Threats
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 5.5 medium | CVE-2026-105392 | Lybbn Django-Vue-Lyadmin A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." | — | 5 Oct 2026 |
| 2.1 low | CVE-2026-105389 | feelec-yishu feelcrm-os A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | — | 5 Oct 2026 |
| 2.1 low | CVE-2026-105388 | feelec-yishu feelcrm-os A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | — | 5 Oct 2026 |
| 5.5 medium | CVE-2026-104030 | Red Hat Enterprise Linux 10 A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting authentication services. | — | 5 Oct 2026 |
| 3.3 low | CVE-2026-104029 | Red Hat Enterprise Linux 10 A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to crash, resulting in a denial of service (DoS). | — | 5 Oct 2026 |
| 7.2 high | CVE-2026-103348 | Smackcoders Inc. WP Ultimate Exporter Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0. | — | 5 Oct 2026 |
| 6.5 medium | CVE-2026-103337 | Kirillbdev WC Ukraine Shipping Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2. | — | 5 Oct 2026 |
| 8.5 high | CVE-2026-103066 | WP BASE Booking Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | — | 5 Oct 2026 |
| 8.8 high | CVE-2026-100511 | Vektor Inc. VK Google Job Posting Manager Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1. | — | 5 Oct 2026 |
| 7.2 high | CVE-2026-100506 | WP Spell Check Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1. | — | 5 Oct 2026 |
| 7.1 high | CVE-2026-97309 | Webful Creations RepairBuddy Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226. | — | 5 Oct 2026 |
| 6.9 medium | CVE-2026-97305 | Themeisle AI Chatbot for WordPress – Hyve Lite Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 2.0.2. | — | 5 Oct 2026 |
| 6.5 medium | CVE-2026-97304 | Arraytics Timetics Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63. | — | 5 Oct 2026 |
| 7.6 high | CVE-2026-97303 | Apps Mav Scratch & Win – Giveaways and Contests Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2. | — | 5 Oct 2026 |
| 9.8 critical | CVE-2026-97283 | Liquid Web / StellarWP Advanced Post Manager Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5. | — | 5 Oct 2026 |
| 5.3 medium | CVE-2026-97275 | VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | — | 5 Oct 2026 |
| 6.9 medium | CVE-2026-97070 | CozyThemes Cozy Blocks Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23. | — | 5 Oct 2026 |
| — unscored | CVE-2026-95166 | In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload. | — | 5 Oct 2026 |
| — unscored | CVE-2026-95165 | Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field. | — | 5 Oct 2026 |
| — unscored | CVE-2026-88424 | FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | — | 5 Oct 2026 |