| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-90235 | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE | Linux | Linux | Critical | 9.8 | 2026-09-17 16:07:41 | Deep Dive |
| CVE-2026-90230 | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() | Linux | Linux | Critical | 9.1 | 2026-09-17 16:07:38 | Deep Dive |
| CVE-2026-90173 | smb: smbdirect: free completion queues with ib_free_cq() | Linux | Linux | Critical | 9.8 | 2026-09-17 16:07:00 | Deep Dive |
| CVE-2026-90151 | NFSv4: remove callback IDR entry on client allocation failure | Linux | Linux | Critical | 9.8 | 2026-09-17 16:06:45 | Deep Dive |
| CVE-2026-90110 | inetpeer: randomize RB-tree node comparison using SipHash | Linux | Linux | Critical | 9.4 | 2026-09-17 16:06:18 | Deep Dive |
| CVE-2026-90104 | NFSv4.1: zero referring call lists before decoding | Linux | Linux | Critical | 9.8 | 2026-09-17 16:06:14 | Deep Dive |
| CVE-2026-86863 | pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode | pgadmin.org | pgAdmin 4 | Critical | 9.8 | 2026-09-17 15:30:58 | Deep Dive |
| CVE-2026-91039 | dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover | team-alembic | ash_authentication | Critical | 9.1 | 2026-09-17 15:19:16 | Deep Dive |
| CVE-2026-79752 | CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection | cakephp | cakephp | Critical | 9.2 | 2026-09-17 14:49:57 | Deep Dive |
| CVE-2026-63472 | Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification | vendurehq | vendure | Critical | 9.1 | 2026-09-17 14:40:31 | Deep Dive |
| CVE-2026-88952 | OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication | team-alembic | ash_authentication | Critical | 9.1 | 2026-09-17 14:15:20 | Deep Dive |
| CVE-2026-92960 | vm2 before 3.11.6 Process-wide State Exposure via os and dns | patriksimek | vm2 | Critical | 10.0 | 2026-09-17 13:46:17 | Deep Dive |
| CVE-2026-92957 | vm2 before 3.11.7 Authentication Bypass via node: Prefix | patriksimek | vm2 | Critical | 9.9 | 2026-09-17 13:46:15 | Deep Dive |
| CVE-2026-92956 | vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming | patriksimek | vm2 | Critical | 10.0 | 2026-09-17 13:46:14 | Deep Dive |
| CVE-2026-92955 | vm2 before 3.11.8 Sandbox Escape via NodeVM | patriksimek | vm2 | Critical | 10.0 | 2026-09-17 13:46:14 | Deep Dive |
| CVE-2026-92953 | vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray | patriksimek | vm2 | Critical | 10.0 | 2026-09-17 13:46:12 | Deep Dive |
| CVE-2026-92951 | vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver | patriksimek | vm2 | Critical | 9.9 | 2026-09-17 13:46:11 | Deep Dive |
| CVE-2026-92948 | vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test | patriksimek | vm2 | Critical | 9.9 | 2026-09-17 13:46:09 | Deep Dive |
| CVE-2026-92947 | vm2 before 3.11.7 Memory Disclosure via Buffer Pool | patriksimek | vm2 | Critical | 10.0 | 2026-09-17 13:46:08 | Deep Dive |
| CVE-2026-92946 | vm2 before 3.11.7 Remote Code Execution via require.external | patriksimek | vm2 | Critical | 10.0 | 2026-09-17 13:46:07 | Deep Dive |