| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-104002 | Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python) | AWS | powertools-lambda-python | Medium | 5.3 | 2026-10-01 21:05:55 | Deep Dive |
| CVE-2026-71451 | Johnson Controls EasyIO FS32 < 3.0b63 命令注入漏洞 | Johnson Controls | EasyIO FS32 | Medium | 5.6 | 2026-10-01 20:59:35 | Deep Dive |
| CVE-2026-27874 | EasyIO FS32硬编码凭据漏洞 | Johnson Controls | EasyIO FS32 | Medium | 5.0 | 2026-10-01 20:55:59 | Deep Dive |
| CVE-2026-102370 | Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71 | TP-Link Systems Inc. | Kasa EC70 V4 | Medium | 5.4 | 2026-10-01 20:47:30 | Deep Dive |
| CVE-2026-104020 | Uncontrolled recursion in the Ion reader in Amazon Ion Python | Amazon | ion-python | High | 7.5 | 2026-10-01 20:36:34 | Deep Dive |
| CVE-2026-96780 | figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width | patorjk | figlet.js | High | 8.2 | 2026-10-01 20:21:54 | Deep Dive |
| CVE-2026-104183 | stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects | uhop | stream-json | Medium | 5.1 | 2026-10-01 20:17:22 | Deep Dive |
| CVE-2026-104182 | stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk | uhop | stream-json | Medium | 6.2 | 2026-10-01 20:15:39 | Deep Dive |
| CVE-2026-104181 🧪 | Filament: Multi-factor authentication (app) management actions do not require password reauthentication | filamentphp | filament | Medium | 5.4 | 2026-10-01 20:02:31 | Deep Dive |
| CVE-2026-102514 | Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive | PeaZip | PeaZip | High | 8.4 | 2026-10-01 20:00:52 | Deep Dive |
| CVE-2026-55396 | Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2 | Teledyne FLIR | Aware2 | High | 8.5 | 2026-10-01 19:59:40 | Deep Dive |
| CVE-2026-55395 | Hardcoded Passwords in Teledyne FLIR Robots running Aware2 | Teledyne FLIR | Aware2 | Critical | 9.4 | 2026-10-01 19:59:33 | Deep Dive |
| CVE-2026-55394 | Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2 | Teledyne FLIR | Aware2 | Medium | 5.3 | 2026-10-01 19:59:28 | Deep Dive |
| CVE-2026-55393 | Local File Inclusion in Teledyne FLIR Robots running Aware2 | Teledyne FLIR | Aware2 | Critical | 10.0 | 2026-10-01 19:59:20 | Deep Dive |
| CVE-2026-14984 | Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2 | Teledyne FLIR | Aware2 | Critical | 9.4 | 2026-10-01 19:59:09 | Deep Dive |
| CVE-2026-14983 | Missing Authentication in Teledyne FLIR Robots running Aware2 | Teledyne FLIR | Aware2 | High | 7.1 | 2026-10-01 19:59:00 | Deep Dive |
| CVE-2026-53964 | Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) | adfinis | document-merge-service | High | 7.2 | 2026-10-01 19:55:08 | Deep Dive |
| CVE-2026-55252 | OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect | openrundev | openrun | Medium | 5.1 | 2026-10-01 19:52:31 | Deep Dive |
| CVE-2026-55251 | NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files | netbox-community | devicetype-library | Medium | 6.5 | 2026-10-01 19:49:33 | Deep Dive |
| CVE-2026-103484 | pgvector buffer overflow in IVFFlat index build | - | pgvector | High | 8.8 | 2026-10-01 19:49:04 | Deep Dive |