| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-54404 | Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation | colinhacks | zod | High | 7.5 | 2026-10-01 17:11:14 | Deep Dive |
| CVE-2026-73976 | djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`) | 4TUResearchData | djehuty | High | 7.1 | 2026-10-01 17:08:12 | Deep Dive |
| CVE-2026-21833 | HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnerability (CVE-2026-21833) | HCL Software | AION | Low | 3.7 | 2026-10-01 16:54:24 | Deep Dive |
| CVE-2026-73975 | djehuty: Authenticated SPARQL injection in session editing allows writing arbitrary RDF triples | 4TUResearchData | djehuty | High | 8.4 | 2026-10-01 16:41:19 | Deep Dive |
| CVE-2026-77387 | geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point | geopy | geopy | Medium | 4.0 | 2026-10-01 16:38:54 | Deep Dive |
| CVE-2026-103921 | GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor | ardatan | graphql-tools | High | 7.4 | 2026-10-01 16:32:38 | Deep Dive |
| CVE-2026-96659 | Foreman: excessive permissions for viewer role on preview | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | Critical | 9.1 | 2026-10-01 16:23:24 | Deep Dive |
| CVE-2026-96658 | Foreman: safemode bypass leading to rce | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | Critical | 9.9 | 2026-10-01 16:23:24 | Deep Dive |
| CVE-2026-12544 | Foreman: ssti and insecure deserialization in foreman-rake configuration | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 7.7 | 2026-10-01 16:22:15 | Deep Dive |
| CVE-2026-12541 | Foreman: command injection in foreman-rake database tasks | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 8.2 | 2026-10-01 16:22:10 | Deep Dive |
| CVE-2026-101890 | Prime Mover < 2.2.1 Stored XSS via Package Metadata | Codexonics | Prime Mover | Medium | 5.4 | 2026-10-01 16:22:08 | Deep Dive |
| CVE-2026-12540 | Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 8.2 | 2026-10-01 16:22:03 | Deep Dive |
| CVE-2026-12423 | Foreman: unauthenticated information disclosure via provisioning token validation flaw | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 7.5 | 2026-10-01 16:21:53 | Deep Dive |
| CVE-2026-12405 | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | High | 8.8 | 2026-10-01 16:21:44 | Deep Dive |
| CVE-2026-101889 | Prime Mover < 2.2.1 Path Traversal via wprime-config.json | Codexonics | Prime Mover | Medium | 6.5 | 2026-10-01 16:20:55 | Deep Dive |
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:20:14 | Deep Dive |
| CVE-2026-101888 | Prime Mover < 2.2.1 Zip Slip Path Traversal File Write | Codexonics | Prime Mover | High | 7.2 | 2026-10-01 16:19:51 | Deep Dive |
| CVE-2026-93546 | Apache HTTP Server: mod_dav_fs namespace overflow | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:19:33 | Deep Dive |
| CVE-2026-79768 | Apache HTTP Server: mod_userdir information disclosure | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:18:58 | Deep Dive |
| CVE-2026-73637 | Apache HTTP Server: mod_auth_digest DoS attack | Apache Software Foundation | Apache HTTP Server | - | - | 2026-10-01 16:18:30 | Deep Dive |