Daily digest · in progress
Tuesday 6 October 2026
A quiet day: only 29 new CVEs against a recent average of about 385 so far. Of those, 2 critical and 6 high. Red Hat was the most-affected vendor with 15.
New this day, ranked by depth score
The 12 that matter most of the 29 published.
CVE-2026-105484Critical· 10.0TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of t…
CVE-2026-105763Critical· 9.6Twenty is an open-source CRM (customer relationship management) platform
Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a wor…
CVE-2026-105786High· 8.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, appli…
CVE-2026-105762High· 8.3Dify is an open-source LLM app development platform
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify ser…
CVE-2026-105783High· 8.0Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServe…
CVE-2026-105764High· 7.7Immich is a high-performance self-hosted photo and video management solution
Immich is a high-performance self-hosted photo and video management solution. Prior to 3.2.4, an authenticated non-admin user could upload SVG files that thumbnail-generation code in server/src/repositories/media.repository.ts passed to …
CVE-2026-105782High· 7.5Scrapy is a high-level web crawling and scraping framework for Python
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path …
CVE-2026-105471High· 7.3A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipu…
CVE-2026-92821Medium· 6.8A flaw was found in SSSD
A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early…
CVE-2026-105472Medium· 6.3A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5
A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manip…
CVE-2026-104044Medium· 6.2Sssd: sssd: denial of service via crafted passkey kerberos authentication request
A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check…
CVE-2026-104038Medium· 5.9A flaw was found in sssd
A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, t…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2014-6407Arbitrary Code Execution in Dockercvss41
- CVE-2026-51881deeptutor 1.4.0 contains code injection in ExecTool.executeseverity, cvss, exploit_available66
- CVE-2026-51886langflow-ai langflow v1.9.3 is affected by: Code Injectionexploit_available, severity, cvss66
- CVE-2026-51876DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flowseverity, cvss, exploit_available62
- CVE-2025-71348picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methodsexploit_available45
- CVE-2021-31624Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.exploit_available61
- CVE-2020-23546IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting a…exploit_available55
Most-affected vendors
By CVEs published in the period.