Daily High-Risk Vuln Digest 2026-10-06 (3)
Daily High-Risk Vulnerability Digest · 2026-10-06
3 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-105641 —
9.8— Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that r… - CVE-2026-105638 —
9.1— Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and… - CVE-2026-105640 —
9.1— Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying t…
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.