Common Vulnerabilities and Exposures (CVE)

CVE-2026-105775

Oct 6, 2026 05:45:11 UTC

A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipula...

CVE-2026-7700

Oct 6, 2026 05:35:31 UTC

A weakness has been identified in langflow-ai langflow up to 1.10.2. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.py of the component LambdaFilterComponent. Executing a manipulation can ...

CVE-2026-75962

Oct 6, 2026 05:30:46 UTC

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and in...

CVE-2026-105708

Oct 6, 2026 05:15:15 UTC

A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is ...

CVE-2026-97300

Oct 6, 2026 05:14:51 UTC

Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.

CVE-2026-41563

Oct 6, 2026 05:14:51 UTC

Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.

CVE-2026-41558

Oct 6, 2026 05:14:50 UTC

Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.

CVE-2026-39789

Oct 6, 2026 05:14:49 UTC

Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.

CVE-2026-39760

Oct 6, 2026 05:14:49 UTC

Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.

CVE-2026-39723

Oct 6, 2026 05:14:48 UTC

Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.

CVE-2026-39599

Oct 6, 2026 05:14:47 UTC

Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.

CVE-2026-32582

Oct 6, 2026 05:14:46 UTC

Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.

CVE-2026-32576

Oct 6, 2026 05:14:45 UTC

Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.

CVE-2026-105072

Oct 6, 2026 05:14:44 UTC

Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.

CVE-2026-104380

Oct 6, 2026 05:07:59 UTC

Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and...