| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102807 | OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket | OpenClaw | OpenClaw | Medium | 5.3 | 2026-09-29 17:22:40 | Deep Dive |
| CVE-2026-102806 | OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines | OpenClaw | OpenClaw | Medium | 6.3 | 2026-09-29 17:22:40 | Deep Dive |
| CVE-2026-102560 | Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth | Red Hat | Red Hat Enterprise Linux 10 | High | 8.6 | 2026-09-29 17:15:36 | Deep Dive |
| CVE-2026-102559 | Libsoup: libsoup: heap buffer overflow during websocket client-frame masking | Red Hat | Red Hat Enterprise Linux 10 | High | 8.6 | 2026-09-29 17:15:34 | Deep Dive |
| CVE-2026-102558 | Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth | Red Hat | Red Hat Enterprise Linux 10 | High | 8.6 | 2026-09-29 17:15:32 | Deep Dive |
| CVE-2026-102555 | Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding | Red Hat | Red Hat Enterprise Linux 10 | High | 8.2 | 2026-09-29 17:15:14 | Deep Dive |
| CVE-2026-102424 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 | balbooa.com | Balbooa Forms extension for Joomla | High | 8.9 | 2026-09-29 17:07:26 | Deep Dive |
| CVE-2026-102623 | Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed ephemeral volume | Red Hat | Red Hat OpenShift Virtualization 4 | Medium | 6.5 | 2026-09-29 17:06:08 | Deep Dive |
| CVE-2026-102425 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 | balbooa.com | Balbooa Forms extension for Joomla | Critical | 9.5 | 2026-09-29 17:04:35 | Deep Dive |
| CVE-2026-101126 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 | balbooa.com | Balbooa Forms extension for Joomla | Medium | 6.9 | 2026-09-29 17:02:39 | Deep Dive |
| CVE-2026-101112 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 | balbooa.com | Balbooa Forms extension for Joomla | Medium | 6.9 | 2026-09-29 17:00:26 | Deep Dive |
| CVE-2026-101127 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 | balbooa.com | Balbooa Forms extension for Joomla | High | 8.6 | 2026-09-29 16:57:37 | Deep Dive |
| CVE-2026-102676 | Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions | electron | electron | High | 8.3 | 2026-09-29 16:56:49 | Deep Dive |
| CVE-2026-102796 | Unauthenticated SQL injection in UserPageViewTracker via filterusers and ignoreusers parameters | Wikimedia Foundation | Mediawiki - UserPageViewTracker Extension | - | - | 2026-09-29 16:55:38 | Deep Dive |
| CVE-2026-102675 | Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled | electron | electron | High | 7.4 | 2026-09-29 16:54:29 | Deep Dive |
| CVE-2026-100245 | Stored XSS on Wikibase Special:SetSiteLink via unescaped system message | Wikimedia Foundation | Mediawiki - Wikibase Extension | - | - | 2026-09-29 16:52:55 | Deep Dive |
| CVE-2026-102674 | Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions | electron | electron | High | 8.2 | 2026-09-29 16:51:27 | Deep Dive |
| CVE-2026-100244 | CentralAuth exposes locally suppressed block information via globaluserinfo API and Special:CentralAuth (incomplete fix for CVE-2025-62669) | Wikimedia Foundation | Mediawiki - CentralAuth Extension | - | - | 2026-09-29 16:48:28 | Deep Dive |
| CVE-2026-102697 | Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefix-Based Authorization | ollama | ollama | High | 7.8 | 2026-09-29 16:46:09 | Deep Dive |
| CVE-2026-90915 | Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 | Joomla! Project | Joomla! CMS | High | 7.0 | 2026-09-29 16:45:46 | Deep Dive |