CVE ID :CVE-2026-100886 Published : Sept. 27, 2026, 11:16 p.m. | 1 hour, 8 minutes ago Description :A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an…
CVE-2026-101090 – Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
CVE ID :CVE-2026-101090 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional…
CVE-2026-101084 – obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE ID :CVE-2026-101084 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated…
CVE-2026-101065 – Obot Quickstart Docker Deployment Unauthenticated Admin Access
CVE ID :CVE-2026-101065 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the…
CVE-2026-101064 – Obot before v0.23.0 Server-Side Request Forgery via MCP
CVE ID :CVE-2026-101064 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged…
CVE-2026-82901 – Ultra Addons for Contact Form 7 <= 3.5.50 – Unauthenticated Arbitrary File Upload via Signature Form Field
CVE ID :CVE-2026-82901 Published : Sept. 26, 2026, 7:16 p.m. | 5 hours, 3 minutes ago Description :The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due…
CVE-2026-85984 – miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 – Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter
CVE ID :CVE-2026-85984 Published : Sept. 26, 2026, 6:16 p.m. | 6 hours, 3 minutes ago Description :The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via…
CVE-2026-77203 – Groups <= 4.6.0 – Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode
CVE ID :CVE-2026-77203 Published : Sept. 26, 2026, 6:16 p.m. | 6 hours, 3 minutes ago Description :The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all…
CVE-2026-97163 – Joomla Extension – lomart.fr – Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE ID :CVE-2026-97163 Published : Sept. 26, 2026, 3:16 p.m. | 9 hours, 3 minutes ago Description :Joomla Extension – lomart.fr – Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 10.0…
CVE-2026-97162 – Joomla Extension – lomart.fr – Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE ID :CVE-2026-97162 Published : Sept. 26, 2026, 3:16 p.m. | 9 hours, 3 minutes ago Description :Joomla Extension – lomart.fr – Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 Severity: 8.3…