| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-90608 | Totolink A3002MU boa formPortFw buffer overflow | Totolink | A3002MU | Critical | 9.9 | 2026-09-14 00:15:08 | Deep Dive |
| CVE-2026-90607 | Totolink A3002MU boa formNewSchedule buffer overflow | Totolink | A3002MU | Critical | 9.9 | 2026-09-14 00:00:10 | Deep Dive |
| CVE-2026-90606 | Totolink A3002MU boa formIpv6Setup buffer overflow | Totolink | A3002MU | Critical | 9.9 | 2026-09-13 23:45:11 | Deep Dive |
| CVE-2026-90605 | Totolink A3002MU boa formFilter buffer overflow | Totolink | A3002MU | Critical | 9.9 | 2026-09-13 23:30:11 | Deep Dive |
| CVE-2026-81648 | CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router | Unknown | CryptoPayment Gateway | Critical | 10.0 | 2026-09-13 20:06:35 | Deep Dive |
| CVE-2026-90558 | sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers | irontec | sngrep | Critical | 9.8 | 2026-09-12 18:06:42 | Deep Dive |
| CVE-2026-78159 | The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation | stellarwp | The Events Calendar | Critical | 9.8 | 2026-09-12 07:39:16 | Deep Dive |
| CVE-2026-78006 | The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution | stellarwp | The Events Calendar | Critical | 9.8 | 2026-09-12 07:39:15 | Deep Dive |
| CVE-2026-85706 KEV 📌 💣 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | GitLab | GitLab | Critical | 10.0 | 2026-09-12 02:46:32 | Deep Dive |
| CVE-2026-87719 | Deserialization of Untrusted Data in GitLab | GitLab | GitLab | Critical | 9.9 | 2026-09-12 02:46:27 | Deep Dive |
| CVE-2026-90456 | CISA Malcolm 信任管理问题漏洞 | CISA | Malcolm | Critical | 9.2 | 2026-09-11 21:52:17 | Deep Dive |
| CVE-2026-89713 | NFSD: check truncate permission under inode lock | Linux | Linux | Critical | 9.1 | 2026-09-11 19:46:28 | Deep Dive |
| CVE-2026-89712 | NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:27 | Deep Dive |
| CVE-2026-89708 | nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:24 | Deep Dive |
| CVE-2026-89702 | nfsd: size fh_verify server sockaddr slot by xpt_locallen | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:20 | Deep Dive |
| CVE-2026-89703 | nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:20 | Deep Dive |
| CVE-2026-89697 | nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() | Linux | Linux | Critical | 9.1 | 2026-09-11 19:46:16 | Deep Dive |
| CVE-2026-89689 | nfsd: don't free session slots that are still in use | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:10 | Deep Dive |
| CVE-2026-89688 | nfsd: drop the stateid, not the stateowner, on seqid_op replay retry | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:09 | Deep Dive |
| CVE-2026-89686 | nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke | Linux | Linux | Critical | 9.8 | 2026-09-11 19:46:08 | Deep Dive |