Common Vulnerabilities and Exposures (CVE)

CVE-2026-63277

Oct 5, 2026 11:17:20 UTC

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Ja...

CVE-2026-105307

Oct 5, 2026 11:15:11 UTC

A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be init...

CVE-2026-105396

Oct 5, 2026 11:09:45 UTC

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workf...

CVE-2025-53345

Oct 5, 2026 11:03:05 UTC

Missing Authorization vulnerability in ThimPress Thim Core thim-core.This issue affects Thim Core: from n/a through 2.3.3.

CVE-2026-105291

Oct 5, 2026 11:00:21 UTC

A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. ...

CVE-2026-17005

Oct 5, 2026 10:53:49 UTC

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announce...

CVE-2026-104118

Oct 5, 2026 10:53:49 UTC

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrar...

CVE-2026-104119

Oct 5, 2026 10:53:49 UTC

The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scr...

CVE-2026-86817

Oct 5, 2026 10:53:49 UTC

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input tha...

CVE-2026-93549

Oct 5, 2026 10:53:49 UTC

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request fo...

CVE-2026-97332

Oct 5, 2026 10:53:49 UTC

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allow...

CVE-2026-84169

Oct 5, 2026 10:53:48 UTC

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary orde...

CVE-2026-13607

Oct 5, 2026 10:53:48 UTC

The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who k...

CVE-2026-78371

Oct 5, 2026 10:53:48 UTC

The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to ...

CVE-2026-20586

Oct 5, 2026 10:53:48 UTC

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS113...