CVE Find is a real-time vulnerability database indexing 404 200 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3149 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-108540 |
2026-10-11 07h17 +00:00 |
A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the fi... Command InjectionOS Command Injection |
9.9 |
Critical |
|
CVE-2026-108707 |
2026-10-11 02h16 +00:00 |
Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect tha... Authorization problems |
9.8 |
Critical |
|
CVE-2026-108708 |
2026-10-11 01h12 +00:00 |
Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAsp... Authorization problems |
8.7 |
High |
|
CVE-2026-81797 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 ... |
9.8 |
Critical |
|
CVE-2026-78535 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.... |
9.8 |
Critical |
|
CVE-2026-78533 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.... |
9.8 |
Critical |
|
CVE-2026-78531 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.... |
9.8 |
Critical |
|
CVE-2026-78529 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.... |
9.8 |
Critical |
|
CVE-2026-66569 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.... |
9.8 |
Critical |
|
CVE-2026-66568 |
2026-10-10 20h16 +00:00 |
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.... |
9.8 |
Critical |