CVE ID :CVE-2026-105126 Published : Oct. 4, 2026, 12:16 a.m. | 1 hour, 9 minutes ago Description :LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to…
CVE-2026-105123 – W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API
CVE ID :CVE-2026-105123 Published : Oct. 4, 2026, 12:16 a.m. | 1 hour, 9 minutes ago Description :W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary…
CVE-2026-96451 – WordPress Ultimate Member plugin <= 2.13.1 – Privilege Escalation vulnerability
CVE ID :CVE-2026-96451 Published : Oct. 3, 2026, 4:16 p.m. | 7 hours, 9 minutes ago Description :Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects…
CVE-2026-103065 – WordPress Kirki plugin <= 6.3.1 – Arbitrary Code Execution vulnerability
CVE ID :CVE-2026-103065 Published : Oct. 3, 2026, 3:16 p.m. | 8 hours, 9 minutes ago Description :Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly…
CVE-2026-105115 – OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
CVE ID :CVE-2026-105115 Published : Oct. 3, 2026, 2:16 p.m. | 9 hours, 9 minutes ago Description :OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that…
CVE-2026-105105 – Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration
CVE ID :CVE-2026-105105 Published : Oct. 3, 2026, 12:16 p.m. | 11 hours, 8 minutes ago Description :CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core…
CVE-2026-85515 – OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check
CVE ID :CVE-2026-85515 Published : Oct. 3, 2026, 9:17 a.m. | 14 hours, 8 minutes ago Description :In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error…
CVE-2026-105080 – ConvertX Arbitrary Code Execution
CVE ID :CVE-2026-105080 Published : Oct. 3, 2026, 12:39 a.m. | 43 minutes ago Description :In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program…
CVE-2026-104476 – Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive
CVE ID :CVE-2026-104476 Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 6 minutes ago Description :Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export…
CVE-2026-104433 – Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString
CVE ID :CVE-2026-104433 Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 6 minutes ago Description :Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that…