← Back to the live CVE advisory feed

CVE-2026-105292: Product identification pending

Severity
6 (MEDIUM)
Vendor
CHATERM BEFORE
Affected versions
Before 0.12.1
Fixed version
0.12.1
Patch status
Patched
Published
2026-10-05T01:16:28.630
Modified
2026-10-05T01:16:28.630

Why it matters

This matters because the issue affects identity or token handling. Successful exploitation could allow unauthorized authentication, client manipulation, or access to protected services.

Recommended admin actions

  • Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the victim into the attacker's account so default data sync uploads saved hosts, passwords, and private keys.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 05, 2026 04:00 AM UTC
110 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-105134
AhsayCBS PATCH
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-105135
MindSearch
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-103355
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-105207
zitadel PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-105209
zitadel PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-105215
zitadel PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-105086
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-105089
AVideo
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-105211
zitadel PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-105293
Legcord
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-105216
go-micro PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105218
gopay PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105221
gist PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105222
google-maps
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105223
kubernetes-client PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105294
Legcord
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-105210
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-105213
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-88779 EXPLOITED
ADC PATCH
Reporter: 50A63C94-1EA7-4568-8C11-EB79E7C5A2B5
8.7
HIGH
VIEW RECORD
CVE-2026-105208
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-105212
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-105219
mammoth.js PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-105220
twinejs
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-105295
GitAhead
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-97307
Cost Calculator Builder PATCH
Reporter: AUDIT
7.5
HIGH
VIEW RECORD
CVE-2026-103062
TranslatePress PATCH
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-103344
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-103354
Gutenberg Blocks by Kadence Blocks PATCH
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-97276
WP Statistics PATCH
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-105205
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-105161
aiir
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-105163
crossplane-runtime PATCH
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-105292
Product identification pending PATCH
Reporter: DISCLOSURE
6
MEDIUM
VIEW RECORD
CVE-2026-105133
AhsayCBS PATCH
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105144
Drogon
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105145
Verba
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105147
R2R
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105148
R2R
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105149
mooSocial
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105158
DocSys
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105166
food-waste-management-system
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105167
food-waste-management-system
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105169
food-waste-management-system
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105170
food-waste-management-system
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105172
Online Admission System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105175
Drug Recommendation System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105182
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105183
Online Admission System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105184
Online Admission System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-105141
cognee PATCH
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-105206
Product identification pending PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105165
secrets-replicator PATCH
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-105224
Product identification pending PATCH
Reporter: DISCLOSURE
5.1
MEDIUM
VIEW RECORD
CVE-2026-105164
cFS
Reporter: CNA
5.1
MEDIUM
VIEW RECORD
CVE-2026-104402
Mindio Magic MCP PATCH
Reporter: AUDIT
4.3
MEDIUM
VIEW RECORD
CVE-2026-105156
YzmCMS
Reporter: CNA
2.9
LOW
VIEW RECORD
CVE-2026-105214
Product identification pending PATCH
Reporter: DISCLOSURE
2.3
LOW
VIEW RECORD
CVE-2026-105217
Product identification pending PATCH
Reporter: DISCLOSURE
2.3
LOW
VIEW RECORD
CVE-2026-105098
CoinEx Crypto
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105157
DocSys
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105168
food-waste-management-system
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105171
food-waste-management-system
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105174
Gerapy
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105180
Jeebase
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105181
Online Admission System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105099
CoinEx Crypto
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105146
Discuz!
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105173
Human Resource Management
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105176
Drug Recommendation System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105177
Drug Recommendation System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105178
Drug Recommendation System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105179
Drug Recommendation System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-105137
Laradock
Reporter: CNA
1.3
LOW
VIEW RECORD
CVE-2026-104118
Razorpay for WooCommerce PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-104119
Simple Shopping Cart PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-17005
Horizontal scrolling announcements
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-86817
Five Star Business Profile and Schema PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-93549
CoCart PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-97332
User Private Files PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-20519
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20520
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20521
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20522
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20523
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20524
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20525
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20526
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20527
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20528
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20529
MediaTek chipset
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20530
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20531
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20532
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20533
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20534
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20535
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20536
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20537
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20538
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20539
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.