CVE ID :CVE-2026-105293 Published : Oct. 5, 2026, 12:44 a.m. | 43 minutes ago Description :Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the…
CVE-2026-105222 – alexpechkarev/google-maps through 12.16 Disabled TLS Certificate Verification via ssl_verify_peer
CVE ID :CVE-2026-105222 Published : Oct. 4, 2026, 11:16 p.m. | 2 hours, 11 minutes ago Description :The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets…
CVE-2026-105221 – Gist RubyGem before 6.1.0 Disabled TLS Certificate Verification
CVE ID :CVE-2026-105221 Published : Oct. 4, 2026, 11:16 p.m. | 2 hours, 11 minutes ago Description :The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept…
CVE-2026-105220 – Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files
CVE ID :CVE-2026-105220 Published : Oct. 4, 2026, 11:16 p.m. | 2 hours, 11 minutes ago Description :Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported…
CVE-2026-105219 – Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser
CVE ID :CVE-2026-105219 Published : Oct. 4, 2026, 6:16 p.m. | 5 hours, 11 minutes ago Description :Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser…
CVE-2026-105218 – gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client
CVE ID :CVE-2026-105218 Published : Oct. 4, 2026, 6:16 p.m. | 5 hours, 11 minutes ago Description :gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment…
CVE-2026-105216 – go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper
CVE ID :CVE-2026-105216 Published : Oct. 4, 2026, 6:16 p.m. | 5 hours, 11 minutes ago Description :go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because…
CVE-2026-105089 – WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates
CVE ID :CVE-2026-105089 Published : Oct. 4, 2026, 4:16 p.m. | 7 hours, 11 minutes ago Description :WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to…
CVE-2026-105086 – WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
CVE ID :CVE-2026-105086 Published : Oct. 4, 2026, 4:16 p.m. | 7 hours, 11 minutes ago Description :WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject…
CVE-2026-105126 – LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
CVE ID :CVE-2026-105126 Published : Oct. 4, 2026, 12:16 a.m. | 1 hour, 9 minutes ago Description :LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to…