Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-66331 |
6.9 (4.0)
|
Apache Thrift: Buffered transport reads are not accoun… |
Apache Software Foundation |
Apache Thrift |
2026-10-02T12:32:46.166Z | 2026-10-03T15:52:56.858Z |
| CVE-2026-66055 |
8.2 (4.0)
|
Apache Thrift, Apache Thrift, Apache Thrift, Apache Th… |
Apache Software Foundation |
Apache Thrift |
2026-10-02T12:49:40.955Z | 2026-10-03T15:52:56.729Z |
| CVE-2026-63772 |
8.7 (4.0)
|
Apache Thrift: Unauthenticated single-packet crash of … |
Apache Software Foundation |
Apache Thrift |
2026-10-02T12:52:07.427Z | 2026-10-03T15:52:56.607Z |
| CVE-2026-61374 |
7.1 (4.0)
|
Apache Thrift: Java TSaslTransport post-auth data-fram… |
Apache Software Foundation |
Apache Thrift |
2026-10-02T12:53:00.477Z | 2026-10-03T15:52:56.479Z |
| CVE-2026-66054 |
6.9 (4.0)
|
Apache Thrift: C++ THeaderTransport does not enforce c… |
Apache Software Foundation |
Apache Thrift |
2026-10-02T12:58:05.610Z | 2026-10-03T15:52:56.354Z |
| CVE-2026-101104 |
6.3 (4.0)
7.7 (3.1)
|
Missing Authorization in Meari IoT Cloud Platform Open… |
Meari |
IoT Cloud Platform OpenAPI Service |
2026-10-02T15:58:21.626Z | 2026-10-03T15:52:56.225Z |
| CVE-2026-104910 |
5.3 (4.0)
|
MISP Information Disclosure via Related Events Listing… |
MISP |
MISP |
2026-10-02T16:01:32.781Z | 2026-10-03T15:52:56.095Z |
| CVE-2026-96613 |
7.1 (4.0)
6.5 (3.1)
|
Missing Authorization in Meari IoT Cloud Platform Open… |
Meari |
IoT Cloud Platform OpenAPI Service |
2026-10-02T16:03:04.281Z | 2026-10-03T15:52:55.965Z |
| CVE-2026-104912 |
7.1 (4.0)
|
MISP Correlation Authorization Bypass Exposes Restrict… |
MISP |
MISP |
2026-10-02T16:04:50.580Z | 2026-10-03T15:52:55.841Z |
| CVE-2026-103648 |
9.1 (3.1)
|
Improper Limitation of a Pathname to a Restricted Dire… |
demsking |
image-downloader |
2026-10-02T16:05:25.331Z | 2026-10-03T15:52:55.709Z |
| CVE-2026-12392 |
5.3 (3.1)
|
RPC secret disclosure via vendor data endpoint in Cano… |
Canonical |
MAAS |
2026-10-02T19:24:09.110Z | 2026-10-03T15:52:55.367Z |
| CVE-2026-75937 |
9.4 (4.0)
|
OS Command Injection in Digi Accelerated Linux (DAL OS) |
Digi International |
IX Family |
2026-10-02T20:33:56.823Z | 2026-10-03T15:52:55.213Z |
| CVE-2026-104055 |
5.3 (4.0)
|
Monitoring-user password logged in cleartext by postgr… |
Canonical |
postgresql-operator |
2026-10-02T20:35:50.514Z | 2026-10-03T15:52:55.087Z |
| CVE-2026-93474 |
6.5 (3.1)
6.9 (4.0)
|
Monta monta.app Insufficiently Protected Credentials |
Monta |
monta.app |
2026-10-02T21:27:59.493Z | 2026-10-03T15:52:54.945Z |
| CVE-2026-97212 |
7.3 (3.1)
6.9 (4.0)
|
Monta monta.app Insufficient Session Expiration |
Monta |
monta.app |
2026-10-02T21:30:37.104Z | 2026-10-03T15:52:54.811Z |
| CVE-2026-97363 |
7.5 (3.1)
8.7 (4.0)
|
Monta monta.app Improper Restriction of Excessive Auth… |
Monta |
monta.app |
2026-10-02T21:32:30.615Z | 2026-10-03T15:52:54.687Z |
| CVE-2026-95102 |
9.4 (3.1)
9.3 (4.0)
|
Monta monta.app Missing Authentication for Critical Function |
Monta |
monta.app |
2026-10-02T21:34:37.182Z | 2026-10-03T15:52:54.557Z |
| CVE-2026-94594 |
4 (3.1)
5.1 (4.0)
|
Armatura LLC Armatura One Insertion of Sensitive Infor… |
Armatura LLC |
Armatura One |
2026-10-02T21:48:14.765Z | 2026-10-03T15:52:54.425Z |
| CVE-2026-94593 |
7.8 (3.1)
8.5 (4.0)
|
Armatura LLC Armatura One Insertion of Sensitive Infor… |
Armatura LLC |
Armatura One |
2026-10-02T21:51:00.902Z | 2026-10-03T15:52:54.296Z |
| CVE-2026-94592 |
8.4 (3.1)
8.6 (4.0)
|
Armatura LLC Armatura One Use of Hard-coded Credentials |
Armatura LLC |
Armatura One |
2026-10-02T21:52:54.438Z | 2026-10-03T15:52:54.168Z |
| CVE-2026-94591 |
8.4 (3.1)
8.6 (4.0)
|
Armatura LLC Armatura One Use of Hard-coded Cryptograp… |
Armatura LLC |
Armatura One |
2026-10-02T21:54:42.665Z | 2026-10-03T15:52:54.018Z |
| CVE-2026-84411 |
9.8 (3.1)
9.3 (4.0)
|
MikroTik RouterOS Integer Underflow |
MikroTik |
RouterOS |
2026-10-02T22:09:48.298Z | 2026-10-03T15:52:53.879Z |
| CVE-2026-105105 |
9.8 (3.1)
|
Unauthenticated ZeroMQ command/telemetry bus in AIT-Co… |
NASA-AMMOS |
AIT-Core |
2026-10-03T11:55:44.853Z | 2026-10-03T15:52:53.747Z |
| CVE-2026-92245 |
7.5 (3.1)
|
Simply Schedule Appointments <= 1.6.12.32 - Missing Au… |
croixhaug |
Simply Schedule Appointments |
2026-10-01T03:28:21.953Z | 2026-10-03T15:42:53.270Z |
| CVE-2026-91109 |
6.5 (3.1)
|
Simply Schedule Appointments <= 1.6.12.31 - Insecure D… |
croixhaug |
Simply Schedule Appointments |
2026-10-01T03:28:22.807Z | 2026-10-03T15:42:53.139Z |
| CVE-2026-92548 |
5.3 (3.1)
|
WP Popular Posts <= 7.4.2 - Unauthenticated Informatio… |
hcabrera |
WP Popular Posts |
2026-10-01T04:27:33.328Z | 2026-10-03T15:42:52.997Z |
| CVE-2026-12241 |
5.4 (3.1)
|
Advanced Woo Labels – Product Labels & Badges for WooC… |
mihail-barinov |
Advanced Woo Labels – Product Labels & Badges for WooCommerce |
2026-10-01T04:27:33.782Z | 2026-10-03T15:42:52.868Z |
| CVE-2026-85679 |
7.2 (3.1)
|
Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site… |
extendify |
Extendify |
2026-10-01T05:30:55.047Z | 2026-10-03T15:42:52.738Z |
| CVE-2026-88999 |
4.3 (3.1)
|
Redux Framework <= 4.5.14 - Missing Authorization to A… |
davidanderson |
Redux Framework |
2026-10-01T05:30:55.556Z | 2026-10-03T15:42:52.610Z |
| CVE-2026-89047 |
6.1 (3.1)
|
Social Media Share Buttons & Social Sharing Icons <= 3… |
inisev |
Social Media Share Buttons & Social Sharing Icons |
2026-10-01T07:40:22.379Z | 2026-10-03T15:42:52.484Z |