VulnSea

Weekly digest · in progress

Week 41, 2026 (5–11 Oct)

A quiet week: only 13 new CVEs against a recent average of about 2,492 so far. Severity skewed high: 8 high, 62% of the total. kishor-23 was the most-affected vendor with 4.

13
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2026-105293High· 8.1
today

Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, su…

▾ TwilightLegcord · Legcordvia CVEORG
CVE-2026-105295High· 7.5
today

GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting a…

▾ Twilightgitahead · GitAheadvia CVEORG
CVE-2026-105294High· 7.4
today

Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set addi…

▾ TwilightLegcord · Legcordvia CVEORG
CVE-2026-105223High· 7.4
today

maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers c…

▾ Twilightmaclof · kubernetes-clientvia CVEORG
CVE-2026-105175High· 7.3
today

SourceCodester Drug Recommendation System Student Registration add_student.php sql injection

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool re…

▾ TwilightSourceCodester · Drug Recommendation Systemvia CVEORG
CVE-2026-105172High· 7.3
today

itsourcecode Online Admission System login1.php sql injection

A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack m…

▾ Twilightitsourcecode · Online Admission Systemvia CVEORG
CVE-2026-105170High· 7.3
today

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Adm…

▾ Twilightkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105169High· 7.3
today

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the co…

▾ Twilightkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105171Medium· 6.3
today

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the fil…

▾ Sunlitkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105168Medium· 6.3
today

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Ord…

▾ Sunlitkishor-23 · food-waste-management-systemvia NVD
CVE-2026-105292Medium· 5.9
today

Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback w…

▾ Sunlitchaterm · Chatermvia CVEORG
CVE-2026-105174Medium· 5.4
today

Gerapy Project Management views.py project_create path traversal

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name lead…

▾ Sunlitvia CVEORG

Most-affected vendors

By CVEs published in the period.