| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-57131 | praisonai: Jobs API exposes agent-execution endpoints with no authentication | MervinPraison | PraisonAI | Critical | 9.8 | 2026-09-14 15:06:20 | Deep Dive |
| CVE-2026-57124 | PraisonAI UI MCP connect endpoint allows unauthenticated local command execution | MervinPraison | PraisonAI | Critical | 9.8 | 2026-09-14 15:04:54 | Deep Dive |
| CVE-2026-57127 | praisonai: recipe serve auth middleware silently disables itself when no secret is set | MervinPraison | PraisonAI | Critical | 9.8 | 2026-09-14 15:01:49 | Deep Dive |
| CVE-2026-57123 | PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in | MervinPraison | praisonaiagents | Critical | 9.8 | 2026-09-14 14:46:13 | Deep Dive |
| CVE-2026-57125 | PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass | MervinPraison | PraisonAI | Critical | 9.8 | 2026-09-14 14:19:43 | Deep Dive |
| CVE-2026-82434 | Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs | Apache Software Foundation | Apache Storm Nimbus | Critical | 10.0 | 2026-09-14 14:10:15 | Deep Dive |
| CVE-2026-90961 | MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials | MISP | MISP | Critical | 9.3 | 2026-09-14 13:22:07 | Deep Dive |
| CVE-2026-90937 | froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL | froxlor | froxlor | Critical | 9.9 | 2026-09-14 12:48:31 | Deep Dive |
| CVE-2026-12258 | Inadequate access control in the Hiperdino REST API | Hiperdino | REST API | Critical | 9.2 | 2026-09-14 12:11:13 | Deep Dive |
| CVE-2026-90919 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization | ModelTC | LightLLM | Critical | 9.8 | 2026-09-14 11:31:00 | Deep Dive |
| CVE-2026-21391 | Improper Claim Validation in PingAM OIDC Provider | Ping Identity | PingAM | Critical | 9.5 | 2026-09-14 11:18:33 | Deep Dive |
| CVE-2026-90898 | Bifrost unauthenticated remote code execution via MCP stdio client registration | maximhq | Bifrost | Critical | 9.8 | 2026-09-14 10:18:53 | Deep Dive |
| CVE-2026-90703 | D-Link DWR-M921 formDiskCreateShare system os command injection | D-Link | DWR-M921 | Critical | 9.1 | 2026-09-14 09:45:10 | Deep Dive |
| CVE-2026-90702 | D-Link DWR-M921 formDiskFormat system os command injection | D-Link | DWR-M921 | Critical | 9.1 | 2026-09-14 09:30:12 | Deep Dive |
| CVE-2026-90699 | D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection | D-Link | DWR-M920 | Critical | 9.9 | 2026-09-14 08:45:10 | Deep Dive |
| CVE-2026-90693 | D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow | D-Link | DIR-878 | Critical | 9.9 | 2026-09-14 07:15:11 | Deep Dive |
| CVE-2026-90692 | D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow | D-Link | DIR-878 | Critical | 9.9 | 2026-09-14 07:00:09 | Deep Dive |
| CVE-2026-82787 | Contec CONPROSYS IO-Link Master 授权问题漏洞 | Contec Co., Ltd. | CPSL-08P1EN | Critical | 9.8 | 2026-09-14 06:44:22 | Deep Dive |
| CVE-2026-85192 | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 | regularlabs.com | Conditional Content Pro extension for Joomla | Critical | 9.4 | 2026-09-14 06:18:01 | Deep Dive |
| CVE-2026-90680 | D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow | D-Link | DIR-823G | Critical | 9.9 | 2026-09-14 04:00:09 | Deep Dive |