| المجال | الحدث / CVE | المصدر | الوصف | الاستغلال | الخطورة | الأنظمة المتأثرة | نوع التهديد | الحلول | 📅 تاريخ النشر |
|---|---|---|---|---|---|---|---|---|---|
| Open Source |
CVE-2026-90970
CVSS 9.9 Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks 📄 التفاصيل ← |
Cyber Security News | GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow… | No | 🔴 Critical | GitLab | AI Attack | Update to v19.2.4 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Vulnerability |
CVE-2026-97363
CVE-2026-97363 - Monta monta.app Improper Restriction of Excessive Authenticatio… 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-97363 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… | No | 🔴 Critical | Vulnerability | Refer to CVE-2026-97363 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-82042
CVE-2026-82042 - UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyF… 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-82042 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Descrip… | No | 🔴 Critical | Vulnerability | Refer to CVE-2026-82042 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| NVIDIA |
CVE-2026-105080
CVSS 9.9 CVE-2026-105080 — In ConvertX before 0.19.0, converters/calibre.ts does not bloc… 📄 التفاصيل ← |
NVD | In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes the… | No | 🔴 Critical | Vulnerability | Refer to CVE-2026-105080 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-73802
CVSS 9.9 CVE-2026-73802 — gitea-runner: workflow container.options passes host namespaces… 📄 التفاصيل ← |
GHSA | ### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker… | No | 🔴 Critical | Ubuntu Linux | Docker | Vulnerability | Refer to CVE-2026-73802 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Web |
CVE-2026-10032
CVSS 9.3 CVE-2026-10032 — @a2ui/web_core: `openUrl` permits `javascript:` URI execution v… 📄 التفاصيل ← |
GHSA | ### Summary The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `… | No | 🔴 Critical | Vulnerability | Update to v0.10.2 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Exploit |
CVE-2026-3483
Security Advisory Ivanti DSM (CVE-2026-3483) 📄 التفاصيل ← |
Vulners | Security Advisory Ivanti DSM CVE-2026-3483 Summary Ivanti has released an update for Ivanti Desktop … | No | 🟠 High | Exploit | Refer to CVE-2026-3483 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress | EUVD-2026-91879 📄 التفاصيل ← | Vulners | The SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent plugin for WordPre… | No | 🟠 High | WordPress | AI Attack | Update to v3.5.3 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91875 📄 التفاصيل ← | Vulners | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t… | No | 🟠 High | WordPress | Vulnerability | Update to v2.11.0 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Web | EUVD-2026-91874 📄 التفاصيل ← | Vulners | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts f… | No | 🟠 High | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress | EUVD-2026-91893 📄 التفاصيل ← | Vulners | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr… | No | 🟠 High | WordPress | Vulnerability | Update to v4.9 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91891 📄 التفاصيل ← | Vulners | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Re… | No | 🟠 High | WordPress | Vulnerability | Update to v4.17.4 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91890 📄 التفاصيل ← | Vulners | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &amp; Re… | No | 🟠 High | WordPress | Vulnerability | Update to v4.17.4 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Network | Citrix NetScaler Keeps Rebooting Following the 0-Day Patch 📄 التفاصيل ← | Cyber Security News | Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.3… | Yes | 🟠 High | Citrix | Zero-Day | Update to v14.1 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Linux | Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Es… 📄 التفاصيل ← | Cyber Security News | Debian has released a major Linux kernel security update covering 1,313 CVE entries, addressing flaw… | No | 🟠 High | Linux Kernel | Debian Linux | Vulnerability | Update to v6.12.111 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Network |
CVE-2026-84411
CVE-2026-84411 - MikroTik RouterOS Integer Underflow 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-84411 Published : 2 octobre 2026 23:16 | 4 heures, 37 minutes ago Descrip… | No | 🟠 High | Vulnerability | Refer to CVE-2026-84411 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Linux |
CVE-2026-75937
CVE-2026-75937 - OS Command Injection in Digi Accelerated Linux (DAL OS) 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-75937 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Descrip… | No | 🟠 High | Vulnerability | Refer to CVE-2026-75937 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Cloud |
CVE-2026-18140
CVSS 7.5 CVE-2026-18140 — aws-smithy-json: Uncontrolled recursion in the aws-smithy-json … 📄 التفاصيل ← |
GHSA | ### Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients an… | No | 🟠 High | Vulnerability | Update to v0.62.6 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-96780
CVE-2026-96780 — figlet is vulnerable to denial of service via unbounded loop wh… 📄 التفاصيل ← |
GHSA | ### Impact A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when **both**: -… | No | 🟠 High | Node.js | Vulnerability | Update to v1.11.3 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Vulnerability |
CVE-2026-104433
CVSS 7.5 CVE-2026-104433 — Mooncake transfer engine before 0.3.12 contains an out-of-boun… 📄 التفاصيل ← |
NVD | Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readStrin… | No | 🟠 High | Vulnerability | Refer to CVE-2026-104433 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Web |
CVE-2026-104478
CVSS 7.1 CVE-2026-104478 — Formwork before 2.3.13 contains a path traversal vulnerability… 📄 التفاصيل ← |
NVD | Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authe… | No | 🟠 High | PHP | Vulnerability | Refer to CVE-2026-104478 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Web |
CVE-2026-105090
CVE-2026-105090 — Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. … 📄 التفاصيل ← |
NVD | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts f… | No | 🟠 High | Vulnerability | Refer to CVE-2026-105090 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress |
CVE-2026-93428
CVSS 7.5 CVE-2026-93428 — The Ultimate Member – User Profile, Registration, Login, Member… 📄 التفاصيل ← |
NVD | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… | No | 🟠 High | WordPress | Vulnerability | Update to v2.13.1 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-96270
CVSS 7.2 CVE-2026-96270 — The Ultimate Member – User Profile, Registration, Login, Member… 📄 التفاصيل ← |
NVD | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… | No | 🟠 High | WordPress | Vulnerability | Update to v2.13.1 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92536
CVSS 8.8 CVE-2026-92536 — The Paid Membership Plugin, Ecommerce, User Registration Form, … 📄 التفاصيل ← |
NVD | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… | No | 🟠 High | WordPress | Exploit | Update to v4.17.4 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92977
CVSS 7.2 CVE-2026-92977 — The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plug… 📄 التفاصيل ← |
NVD | The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Sto… | No | 🟠 High | WordPress | Exploit | Update to v5.3.5 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-97644
CVSS 8.8 CVE-2026-97644 — The Groundhogg — CRM, Newsletters, and Marketing Automation plu… 📄 التفاصيل ← |
NVD | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr… | No | 🟠 High | WordPress | Vulnerability | Update to v4.9 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Vulnerability |
CVE-2026-105050
CVE-2026-105050 | PeaZip up to 11.2.x os command injection 📄 التفاصيل ← |
VulDB | A vulnerability was found in PeaZip up to 11.2.x. It has been classified as problematic. The affecte… | No | 🟠 High | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-104861
CVSS 7.5 CVE-2026-104861 — probe-image-size: Quadratic-time Denial of Service in the SVG … 📄 التفاصيل ← |
GHSA | ## Overview `probe-image-size` scans the SVG header with a searching regular expression, `/]*>/`… | No | 🟠 High | Vulnerability | Refer to CVE-2026-104861 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Linux |
CVE-2026-71416
CVSS 8.8 CVE-2026-71416 — Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) 📄 التفاصيل ← |
GHSA | ### Summary The Headroom WebSocket server does not validate the `Origin` header of incoming client W… | PoC Only | 🟠 High | AI Attack | Refer to CVE-2026-71416 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Exploit | ctf2ktoo6 exploit 📄 التفاصيل ← | Sploitus | Proof-of-concept exploit. | PoC Only | 🟡 Medium | PoC Research | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Exploit | ps5-pihost exploit 📄 التفاصيل ← | Sploitus | Proof-of-concept exploit. | PoC Only | 🟡 Medium | PoC Research | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress | EUVD-2026-91876 📄 التفاصيل ← | Vulners | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… | No | 🟡 Medium | WordPress | Vulnerability | Update to v2.13.1 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91878 📄 التفاصيل ← | Vulners | The SupportCandy – AI Customer Support Ticket System &amp; Live Chatbot Agent plugin for WordPre… | No | 🟡 Medium | WordPress | AI Attack | Update to v3.5.3 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91880 📄 التفاصيل ← | Vulners | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit… | No | 🟡 Medium | WordPress | Vulnerability | Update to v5.5.18 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91877 📄 التفاصيل ← | Vulners | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets &amp; Templates for WordPress… | No | 🟡 Medium | WordPress | Vulnerability | Update to v3.2.19 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Open Source | EUVD-2026-91870 📄 التفاصيل ← | Vulners | ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache … | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress | EUVD-2026-91895 📄 التفاصيل ← | Vulners | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul… | No | 🟡 Medium | WordPress | Vulnerability | Update to v4.4.7 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91896 📄 التفاصيل ← | Vulners | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload &amp; Emb… | No | 🟡 Medium | WordPress | Vulnerability | Update to v4.6.6 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91894 📄 التفاصيل ← | Vulners | The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via RE… | No | 🟡 Medium | WordPress | Vulnerability | Update to v8.7.7 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress | EUVD-2026-91892 📄 التفاصيل ← | Vulners | The Real Cookie Banner: GDPR &amp; ePrivacy Cookie Consent plugin for WordPress is vulnerable to… | No | 🟡 Medium | WordPress | Vulnerability | Update to v5.3.5 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Exploit | relapse exploit 📄 التفاصيل ← | Sploitus | Proof-of-concept exploit. | PoC Only | 🟡 Medium | PoC Research | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Exploit | cheesy-p4u-decomp exploit 📄 التفاصيل ← | Sploitus | Proof-of-concept exploit. | PoC Only | 🟡 Medium | PoC Research | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Web | Recruit-SSRF-LFI-SQL-Injection-Admin-Takeover-THM- exploit 📄 التفاصيل ← | Sploitus | Proof-of-concept exploit. | PoC Only | 🟡 Medium | PoC Research | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Web | Recruit-SSRF-LFI-SQL-Injection-Admin-Takeover-THM exploit 📄 التفاصيل ← | Sploitus | Proof-of-concept exploit. | PoC Only | 🟡 Medium | PoC Research | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Exploit |
CVE-2026-95102
CVE-2026-95102 - Monta monta.app Missing Authentication for Critical Function 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-95102 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… | No | 🟡 Medium | Exploit | Refer to CVE-2026-95102 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-94593
CVE-2026-94593 - Armatura LLC Armatura One Insertion of Sensitive Information in… 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-94593 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-94593 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-94592
CVE-2026-94592 - Armatura LLC Armatura One Use of Hard-coded Credentials 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-94592 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-94592 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-94591
CVE-2026-94591 - Armatura LLC Armatura One Use of Hard-coded Cryptographic Key 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-94591 Published : 2 octobre 2026 22:16 | 5 heures, 37 minutes ago Descrip… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-94591 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-82041
CVE-2026-82041 - UTMStack < 11.2.16 Missing Authorization via Command WebSock… 📄 التفاصيل ← |
MITRE CVE High | CVE ID :CVE-2026-82041 Published : 2 octobre 2026 21:16 | 6 heures, 37 minutes ago Descrip… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-82041 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-104474
CVSS 6.7 CVE-2026-104474 — OpenLiteSpeed before 1.9.3 contains a local privilege escalati… 📄 التفاصيل ← |
NVD | OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-104474 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Web |
CVE-2026-104475
CVSS 5.4 CVE-2026-104475 — IDURAR ERP CRM through 4.1.1 contains a stored cross-site scri… 📄 التفاصيل ← |
NVD | IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authen… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-104475 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-104476
CVSS 5.9 CVE-2026-104476 — Backdrop CMS before 1.35.1 contains an information disclosure … 📄 التفاصيل ← |
NVD | Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthentica… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-104476 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Web |
CVE-2026-104477
CVSS 6.1 CVE-2026-104477 — Showdown through 2.1.0 contains a cross-site scripting vulnera… 📄 التفاصيل ← |
NVD | Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image … | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-104477 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Web |
CVE-2026-104479
CVSS 5.4 CVE-2026-104479 — Shopclass before 6.2.0 contains a stored cross-site scripting … 📄 التفاصيل ← |
NVD | Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registe… | No | 🟡 Medium | PHP | Vulnerability | Refer to CVE-2026-104479 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Web |
CVE-2026-105029
CVSS 4.3 CVE-2026-105029 — UVdesk support-center-bundle before 1.1.3.3 contains an insecu… 📄 التفاصيل ← |
NVD | UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerabili… | No | 🟡 Medium | PHP | Vulnerability | Refer to CVE-2026-105029 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Vulnerability |
CVE-2026-105030
CVSS 5.3 CVE-2026-105030 — Kener 4.0.0 before 4.1.6 contains an information disclosure vu… 📄 التفاصيل ← |
NVD | Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticate… | No | 🟡 Medium | Vulnerability | Refer to CVE-2026-105030 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress |
CVE-2026-100180
CVSS 5.4 CVE-2026-100180 — The Jeg Kit for Elementor – Powerful Addons for Elementor, Wid… 📄 التفاصيل ← |
NVD | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plu… | No | 🟡 Medium | WordPress | Vulnerability | Update to v3.2.19 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92243
CVSS 6.1 CVE-2026-92243 — The Ivory Search – WordPress Search Plugin plugin for WordPress… 📄 التفاصيل ← |
NVD | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit… | No | 🟡 Medium | WordPress | Exploit | Update to v5.5.18 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-94378
CVSS 6.4 CVE-2026-94378 — The SupportCandy – AI Customer Support Ticket System & Live… 📄 التفاصيل ← |
NVD | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress i… | No | 🟡 Medium | WordPress | AI Attack | Update to v3.5.3 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-94539
CVSS 6.5 CVE-2026-94539 — The SupportCandy – AI Customer Support Ticket System & Live… 📄 التفاصيل ← |
NVD | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress i… | No | 🟡 Medium | WordPress | AI Attack | Update to v3.5.3 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-95865
CVSS 6.5 CVE-2026-95865 — The Beaver Builder Page Builder – Drag and Drop Website Builder… 📄 التفاصيل ← |
NVD | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t… | No | 🟡 Medium | WordPress | Vulnerability | Update to v2.11.0 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92538
CVSS 6.1 CVE-2026-92538 — The LearnPress – WordPress LMS Plugin for Create and Sell Onlin… 📄 التفاصيل ← |
NVD | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul… | No | 🟡 Medium | WordPress | Vulnerability | Update to v4.4.7 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92551
CVSS 6.1 CVE-2026-92551 — The Paid Membership Plugin, Ecommerce, User Registration Form, … 📄 التفاصيل ← |
NVD | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… | No | 🟡 Medium | WordPress | Exploit | Update to v4.17.4 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92727
CVSS 6.4 CVE-2026-92727 — The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews,… 📄 التفاصيل ← |
NVD | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed P… | No | 🟡 Medium | WordPress | Vulnerability | Update to v4.6.6 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| WordPress |
CVE-2026-92826
CVSS 6.1 CVE-2026-92826 — The EWWW Image Optimizer plugin for WordPress is vulnerable to … 📄 التفاصيل ← |
NVD | The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via RE… | No | 🟡 Medium | WordPress | Exploit | Update to v8.7.7 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Vulnerability |
CVE-2026-105051
CVE-2026-105051 | Irdeto Denuvo Anti-Tamper up to 2026-03-04 Hypervisor SimpleSv… 📄 التفاصيل ← |
VulDB | A vulnerability was found in Irdeto Denuvo Anti-Tamper up to 2026-03-04. It has been declared as pro… | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-105049
CVE-2026-105049 | Zilliz Attu up to 2.6.4/2.x Playground Feature missing authent… 📄 التفاصيل ← |
VulDB | A vulnerability was found in Zilliz Attu up to 2.6.4/2.x and classified as critical. Impacted is an … | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Exploit |
CVE-2026-105048
CVE-2026-105048 | Zilliz Attu up to 2.6.4 Playground server-side request forgery 📄 التفاصيل ← |
VulDB | A vulnerability has been found in Zilliz Attu up to 2.6.4 and classified as critical. This issue aff… | No | 🟡 Medium | Exploit | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-105046
CVE-2026-105046 | Kentico Xperience up to 13.0.215 Administration API Endpoints … 📄 التفاصيل ← |
VulDB | A vulnerability, which was classified as problematic, has been found in Kentico Xperience up to 13.0… | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-105043
CVE-2026-105043 | MathWorks Simulink prior R2026b code injection 📄 التفاصيل ← |
VulDB | A vulnerability marked as problematic has been reported in MathWorks Simulink. This impacts an unkno… | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-97212
CVE-2026-97212 | Monta monta.app WebSocket backend improper authorization 📄 التفاصيل ← |
VulDB | A vulnerability labeled as critical has been found in Monta monta.app. This affects an unknown funct… | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-94594
CVE-2026-94594 | Armatura One Message Broker cleartext storage 📄 التفاصيل ← |
VulDB | A vulnerability identified as problematic has been detected in Armatura One. The impacted element is… | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-93474
CVE-2026-93474 | Monta App information disclosure 📄 التفاصيل ← |
VulDB | A vulnerability was found in Monta App. It has been declared as problematic. This issue affects some… | No | 🟡 Medium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-77387
CVSS 4 CVE-2026-77387 — geopy: Regular Expression Denial of Service (ReDoS) in geopy.Po… 📄 التفاصيل ← |
GHSA | ### Impact `geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, m… | No | 🟡 Medium | Vulnerability | Update to v2.5.0 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Ransomware | 🏴☠️ Akira has just published a new victim : The Official Collegeof Architects o… 📄 التفاصيل ← | Ransomware.live | The Official College of Architects of León (COAL) was established on July 12, 1931, encompassi ng th… | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Cloud | Critical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Ad… 📄 التفاصيل ← | Cyber Security News | Dell has released security update DSA-2026-448 to address multiple critical vulnerabilities in its C… | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | ps5-pihost 📄 التفاصيل ← | Vulners | PS5 Pi Host Use Raspberry Pi OS Lite 64-bit, Bookworm or newer with NetworkManager. A 64 GB SD card … | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| WordPress | EUVD-2026-91881 📄 التفاصيل ← | Vulners | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction &… | No | 🟢 Low | WordPress | Vulnerability | Update to v2.13.1 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| General | EUVD-2026-91869 📄 التفاصيل ← | Vulners | OpenAPV before 1.1.1.0 has a readbitstream heap-based buffer overflow... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| NVIDIA | EUVD-2026-91868 📄 التفاصيل ← | Vulners | In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes the… | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | GHSA-P58F-9548-MPM2 vulnerabilities 📄 التفاصيل ← | Vulners | Vulnerabilities for packages: py3-cassandra-medusa... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | GHSA-X78J-V8H9-3J2Q vulnerabilities 📄 التفاصيل ← | Vulners | Vulnerabilities for packages: py3-cassandra-medusa... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | GHSA-C475-QRG2-PJ4R vulnerabilities 📄 التفاصيل ← | Vulners | Vulnerabilities for packages: code-server... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | GHSA-WHH4-5Q6C-9V3X vulnerabilities 📄 التفاصيل ← | Vulners | Vulnerabilities for packages: awx... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | GHSA-QPF5-3WFW-FH7Q vulnerabilities 📄 التفاصيل ← | Vulners | Vulnerabilities for packages: awx... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| General | GHSA-G5VV-9GXW-82HX vulnerabilities 📄 التفاصيل ← | Vulners | Vulnerabilities for packages: awx... | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| OT/ICS | 🏴☠️ Nightspire has just published a new victim : Forma Therapeutics Holdings, I… 📄 التفاصيل ← | Ransomware.live | - Clinical Trial &amp; Statistical Data- Electronic Lab Notebooks &amp; Research IP- Drug Di… | No | 🟢 Low | ICS/OT | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Browser | Chrome Dev for Desktop Update 📄 التفاصيل ← | Chrome Releases | The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux.A partial list of change… | No | 🟢 Low | Microsoft Windows | Google Chrome | Vulnerability | Update to v157.0.8081 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| General | 🏴☠️ Spirals has just published a new victim : seven seas group 📄 التفاصيل ← | Ransomware.live | Seven Seas is a global maritime services group that specializes in providing general ship supplies, … | No | 🟢 Low | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Browser | Chrome Dev for Android Update 📄 التفاصيل ← | Chrome Releases | Hi everyone! We've just released Chrome Dev 157 (157.0.8080.0) for Android. It's now avail… | No | 🟢 Low | Android | Google Chrome | Chromium | Vulnerability | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| General | 🏴☠️ Qilin has just published a new victim : Thai Lion Air 📄 التفاصيل ← | Ransomware.live | N/A | No | 🟢 Low | AI Attack | Apply vendor security patch |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Vulnerability |
CVE-2026-79113
CVE-2026-79113 — OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer o… 📄 التفاصيل ← |
NVD | OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. | No | 🟢 Low | Vulnerability | Refer to CVE-2026-79113 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Open Source |
CVE-2026-105083
CVSS 3.9 CVE-2026-105083 — ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy by… 📄 التفاصيل ← |
NVD | ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache … | No | 🟢 Low | Vulnerability | Refer to CVE-2026-105083 NVD advisory |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
|
| Browser | Chrome Dev for Desktop Update 📄 التفاصيل ← | Chrome Releases | The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux.A partial list of change… | No | 🟢 Low | Google Chrome / ChromeOS | Vulnerability | Update Chrome to latest version |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Browser | Chrome Dev for Android Update 📄 التفاصيل ← | Chrome Releases | Hi everyone! We've just released Chrome Dev 157 (157.0.8080.0) for Android. It's now avail… | No | 🟢 Low | Google Chrome / ChromeOS | Vulnerability | Update Chrome to latest version |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|
| Vulnerability |
CVE-2026-104855
CVE-2026-104855 — Wasmtime: Preemption and traps during bulk operations enable b… 📄 التفاصيل ← |
GHSA | ### Impact Wasmtime's implementation of bulk-data-transfer WebAssembly instructions, such as `… | PoC Only | 🟢 Low | PoC Research | Update to v46.0.2 |
UTC: 2026-10-03
EDT: 2026-10-03
SA: 2026-10-03
|