Common Vulnerabilities and Exposures (CVE)

CVE-2026-82806

Oct 1, 2026 10:58:32 UTC

Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into la...

CVE-2026-78242

Oct 1, 2026 10:58:13 UTC

Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure.  This issue affects Apache APISI...

CVE-2023-1989

Oct 1, 2026 10:58:00 UTC

A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices.

CVE-2026-101147

Oct 1, 2026 10:55:59 UTC

The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL...

CVE-2026-101148

Oct 1, 2026 10:55:59 UTC

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, i...

CVE-2026-19253

Oct 1, 2026 10:55:59 UTC

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated use...

CVE-2026-81739

Oct 1, 2026 10:55:59 UTC

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is e...

CVE-2026-88789

Oct 1, 2026 10:51:22 UTC

Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplie...

CVE-2026-100823

Oct 1, 2026 10:50:23 UTC

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.

CVE-2025-6170

Oct 1, 2026 10:49:18 UTC

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue m...

CVE-2026-103353

Oct 1, 2026 10:48:43 UTC

Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.

CVE-2026-81809

Oct 1, 2026 10:45:49 UTC

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled with...

CVE-2026-86610

Oct 1, 2026 10:45:49 UTC

The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripti...

CVE-2026-87970

Oct 1, 2026 10:45:49 UTC

The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the br...

CVE-2026-87973

Oct 1, 2026 10:45:49 UTC

The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in t...