| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55231 | Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read and delete through backup tools | givanz | Vvveb | High | 7.2 | 2026-10-01 18:42:39 | Deep Dive |
| CVE-2026-15911 | Confluent Kafka Python Improper TLS Certificate Validation | confluent | confluent-kafka | High | 7.4 | 2026-10-01 18:29:42 | Deep Dive |
| CVE-2026-104059 | Lektor 3.3.14 CSRF via Admin API Endpoints | lektor | lektor | High | 8.1 | 2026-10-01 18:17:39 | Deep Dive |
| CVE-2026-8618 | Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus | TP-Link Systems Inc. | Deco M9 Plus V2 | High | 7.7 | 2026-10-01 18:16:32 | Deep Dive |
| CVE-2026-104058 | Podgrab Missing Authentication on WebSocket /ws Endpoint | akhilrex | podgrab | Medium | 5.3 | 2026-10-01 18:12:06 | Deep Dive |
| CVE-2026-104057 | Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler | akhilrex | podgrab | High | 7.5 | 2026-10-01 18:04:01 | Deep Dive |
| CVE-2026-104056 | CVE-2026-104056 | Authlib | Authlib | - | - | 2026-10-01 18:03:27 | Deep Dive |
| CVE-2026-55083 | DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) | dhis2 | dhis2-core | Critical | 9.1 | 2026-10-01 18:00:05 | Deep Dive |
| CVE-2026-102369 | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200 | TP-Link Systems Inc. | Tapo C200 v5 | High | 8.7 | 2026-10-01 17:42:25 | Deep Dive |
| CVE-2026-78578 | Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200 | TP-Link Systems Inc. | Tapo C200 v5 | High | 7.1 | 2026-10-01 17:42:06 | Deep Dive |
| CVE-2026-78577 | Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200 | TP-Link Systems Inc. | Tapo C200 v5 | Medium | 5.3 | 2026-10-01 17:41:50 | Deep Dive |
| CVE-2026-9032 | Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200 | TP-Link Systems Inc. | Tapo C200 V5 | High | 7.1 | 2026-10-01 17:41:31 | Deep Dive |
| CVE-2026-103923 | KaTeX: Existing prototype pollution can bypass trust restrictions | KaTeX | KaTeX | Low | 2.1 | 2026-10-01 17:37:48 | Deep Dive |
| CVE-2026-68496 | jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service | FasterXML | jackson-dataformats-binary | High | 7.5 | 2026-10-01 17:36:58 | Deep Dive |
| CVE-2026-68495 | jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLength, enabling memory-exhaustion denial of service | FasterXML | jackson-dataformats-binary | High | 7.5 | 2026-10-01 17:36:22 | Deep Dive |
| CVE-2026-104018 | VxWorks 7 improper privilege management | Wind River Systems Inc | VxWorks 7 | High | 8.8 | 2026-10-01 17:35:20 | Deep Dive |
| CVE-2026-97662 | Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arbitrary host file creation, overwrite, and truncation outside the intended workspace | AWS | security-agent-mcp-server | High | 8.2 | 2026-10-01 17:34:04 | Deep Dive |
| CVE-2026-102294 | Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration | TP-Link System Inc. | TL-WR841N v14 | High | 8.5 | 2026-10-01 17:30:20 | Deep Dive |
| CVE-2026-103922 | Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path | ionic-team | capacitor | Critical | 9.3 | 2026-10-01 17:27:06 | Deep Dive |
| CVE-2026-103884 | Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read | Red Hat | Red Hat Build of Keycloak | Medium | 6.5 | 2026-10-01 17:16:21 | Deep Dive |