| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-54049 | Sakai Conversations has a Stored XSS Issue | sakaiproject | sakai | High | 8.7 | 2026-10-01 19:42:50 | Deep Dive |
| CVE-2026-102668 | Joyland AI accepts TLS certificates without validation | Joyland | Joyland.ai | Medium | 5.3 | 2026-10-01 19:42:46 | Deep Dive |
| CVE-2026-102667 | Joyland AI WebView command injection | Joyland | Joyland.ai | High | 8.3 | 2026-10-01 19:42:24 | Deep Dive |
| CVE-2026-82358 | RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass | RT-Labs AB | C-Open | Medium | 6.5 | 2026-10-01 19:42:17 | Deep Dive |
| CVE-2026-102666 | Joyland AI hard-coded credentials for push notifications | Joyland | Joyland.ai | Medium | 6.5 | 2026-10-01 19:41:55 | Deep Dive |
| CVE-2026-82357 | RT-Labs AB C-Open CANopen NULL pointer dereference | RT-Labs AB | C-Open | Medium | 6.5 | 2026-10-01 19:41:48 | Deep Dive |
| CVE-2026-71542 | GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php | GetSimpleCMS-CE | GetSimpleCMS-CE | High | 8.7 | 2026-10-01 19:40:04 | Deep Dive |
| CVE-2026-71426 | GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field | GetSimpleCMS-CE | GetSimpleCMS-CE | High | 7.1 | 2026-10-01 19:39:29 | Deep Dive |
| CVE-2026-70650 | GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content | GetSimpleCMS-CE | GetSimpleCMS-CE | High | 8.8 | 2026-10-01 19:39:01 | Deep Dive |
| CVE-2026-56662 | GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request | GetSimpleCMS-CE | GetSimpleCMS-CE | Critical | 9.6 | 2026-10-01 19:38:31 | Deep Dive |
| CVE-2026-56661 | GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint | GetSimpleCMS-CE | GetSimpleCMS-CE | High | 7.5 | 2026-10-01 19:38:08 | Deep Dive |
| CVE-2026-56660 | GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction | GetSimpleCMS-CE | GetSimpleCMS-CE | Critical | 9.1 | 2026-10-01 19:37:46 | Deep Dive |
| CVE-2026-53953 | GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover | GetSimpleCMS-CE | GetSimpleCMS-CE | Critical | 9.1 | 2026-10-01 19:36:18 | Deep Dive |
| CVE-2026-104286 | FortiMail路径遍历漏洞影响多个版本 | Fortinet | FortiMail | Critical | 9.8 | 2026-10-01 19:17:39 | Deep Dive |
| CVE-2026-27872 | EasyIO FG | Johnson Controls | Easy IO FG | Medium | 5.6 | 2026-10-01 18:57:16 | Deep Dive |
| CVE-2026-84682 | TDDPv2 setProductVer Command Injection in Archer AX90 | TP-Link Systems Inc. | Archer AX90 v1 | High | 7.7 | 2026-10-01 18:48:43 | Deep Dive |
| CVE-2026-55232 | Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oEmbed proxy | givanz | Vvveb | High | 7.6 | 2026-10-01 18:43:19 | Deep Dive |
| CVE-2026-55230 | Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted greater-than character | givanz | Vvveb | High | 8.7 | 2026-10-01 18:42:50 | Deep Dive |
| CVE-2026-55231 | Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools | givanz | Vvveb | High | 7.2 | 2026-10-01 18:42:39 | Deep Dive |
| CVE-2026-15911 | Confluent Kafka Python Improper TLS Certificate Validation | confluent | confluent-kafka | High | 7.4 | 2026-10-01 18:29:42 | Deep Dive |