| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-82010 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) | Adobe | Adobe Campaign Classic | Critical | 9.9 | 2026-09-22 17:39:50 | Deep Dive |
| CVE-2026-85734 | LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks | HKUDS | LightRAG | Critical | 9.1 | 2026-09-22 16:18:14 | Deep Dive |
| CVE-2026-86059 | Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one | Dokploy | dokploy | Critical | 9.6 | 2026-09-22 16:11:57 | Deep Dive |
| CVE-2026-94456 | Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys | GitroomHQ | postiz-app | Critical | 9.1 | 2026-09-22 16:11:34 | Deep Dive |
| CVE-2026-80156 | Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass | LANTRONIX | SLC8000 | Critical | 9.1 | 2026-09-22 15:23:25 | Deep Dive |
| CVE-2026-63374 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing | agronholm | anyio | Critical | 9.3 | 2026-09-22 15:23:14 | Deep Dive |
| CVE-2026-80155 | Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation | LANTRONIX | SLC8000 | Critical | 10.0 | 2026-09-22 15:22:57 | Deep Dive |
| CVE-2026-80154 | Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass | LANTRONIX | SLC8000 | Critical | 9.6 | 2026-09-22 15:22:34 | Deep Dive |
| CVE-2026-80152 | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule | LANTRONIX | SLC8000 | Critical | 9.1 | 2026-09-22 15:22:10 | Deep Dive |
| CVE-2026-80151 | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download | LANTRONIX | SLC8000 | Critical | 9.1 | 2026-09-22 15:21:45 | Deep Dive |
| CVE-2026-80147 | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write | LANTRONIX | SLC8000 | Critical | 9.9 | 2026-09-22 15:20:02 | Deep Dive |
| CVE-2026-80146 | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read | LANTRONIX | SLC8000 | Critical | 9.9 | 2026-09-22 15:19:39 | Deep Dive |
| CVE-2026-77621 | Vector: Arbitrary file write in the file sink via templated path (path traversal). | vectordotdev | vector | Critical | 9.3 | 2026-09-22 15:19:20 | Deep Dive |
| CVE-2026-80145 | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password | LANTRONIX | SLC8000 | Critical | 9.1 | 2026-09-22 15:18:35 | Deep Dive |
| CVE-2026-80144 | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write | LANTRONIX | SLC8000 | Critical | 9.9 | 2026-09-22 15:17:46 | Deep Dive |
| CVE-2026-80143 | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read | LANTRONIX | SLC8000 | Critical | 9.9 | 2026-09-22 15:17:22 | Deep Dive |
| CVE-2026-94127 | BIG-IP APM OAuth vulnerability | F5 | BIG-IP | Critical | 9.8 | 2026-09-22 14:17:43 | Deep Dive |
| CVE-2026-84388 | CVE-2026-84388 | Fortinet | FortiPAM Chrome Extension | Critical | 9.6 | 2026-09-22 14:12:51 | Deep Dive |
| CVE-2026-65113 | CVE-2026-65113 | NVIDIA | Infrastructure Controller | Critical | 9.8 | 2026-09-22 14:10:31 | Deep Dive |
| CVE-2026-12718 | SQLi in Karel Electronics' KarelIPS | Karel Electronic Industry and Trade Inc. | KarelIPS | Critical | 9.8 | 2026-09-22 13:51:45 | Deep Dive |