Threats
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 6.7 medium | CVE-2026-25270 | Qualcomm, Inc. Snapdragon Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. | — | 6 Oct 2026 |
| 6.7 medium | CVE-2026-25269 | Qualcomm, Inc. Snapdragon Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | — | 6 Oct 2026 |
| 7.8 high | CVE-2026-25267 | Qualcomm, Inc. Snapdragon Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | — | 6 Oct 2026 |
| 6.6 medium | CVE-2026-25263 | Qualcomm, Inc. Snapdragon Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | — | 6 Oct 2026 |
| 8.6 high | CVE-2026-105778 | Tenda AC5 A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | — | 6 Oct 2026 |
| 5.5 medium | CVE-2026-105776 | bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 8.8 high | CVE-2026-105701 | Mauro Cassani ACPT (Premium) The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. The exploit requires the attacker to first create a form with malicious email_settings via the REST API endpoint, then trigger form submission to execute the injected Twig expressions. | — | 6 Oct 2026 |
| 6.5 medium | CVE-2026-97300 | Arraytics WP Event Solution Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | — | 6 Oct 2026 |
| 7.2 high | CVE-2026-75962 | saadiqbal Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-41563 | Dawer Drew Sitemovr Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-41558 | WP Synchro WP Migration Plugin DB & Files – WP Synchro Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-39789 | WP Manage Ninja Fluent Affiliate Pro Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | — | 6 Oct 2026 |
| 7.1 high | CVE-2026-39760 | Creative interactive media Real 3D FlipBook Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-39723 | Green Invoice Morning for WooCommerce Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. | — | 6 Oct 2026 |
| 4.3 medium | CVE-2026-39599 | wallstrdev WDS MCP Content Manager Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | — | 6 Oct 2026 |
| 6.5 medium | CVE-2026-32582 | iatoai IATO MCP Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. | — | 6 Oct 2026 |
| 6.5 medium | CVE-2026-32576 | ZWEISCHNEIDER Faktur Pro for WooCommerce Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions. | — | 6 Oct 2026 |
| 2.1 low | CVE-2026-105775 | vllm-project vLLM A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 2.1 low | CVE-2026-105708 | imgproxy A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | — | 6 Oct 2026 |
| 7.5 high | CVE-2026-105072 | WP Manage Ninja FluentBooking Pro Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | — | 6 Oct 2026 |