MikeTrendsTrends right now

search

CVSS

Trends

  1. 1
    Critical CVSS 9.8 flaw reported in OAuth SSO pluginโ–ผ๐Ÿšจ CVE-2026-97274 โ€” CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On โ€“ SSO (OAuth Client) ๐Ÿ”ŽMmastodonTechnologyCybersecurity01 h ago

    A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On โ€“ SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.

  2. 2
    Critical unauthenticated PHP object injection flaw flagged in Booking Activitiesโ–ผ๐Ÿšจ CVE-2026-97248 โ€” CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities ๐Ÿ”Ž Details: https:// stemMmastodonTechnologyCybersecurity01 h ago

    Security researchers are warning about CVE-2026-97248, a critical vulnerability in the Booking Activities plugin rated 9.8 on the CVSS scale. The flaw is an unauthenticated PHP object injection issue, meaning remote attackers could potentially exploit it without any credentials. Details are being circulated in infosec communities as administrators are urged to check their installations and patch promptly.

  3. 3
    Critical unauthenticated SQL injection flaw reported in Books Galleryโ—๐Ÿšจ CVE-2026-96822 โ€” CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Books Gallery ๐Ÿ”Ž Details: https:// stemshop.top/cveMmastodonTechnologyCybersecurity01 h ago

    Security researchers have flagged CVE-2026-96822, a critical vulnerability in the Books Gallery application, rated CVSS 9.3. The flaw is described as an unauthenticated SQL injection, meaning attackers need no credentials to exploit it remotely. Details and mitigation guidance are being circulated on security channels, with administrators urged to patch or isolate affected deployments quickly.

  4. 4
    Themeum WordPress plugins flagged over 33 unpatched vulnerabilitiesโ–ผThemeum: 33 CVEs, max CVSS 10, and 100% unpatched. Trust score C. WordPress sites running these plugins carry real risk.MmastodonTechnologyCybersecurity13 h ago

    WordPress plugin developer Themeum is being flagged for 33 known CVEs with a maximum CVSS score of 10, all reportedly unpatched, earning the vendor a trust score of C. Security commentary warns that sites running its plugins carry real risk and urges administrators to review whether they depend on this software.

  5. 5
    Critical Citrix NetScaler flaw exploited in the wild since Septemberโ—๐Ÿค– CVE-2026-88772 (CVSS 9.5): DTLS memory overflow in Citrix NetScaler ADC/Gateway lets unauthenticated attackers reach sMmastodonTechnologyCybersecurity13 h ago

    A critical vulnerability, CVE-2026-88772 with a CVSS score of 9.5, has been disclosed in Citrix NetScaler ADC and Gateway products. The DTLS memory overflow allows unauthenticated attackers to achieve shellcode execution. According to Mandiant and Google Threat Intelligence, it has been actively exploited since September to gain root access and deploy the WHIPSHOT and SLAPSHOT malware. Administrators are urged to patch immediately.

  6. 6
    Critical flaw in Digiwin EasyFlow .NET exposes plaintext passwordsโ—๐Ÿšจ CVE-2026-102458 โ€” CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. UnaMmastodonTechnologyCybersecurity05 h ago

    A critical vulnerability, CVE-2026-102458 with a CVSS score of 9.3, has been disclosed in EasyFlow .NET, enterprise software developed by Taiwanese vendor Digiwin. The flaw is a missing authentication issue: unauthenticated remote attackers can use a specific API to obtain other users' plaintext passwords. Security watchers are sharing details and urging affected organisations to review exposure and patch quickly.

  7. 7
    Critical insecure deserialization flaw reported in Digiwin EasyFlow .NETโ—๐Ÿšจ CVE-2026-102455 โ€” CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. UMmastodonTechnologyCybersecurity05 h ago

    A critical vulnerability, tracked as CVE-2026-102455 with a CVSS score of 9.3, has been reported in EasyFlow .NET, software developed by Taiwanese vendor Digiwin. According to the advisory, unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content, exploiting insecure deserialization. Organizations running the software are being urged to review the details and apply fixes promptly.

  8. 8
    Critical Apache PLC4X vulnerability CVE-2026-102508 disclosedโ—๐Ÿšจ CVE-2026-102508 โ€” CVSS 9.2 CRITICAL Improper Verification of Cryptographic Signature and Improper Certificate ValidatiMmastodonTechnologyCybersecurity05 h ago

    A critical vulnerability, CVE-2026-102508 with a CVSS score of 9.2, has been disclosed in the OPC UA driver of Apache PLC4X (PLC4J). The flaw involves improper cryptographic signature verification and certificate validation, allowing a network attacker positioned between client and server to impersonate the OPC UA server. Security watchers are urging industrial users of the library to patch promptly.