Common Vulnerabilities and Exposures (CVE)

CVE-2026-104398

Oct 10, 2026 17:00:10 UTC

Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a throug...

CVE-2026-105889

Oct 10, 2026 17:00:10 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.

CVE-2026-103071

Oct 10, 2026 17:00:10 UTC

Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce...

CVE-2026-103357

Oct 10, 2026 17:00:10 UTC

Missing Authorization vulnerability in VillaTheme GIFT4U gift4u-gift-cards-all-in-one-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GIFT4U: from n/a through 1.1.3.

CVE-2026-106608

Oct 10, 2026 17:00:10 UTC

Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.

CVE-2026-106609

Oct 10, 2026 17:00:10 UTC

Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.

CVE-2026-94160

Oct 10, 2026 17:00:09 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeStek ThemeStek Extras for LabtechCO Theme themestek-labtechco-extras allows Reflected XSS.This issue affects ThemeStek Extras for Lab...

CVE-2026-62044

Oct 10, 2026 17:00:09 UTC

Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.

CVE-2026-108586

Oct 10, 2026 16:14:10 UTC

1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a sing...

CVE-2026-108585

Oct 10, 2026 16:14:09 UTC

argocd-mcp (Argo CD MCP Server) through 0.9.0 contains a path traversal vulnerability in the delete_application tool that allows MCP clients to reach unintended API endpoints via unvalidated applicationName values. Attackers or prompt-injec...

CVE-2025-8787

Oct 10, 2026 15:59:23 UTC

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /registros-de-conteudos-por-disciplina/ of the component Registro das atividades. The manipulation of the argume...

CVE-2025-8786

Oct 10, 2026 15:58:03 UTC

A vulnerability was identified in Portabilis i-Diario up to 1.5.0. Impacted is an unknown function of the file /registros-de-conteudos-por-areas-de-conhecimento/ of the component Registro das atividades. The manipulation of the argument Reg...

CVE-2026-108583

Oct 10, 2026 15:57:51 UTC

zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the age...

CVE-2026-108582

Oct 10, 2026 15:57:50 UTC

GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-...

CVE-2026-108581

Oct 10, 2026 15:57:49 UTC

TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/voice/providers. Attackers can query these...