| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-77387 | geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point | geopy | geopy | Medium | 4.0 | 2026-10-01 16:38:54 | Deep Dive |
| CVE-2026-103921 | GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor | ardatan | graphql-tools | High | 7.4 | 2026-10-01 16:32:38 | Deep Dive |
| CVE-2026-96659 | Foreman: excessive permissions for viewer role on preview | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | Critical | 9.1 | 2026-10-01 16:23:24 | Deep Dive |
| CVE-2026-96658 | Foreman: safemode bypass leading to rce | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | Critical | 9.9 | 2026-10-01 16:23:24 | Deep Dive |
| CVE-2026-12544 | Foreman: ssti and insecure deserialization in foreman-rake configuration | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 7.7 | 2026-10-01 16:22:15 | Deep Dive |
| CVE-2026-12541 | Foreman: command injection in foreman-rake database tasks | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 8.2 | 2026-10-01 16:22:10 | Deep Dive |
| CVE-2026-101890 | Prime Mover < 2.2.1 Stored XSS via Package Metadata | Codexonics | Prime Mover | Medium | 5.4 | 2026-10-01 16:22:08 | Deep Dive |
| CVE-2026-12540 | Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 8.2 | 2026-10-01 16:22:03 | Deep Dive |
| CVE-2026-12423 | Foreman: unauthenticated information disclosure via provisioning token validation flaw | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 7.5 | 2026-10-01 16:21:53 | Deep Dive |
| CVE-2026-12405 | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 8.8 | 2026-10-01 16:21:44 | Deep Dive |
| CVE-2026-101889 | Prime Mover < 2.2.1 Path Traversal via wprime-config.json | Codexonics | Prime Mover | Medium | 6.5 | 2026-10-01 16:20:55 | Deep Dive |
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:20:14 | Deep Dive |
| CVE-2026-101888 | Prime Mover < 2.2.1 Zip Slip Path Traversal File Write | Codexonics | Prime Mover | High | 7.2 | 2026-10-01 16:19:51 | Deep Dive |
| CVE-2026-93546 | Apache HTTP Server: mod_dav_fs namespace overflow | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:19:33 | Deep Dive |
| CVE-2026-79768 | Apache HTTP Server: mod_userdir information disclosure | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:18:58 | Deep Dive |
| CVE-2026-73637 | Apache HTTP Server: mod_auth_digest DoS attack | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:18:30 | Deep Dive |
| CVE-2026-73636 | Apache HTTP Server: mod_auth_digest one-time-nonce replay attack | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:18:00 | Deep Dive |
| CVE-2025-31980 | HCL BigFix Service Management is affected by multiple security vulnerabilities. | HCL Software | HCL BigFix Service Management | Medium | 4.3 | 2026-10-01 16:17:55 | Deep Dive |
| CVE-2026-63718 | Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:17:07 | Deep Dive |
| CVE-2026-14316 | Heap buffer overflow in boks_sshd revoked-key error handling | Fortra | Core Privileged Access Manager (BoKS) | High | 8.1 | 2026-10-01 16:16:37 | Deep Dive |