Common Vulnerabilities and Exposures (CVE)

CVE-2026-104119

Oct 4, 2026 06:00:23 UTC

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scr...

CVE-2026-104118

Oct 4, 2026 06:00:23 UTC

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrar...

CVE-2026-17005

Oct 4, 2026 06:00:22 UTC

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announce...

CVE-2026-105134

Oct 4, 2026 05:30:12 UTC

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os...

CVE-2026-105133

Oct 4, 2026 05:15:14 UTC

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in imprope...

CVE-2026-105099

Oct 4, 2026 03:30:16 UTC

A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scriptin...

CVE-2026-105098

Oct 4, 2026 02:45:13 UTC

A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in inform...

CVE-2026-88779

Oct 4, 2026 02:35:35 UTC

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

CVE-2026-105097

Oct 4, 2026 02:00:11 UTC

A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypa...

CVE-2026-105131

Oct 4, 2026 01:20:29 UTC

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, a...

CVE-2026-105096

Oct 4, 2026 00:45:15 UTC

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass...

CVE-2026-103111

Oct 3, 2026 23:51:52 UTC

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.

CVE-2026-100630

Oct 3, 2026 23:44:08 UTC

AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payl...

CVE-2026-105130

Oct 3, 2026 23:40:02 UTC

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registrati...

CVE-2026-105129

Oct 3, 2026 23:40:01 UTC

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/s...