| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-65639 | WebPros ConfigServer Security & Firewall 命令注入漏洞 | WebPros | ConfigServer Security & Firewall | Critical | 9.5 | 2026-09-10 16:24:53 | Deep Dive |
| CVE-2026-65638 | WebPros ConfigServer Security & Firewall 命令注入漏洞 | WebPros | ConfigServer Security & Firewall | Critical | 9.2 | 2026-09-10 16:24:53 | Deep Dive |
| CVE-2026-88044 | rclone: RC per-server auth-proxy bypass | rclone | rclone | Critical | 9.1 | 2026-09-10 16:08:15 | Deep Dive |
| CVE-2026-88018 | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass | rclone | rclone | Critical | 9.8 | 2026-09-10 16:03:26 | Deep Dive |
| CVE-2026-81046 | Dell ThinOS 10 权限许可和访问控制问题漏洞 | Dell | ThinOS 10 | Critical | 9.4 | 2026-09-10 15:44:21 | Deep Dive |
| CVE-2026-81468 | Dell ThinOS 10 命令注入漏洞 | Dell | ThinOS 10 | Critical | 9.1 | 2026-09-10 15:42:41 | Deep Dive |
| CVE-2026-81467 | Dell ThinOS 10 命令注入漏洞 | Dell | ThinOS 10 | Critical | 9.8 | 2026-09-10 15:40:58 | Deep Dive |
| CVE-2026-81048 | Dell ThinOS 10 命令注入漏洞 | Dell | ThinOS 10 | Critical | 9.6 | 2026-09-10 15:35:07 | Deep Dive |
| CVE-2026-88899 | knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header | knowns-dev | knowns | Critical | 9.8 | 2026-09-10 15:28:52 | Deep Dive |
| CVE-2026-88007 | Traefik HTTP/3 Backend NTLM Connection Reuse | traefik | traefik | Critical | 9.1 | 2026-09-10 14:47:28 | Deep Dive |
| CVE-2026-81800 | WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability | Par avisverifies | Verified Reviews (Avis Vérifiés) | Critical | 9.3 | 2026-09-10 14:23:48 | Deep Dive |
| CVE-2026-88877 | Traefik v3.7.0 Authentication Bypass via from-to-www-redirect | traefik | traefik | Critical | 9.8 | 2026-09-10 13:05:29 | Deep Dive |
| CVE-2026-88869 | AVideo AD_Server Stored XSS via log.php label parameter | WWBN | AVideo | Critical | 9.3 | 2026-09-10 13:05:24 | Deep Dive |
| CVE-2026-88864 | Capgo SSO Provider Authentication Bypass via PostgREST Direct Write | Cap-go | capgo.app | Critical | 9.1 | 2026-09-10 13:05:21 | Deep Dive |
| CVE-2026-9163 | SQLi in GIS Informatics' GisLab Laboratory Management System | GIS Informatics | GisLab Laboratory Management System | Critical | 9.8 | 2026-09-10 12:11:35 | Deep Dive |
| CVE-2026-78082 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 | joomshaper.com | SP Property extension for Joomla | Critical | 9.3 | 2026-09-10 09:59:47 | Deep Dive |
| CVE-2026-8323 | Open Redirect in Armiya Information Technologies' Access Control System | Armiya Information Technologies Ltd. Co. | Access Control System | Critical | 9.3 | 2026-09-10 08:49:12 | Deep Dive |
| CVE-2026-88285 | GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service | GeoVision Inc. | GV-LPC2011/LPC2211 | Critical | 9.4 | 2026-09-10 08:24:16 | Deep Dive |
| CVE-2026-88278 | GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay | GeoVision Inc. | GV-LPCLPC2011/2211 | Critical | 9.8 | 2026-09-10 08:21:59 | Deep Dive |
| CVE-2026-44950 | fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 | SUSE | Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 | Critical | 9.0 | 2026-09-10 08:19:55 | Deep Dive |