🔥 PoC Only Exploit 📅 2026-10-03
Proof-of-concept exploit.…
📄 التفاصيل ←
EUVD-2026-91876
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plug…
📄 التفاصيل ←
EUVD-2026-91878
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to …
📄 التفاصيل ←
EUVD-2026-91880
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …
📄 التفاصيل ←
EUVD-2026-91877
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPres…
📄 التفاصيل ←
EUVD-2026-91870
🟡 Medium
Vulners 🔥 No Open Source 📅 2026-10-03
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips …
📄 التفاصيل ←
EUVD-2026-91895
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected…
📄 التفاصيل ←
EUVD-2026-91896
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plu…
📄 التفاصيل ←
EUVD-2026-91894
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUESTURI Parameter K…
📄 التفاصيل ←
EUVD-2026-91892
🟡 Medium
Vulners 🔥 No WordPress 📅 2026-10-03
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site S…
📄 التفاصيل ←
relapse exploit
🟡 Medium
Sploitus 🔥 PoC Only Exploit 📅 2026-10-03
Proof-of-concept exploit.…
📄 التفاصيل ←
cheesy-p4u-decomp exploit
🟡 Medium
Sploitus 🔥 PoC Only Exploit 📅 2026-10-03
Proof-of-concept exploit.…
📄 التفاصيل ←
Recruit-SSRF-LFI-SQL-Injection-Admin-Takeover-THM- exploit
🟡 Medium
Sploitus 🔥 PoC Only Web 📅 2026-10-03
Proof-of-concept exploit.…
📄 التفاصيل ←
Recruit-SSRF-LFI-SQL-Injection-Admin-Takeover-THM exploit
🟡 Medium
Sploitus 🔥 PoC Only Web 📅 2026-10-03
Proof-of-concept exploit.…
📄 التفاصيل ←
CVE-2026-95102
CVE-2026-95102 - Monta monta.app Missing Authentication for Critical F…
🟡 Medium
MITRE CVE High 🔥 No Exploit 📅 2026-10-03
CVE ID :CVE-2026-95102 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Description :WebSocket endp…
📄 التفاصيل ←
CVE-2026-94593
CVE-2026-94593 - Armatura LLC Armatura One Insertion of Sensitive Info…
🟡 Medium
MITRE CVE High 🔥 No Vulnerability 📅 2026-10-03
CVE ID :CVE-2026-94593 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Description :Armatura One&#…
📄 التفاصيل ←
CVE-2026-94592
CVE-2026-94592 - Armatura LLC Armatura One Use of Hard-coded Credentia…
🟡 Medium
MITRE CVE High 🔥 No Vulnerability 📅 2026-10-03
CVE ID :CVE-2026-94592 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Description :Armatura One&#…
📄 التفاصيل ←
CVE-2026-94591
CVE-2026-94591 - Armatura LLC Armatura One Use of Hard-coded Cryptogra…
🟡 Medium
MITRE CVE High 🔥 No Vulnerability 📅 2026-10-03
CVE ID :CVE-2026-94591 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Description :Armatura One s…
📄 التفاصيل ←
CVE-2026-82041
CVE-2026-82041 - UTMStack < 11.2.16 Missing Authorization via Comma…
🟡 Medium
MITRE CVE High 🔥 No Vulnerability 📅 2026-10-03
CVE ID :CVE-2026-82041 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Description :UTMStack befor…
📄 التفاصيل ←
CVE-2026-104474 CVSS 6.7
CVE-2026-104474 — OpenLiteSpeed before 1.9.3 contains a local privileg…
🟡 Medium
NVD 🔥 No Vulnerability 📅 2026-10-03
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverifie…
📄 التفاصيل ←
CVE-2026-104475 CVSS 5.4
CVE-2026-104475 — IDURAR ERP CRM through 4.1.1 contains a stored cross…
🟡 Medium
NVD 🔥 No Web 📅 2026-10-03
IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inj…
📄 التفاصيل ←
CVE-2026-104476 CVSS 5.9
CVE-2026-104476 — Backdrop CMS before 1.35.1 contains an information d…
🟡 Medium
NVD 🔥 No Vulnerability 📅 2026-10-03
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to ret…
📄 التفاصيل ←
CVE-2026-104477 CVSS 6.1
CVE-2026-104477 — Showdown through 2.1.0 contains a cross-site scripti…
🟡 Medium
NVD 🔥 No Web 📅 2026-10-03
Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fa…
📄 التفاصيل ←
CVE-2026-104479 CVSS 5.4
CVE-2026-104479 — Shopclass before 6.2.0 contains a stored cross-site …
🟡 Medium
NVD 🔥 No Web 📅 2026-10-03
Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users …
📄 التفاصيل ←
CVE-2026-105029 CVSS 4.3
CVE-2026-105029 — UVdesk support-center-bundle before 1.1.3.3 contains…
🟡 Medium
NVD 🔥 No Web 📅 2026-10-03
UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket…
📄 التفاصيل ←
CVE-2026-105030 CVSS 5.3
CVE-2026-105030 — Kener 4.0.0 before 4.1.6 contains an information dis…
🟡 Medium
NVD 🔥 No Vulnerability 📅 2026-10-03
Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retri…
📄 التفاصيل ←
CVE-2026-100180 CVSS 5.4
CVE-2026-100180 — The Jeg Kit for Elementor – Powerful Addons for Elem…
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is…
📄 التفاصيل ←
CVE-2026-92243 CVSS 6.1
CVE-2026-92243 — The Ivory Search – WordPress Search Plugin plugin for…
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …
📄 التفاصيل ←
CVE-2026-94378 CVSS 6.4
CVE-2026-94378 — The SupportCandy – AI Customer Support Ticket System …
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stor…
📄 التفاصيل ←
CVE-2026-94539 CVSS 6.5
CVE-2026-94539 — The SupportCandy – AI Customer Support Ticket System …
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time…
📄 التفاصيل ←
CVE-2026-95865 CVSS 6.5
CVE-2026-95865 — The Beaver Builder Page Builder – Drag and Drop Websi…
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injectio…
📄 التفاصيل ←
CVE-2026-92538 CVSS 6.1
CVE-2026-92538 — The LearnPress – WordPress LMS Plugin for Create and …
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected…
📄 التفاصيل ←
CVE-2026-92551 CVSS 6.1
CVE-2026-92551 — The Paid Membership Plugin, Ecommerce, User Registrat…
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profile…
📄 التفاصيل ←
CVE-2026-92727 CVSS 6.4
CVE-2026-92727 — The EmbedPress – PDF Embedder, 3D PDF FlipBook, Googl…
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin …
📄 التفاصيل ←
CVE-2026-92826 CVSS 6.1
CVE-2026-92826 — The EWWW Image Optimizer plugin for WordPress is vuln…
🟡 Medium
NVD 🔥 No WordPress 📅 2026-10-03
The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter …
📄 التفاصيل ←
CVE-2026-105051
CVE-2026-105051 | Irdeto Denuvo Anti-Tamper up to 2026-03-04 Hyperviso…
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability was found in Irdeto Denuvo Anti-Tamper up to 2026-03-04. It has been declared as problematic. The impact…
📄 التفاصيل ←
CVE-2026-105049
CVE-2026-105049 | Zilliz Attu up to 2.6.4/2.x Playground Feature missi…
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability was found in Zilliz Attu up to 2.6.4/2.x and classified as critical. Impacted is an unknown function of …
📄 التفاصيل ←
CVE-2026-105048
CVE-2026-105048 | Zilliz Attu up to 2.6.4 Playground server-side reque…
🟡 Medium
VulDB 🔥 No Exploit 📅 2026-10-03
A vulnerability has been found in Zilliz Attu up to 2.6.4 and classified as critical. This issue affects some unknown pr…
📄 التفاصيل ←
CVE-2026-105046
CVE-2026-105046 | Kentico Xperience up to 13.0.215 Administration API …
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability, which was classified as problematic, has been found in Kentico Xperience up to 13.0.215. This affects a…
📄 التفاصيل ←
CVE-2026-105043
CVE-2026-105043 | MathWorks Simulink prior R2026b code injection
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability marked as problematic has been reported in MathWorks Simulink. This impacts an unknown function. Perform…
📄 التفاصيل ←
CVE-2026-97212
CVE-2026-97212 | Monta monta.app WebSocket backend improper authorizat…
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability labeled as critical has been found in Monta monta.app. This affects an unknown function of the component…
📄 التفاصيل ←
CVE-2026-94594
CVE-2026-94594 | Armatura One Message Broker cleartext storage
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability identified as problematic has been detected in Armatura One. The impacted element is an unknown function…
📄 التفاصيل ←
CVE-2026-93474
CVE-2026-93474 | Monta App information disclosure
🟡 Medium
VulDB 🔥 No Vulnerability 📅 2026-10-03
A vulnerability was found in Monta App. It has been declared as problematic. This issue affects some unknown processing.…
📄 التفاصيل ←
CVE-2026-77387 CVSS 4
CVE-2026-77387 — geopy: Regular Expression Denial of Service (ReDoS) i…
🟡 Medium
GHSA 🔥 No Vulnerability 📅 2026-10-03
### Impact `geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, malformed coordinate …
📄 التفاصيل ←
🏴‍☠️ Akira has just published a new victim : The Official Collegeof Ar…
🟢 Low
Ransomware.live 🔥 No Ransomware 📅 2026-10-03
The Official College of Architects of León (COAL) was established on July 12, 1931, encompassi ng the regions of León, A…
📄 التفاصيل ←
Critical Dell Container Storage Flaws Let Unauthenticated Attackers Ga…
🟢 Low
Cyber Security News 🔥 No Cloud 📅 2026-10-03
Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its Container Storage Mod…
📄 التفاصيل ←
ps5-pihost
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
PS5 Pi Host Use Raspberry Pi OS Lite 64-bit, Bookworm or newer with NetworkManager. A 64 GB SD card has ample room. This…
📄 التفاصيل ←
EUVD-2026-91881
🟢 Low
Vulners 🔥 No WordPress 📅 2026-10-03
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plug…
📄 التفاصيل ←
EUVD-2026-91869
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
OpenAPV before 1.1.1.0 has a readbitstream heap-based buffer overflow...…
📄 التفاصيل ←
EUVD-2026-91868
🟢 Low
Vulners 🔥 No NVIDIA 📅 2026-10-03
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-conve…
📄 التفاصيل ←
GHSA-P58F-9548-MPM2 vulnerabilities
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
Vulnerabilities for packages: py3-cassandra-medusa...…
📄 التفاصيل ←
GHSA-X78J-V8H9-3J2Q vulnerabilities
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
Vulnerabilities for packages: py3-cassandra-medusa...…
📄 التفاصيل ←
GHSA-C475-QRG2-PJ4R vulnerabilities
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
Vulnerabilities for packages: code-server...…
📄 التفاصيل ←
GHSA-WHH4-5Q6C-9V3X vulnerabilities
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
Vulnerabilities for packages: awx...…
📄 التفاصيل ←
GHSA-QPF5-3WFW-FH7Q vulnerabilities
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
Vulnerabilities for packages: awx...…
📄 التفاصيل ←
GHSA-G5VV-9GXW-82HX vulnerabilities
🟢 Low
Vulners 🔥 No General 📅 2026-10-03
Vulnerabilities for packages: awx...…
📄 التفاصيل ←
🏴‍☠️ Nightspire has just published a new victim : Forma Therapeutics H…
🟢 Low
Ransomware.live 🔥 No OT/ICS 📅 2026-10-03
- Clinical Trial & Statistical Data- Electronic Lab Notebooks & Research IP- Drug Discovery & Pi…
📄 التفاصيل ←
Chrome Dev for Desktop Update
🟢 Low
Chrome Releases 🔥 No Browser 📅 2026-10-03
The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux.A partial list of changes is available in th…
📄 التفاصيل ←
🏴‍☠️ Spirals has just published a new victim : seven seas group
🟢 Low
Ransomware.live 🔥 No General 📅 2026-10-03
Seven Seas is a global maritime services group that specializes in providing general ship supplies, stores, spare parts …
📄 التفاصيل ←
Chrome Dev for Android Update
🟢 Low
Chrome Releases 🔥 No Browser 📅 2026-10-03
Hi everyone! We've just released Chrome Dev 157 (157.0.8080.0) for Android. It's now available on Google Play.…
📄 التفاصيل ←
🏴‍☠️ Qilin has just published a new victim : Thai Lion Air
🟢 Low
Ransomware.live 🔥 No General 📅 2026-10-03
N/A…
📄 التفاصيل ←
CVE-2026-79113
CVE-2026-79113 — OpenAPV before 1.1.1.0 has a read_bitstream heap-base…
🟢 Low
NVD 🔥 No Vulnerability 📅 2026-10-03
OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.…
📄 التفاصيل ←
CVE-2026-105083 CVSS 3.9
CVE-2026-105083 — ImageMagick before 7.1.2-32 and 6.9.13-57 contains a…
🟢 Low
NVD 🔥 No Open Source 📅 2026-10-03
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips …
📄 التفاصيل ←
Chrome Dev for Desktop Update
🟢 Low
Chrome Releases 🔥 No Browser 📅 2026-10-03
The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux.A partial list of changes is available in th…
📄 التفاصيل ←
Chrome Dev for Android Update
🟢 Low
Chrome Releases 🔥 No Browser 📅 2026-10-03
Hi everyone! We've just released Chrome Dev 157 (157.0.8080.0) for Android. It's now available on Google Play.…
📄 التفاصيل ←
CVE-2026-104855
CVE-2026-104855 — Wasmtime: Preemption and traps during bulk operation…
🟢 Low
GHSA 🔥 PoC Only Vulnerability 📅 2026-10-03
### Impact Wasmtime's implementation of bulk-data-transfer WebAssembly instructions, such as `memory.copy`, contai…
📄 التفاصيل ←
Rows: