Security Box Score — October 5, 2026 — page 2
Edition of October 5, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-88394 | await | — | n/a | n/a | — | WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The projec… |
| CVE-2026-88396 | await | — | n/a | n/a | — | ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file… |
| CVE-2026-88397 | await | — | n/a | n/a | — | ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list end… |
| CVE-2026-88424 | await | — | n/a | n/a | — | FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via th… |
| CVE-2026-95165 | await | — | n/a | n/a | — | Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Or… |
| CVE-2026-95166 | await | — | n/a | n/a | — | In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field all… |
| CVE-2026-95263 | await | — | n/a | n/a | — | Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege ba… |
| CVE-2026-95264 | await | — | n/a | n/a | — | Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backen… |
| CVE-2026-95265 | await | — | n/a | n/a | — | Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability i… |
| CVE-2026-104711 | await | — | Apache Software Foundation | Apache Struts | CWE-917 | Apache Struts: OGNL injection in the legacy RESTful action mapper |
| CVE-2026-104712 | await | — | Apache Software Foundation | Apache Struts | CWE-405 | Apache Struts: Disproportionate response size when rendering BigDecimal reque… |
| CVE-2026-104713 | await | — | Apache Software Foundation | Apache Struts | CWE-770 | Apache Struts: Unbounded request body read in the REST plugin |
| CVE-2026-104714 | await | — | Apache Software Foundation | Apache Struts | CWE-362 | Apache Struts: Shared message formatter exposes date and time values across c… |