| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-84390 | Fortinet FortiMonitorOnSight 信息泄露漏洞 | Fortinet | FortiMonitorOnSight | Critical | 9.8 | 2026-09-11 12:13:15 | Deep Dive |
| CVE-2026-89259 | Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS | gohugoio | hugo | Critical | 9.8 | 2026-09-11 11:15:35 | Deep Dive |
| CVE-2026-47839 | Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin | Cloud Foundry Foundation | UAA | Critical | 9.2 | 2026-09-11 09:14:09 | Deep Dive |
| CVE-2026-8778 | MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload | mulika | MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields. | Critical | 9.8 | 2026-09-11 03:39:37 | Deep Dive |
| CVE-2026-19646 | Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent | IBM | Common Licensing | Critical | 9.1 | 2026-09-10 22:02:47 | Deep Dive |
| CVE-2026-78573 | IBM ContextForge MCP Gateway is affected by use of default credentials | IBM | ContextForge MCP Gateway | Critical | 9.8 | 2026-09-10 21:42:37 | Deep Dive |
| CVE-2026-79724 | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards | IBM | Langflow OSS | Critical | 9.8 | 2026-09-10 21:41:22 | Deep Dive |
| CVE-2026-80424 | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software | IBM | DataStage on Cloud Pak for Data | Critical | 9.1 | 2026-09-10 21:37:31 | Deep Dive |
| CVE-2026-81204 | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards | IBM | Langflow OSS | Critical | 9.8 | 2026-09-10 21:36:14 | Deep Dive |
| CVE-2026-82100 | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software | IBM | DataStage on Cloud Pak for Data | Critical | 9.6 | 2026-09-10 21:25:53 | Deep Dive |
| CVE-2026-82107 | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software | IBM | DataStage on Cloud Pak for Data | Critical | 9.6 | 2026-09-10 21:25:36 | Deep Dive |
| CVE-2026-45764 | Suricata http2: protocol-change type confusion can lead to denial of service | OISF | suricata | Critical | 9.1 | 2026-09-10 21:14:30 | Deep Dive |
| CVE-2026-75940 | Lenovo Health Application 信任管理问题漏洞 | Lenovo | Health Application | Critical | 9.1 | 2026-09-10 21:00:06 | Deep Dive |
| CVE-2026-85025 | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards | IBM | Langflow OSS | Critical | 9.8 | 2026-09-10 20:58:37 | Deep Dive |
| CVE-2026-89094 | Forgejo 代码注入漏洞 | Forgejo | Forgejo | Critical | 9.9 | 2026-09-10 20:42:19 | Deep Dive |
| CVE-2026-89086 | OCaml jose 加密问题漏洞 | OCaml | jose | Critical | 9.1 | 2026-09-10 19:52:47 | Deep Dive |
| CVE-2026-88062 📌 💣 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | diegosouzapw | OmniRoute | Critical | 9.5 | 2026-09-10 19:14:18 | Deep Dive |
| CVE-2026-89049 | Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent | AWS | Amazon SSM Agent | Critical | 9.9 | 2026-09-10 18:34:48 | Deep Dive |
| CVE-2026-89042 | passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification | krakenjs | passport-saml-encrypted | Critical | 9.1 | 2026-09-10 17:39:33 | Deep Dive |
| CVE-2026-85228 | Integer overflow in tensor buffer validation in Deep Java Library | Amazon | Deep Java Library | Critical | 9.1 | 2026-09-10 17:03:48 | Deep Dive |