boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, October 5, 2026 · all times UTC← 2026-10-04 · archive

Security Box Score — October 5, 2026 — page 2

Edition of October 5, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–413 of 413
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-88394await—n/an/a—WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The projec…
CVE-2026-88396await—n/an/a—ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file…
CVE-2026-88397await—n/an/a—ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list end…
CVE-2026-88424await—n/an/a—FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via th…
CVE-2026-95165await—n/an/a—Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Or…
CVE-2026-95166await—n/an/a—In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field all…
CVE-2026-95263await—n/an/a—Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege ba…
CVE-2026-95264await—n/an/a—Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backen…
CVE-2026-95265await—n/an/a—Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability i…
CVE-2026-104711await—Apache Software FoundationApache StrutsCWE-917Apache Struts: OGNL injection in the legacy RESTful action mapper
CVE-2026-104712await—Apache Software FoundationApache StrutsCWE-405Apache Struts: Disproportionate response size when rendering BigDecimal reque…
CVE-2026-104713await—Apache Software FoundationApache StrutsCWE-770Apache Struts: Unbounded request body read in the REST plugin
CVE-2026-104714await—Apache Software FoundationApache StrutsCWE-362Apache Struts: Shared message formatter exposes date and time values across c…