search
CVSS
Trends
- 1Critical CVSS 9.8 flaw reported in OAuth SSO pluginโผ๐จ CVE-2026-97274 โ CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On โ SSO (OAuth Client) ๐
A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On โ SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.
- 2Critical unauthenticated PHP object injection flaw flagged in Booking Activitiesโผ๐จ CVE-2026-97248 โ CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities ๐ Details: https:// stem
Security researchers are warning about CVE-2026-97248, a critical vulnerability in the Booking Activities plugin rated 9.8 on the CVSS scale. The flaw is an unauthenticated PHP object injection issue, meaning remote attackers could potentially exploit it without any credentials. Details are being circulated in infosec communities as administrators are urged to check their installations and patch promptly.
- 3Critical unauthenticated SQL injection flaw reported in Books Galleryโ๐จ CVE-2026-96822 โ CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Books Gallery ๐ Details: https:// stemshop.top/cve
Security researchers have flagged CVE-2026-96822, a critical vulnerability in the Books Gallery application, rated CVSS 9.3. The flaw is described as an unauthenticated SQL injection, meaning attackers need no credentials to exploit it remotely. Details and mitigation guidance are being circulated on security channels, with administrators urged to patch or isolate affected deployments quickly.
- 4Themeum WordPress plugins flagged over 33 unpatched vulnerabilitiesโผThemeum: 33 CVEs, max CVSS 10, and 100% unpatched. Trust score C. WordPress sites running these plugins carry real risk.
WordPress plugin developer Themeum is being flagged for 33 known CVEs with a maximum CVSS score of 10, all reportedly unpatched, earning the vendor a trust score of C. Security commentary warns that sites running its plugins carry real risk and urges administrators to review whether they depend on this software.
- 5Critical Citrix NetScaler flaw exploited in the wild since Septemberโ๐ค CVE-2026-88772 (CVSS 9.5): DTLS memory overflow in Citrix NetScaler ADC/Gateway lets unauthenticated attackers reach s
A critical vulnerability, CVE-2026-88772 with a CVSS score of 9.5, has been disclosed in Citrix NetScaler ADC and Gateway products. The DTLS memory overflow allows unauthenticated attackers to achieve shellcode execution. According to Mandiant and Google Threat Intelligence, it has been actively exploited since September to gain root access and deploy the WHIPSHOT and SLAPSHOT malware. Administrators are urged to patch immediately.
- 6Critical flaw in Digiwin EasyFlow .NET exposes plaintext passwordsโ๐จ CVE-2026-102458 โ CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Una
A critical vulnerability, CVE-2026-102458 with a CVSS score of 9.3, has been disclosed in EasyFlow .NET, enterprise software developed by Taiwanese vendor Digiwin. The flaw is a missing authentication issue: unauthenticated remote attackers can use a specific API to obtain other users' plaintext passwords. Security watchers are sharing details and urging affected organisations to review exposure and patch quickly.
- 7Critical insecure deserialization flaw reported in Digiwin EasyFlow .NETโ๐จ CVE-2026-102455 โ CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. U
A critical vulnerability, tracked as CVE-2026-102455 with a CVSS score of 9.3, has been reported in EasyFlow .NET, software developed by Taiwanese vendor Digiwin. According to the advisory, unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content, exploiting insecure deserialization. Organizations running the software are being urged to review the details and apply fixes promptly.
- 8Critical Apache PLC4X vulnerability CVE-2026-102508 disclosedโ๐จ CVE-2026-102508 โ CVSS 9.2 CRITICAL Improper Verification of Cryptographic Signature and Improper Certificate Validati
A critical vulnerability, CVE-2026-102508 with a CVSS score of 9.2, has been disclosed in the OPC UA driver of Apache PLC4X (PLC4J). The flaw involves improper cryptographic signature verification and certificate validation, allowing a network attacker positioned between client and server to impersonate the OPC UA server. Security watchers are urging industrial users of the library to patch promptly.