VulnSea

Daily digest · in progress

Monday 5 October 2026

A quiet day: only 13 new CVEs against a recent average of about 352 so far. Severity skewed high: 8 high, 62% of the total. kishor-23 was the most-affected vendor with 4.

13
New CVEs
0
Critical
0
KEV additions
5
Records changed

New this day, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2026-105293High· 8.1
today

Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, su…

▾ TwilightLegcord · Legcordvia CVEORG
CVE-2026-105295High· 7.5
today

GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting a…

▾ Twilightgitahead · GitAheadvia CVEORG
CVE-2026-105294High· 7.4
today

Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set addi…

▾ TwilightLegcord · Legcordvia CVEORG
CVE-2026-105223High· 7.4
today

maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers c…

▾ Twilightmaclof · kubernetes-clientvia CVEORG
CVE-2026-105175High· 7.3
today

SourceCodester Drug Recommendation System Student Registration add_student.php sql injection

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool re…

▾ TwilightSourceCodester · Drug Recommendation Systemvia CVEORG
CVE-2026-105172High· 7.3
today

itsourcecode Online Admission System login1.php sql injection

A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack m…

▾ Twilightitsourcecode · Online Admission Systemvia CVEORG
CVE-2026-105170High· 7.3
today

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Adm…

▾ Twilightkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105169High· 7.3
today

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the co…

▾ Twilightkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105171Medium· 6.3
today

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the fil…

▾ Sunlitkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105168Medium· 6.3
today

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Ord…

▾ Sunlitkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105292Medium· 5.9
today

Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback w…

▾ Sunlitchaterm · Chatermvia CVEORG
CVE-2026-105174Medium· 5.4
today

Gerapy Project Management views.py project_create path traversal

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name lead…

▾ Sunlitvia CVEORG

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2026-92084The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.562
  • CVE-2026-96451Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.60
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45

Most-affected vendors

By CVEs published in the period.