| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-9163 | SQLi in GIS Informatics' GisLab Laboratory Management System | GIS Informatics | GisLab Laboratory Management System | Critical | 9.8 | 2026-09-10 12:11:35 | Deep Dive |
| CVE-2026-78082 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 | joomshaper.com | SP Property extension for Joomla | Critical | 9.3 | 2026-09-10 09:59:47 | Deep Dive |
| CVE-2026-8323 | Open Redirect in Armiya Information Technologies' Access Control System | Armiya Information Technologies Ltd. Co. | Access Control System | Critical | 9.3 | 2026-09-10 08:49:12 | Deep Dive |
| CVE-2026-88285 | GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service | GeoVision Inc. | GV-LPC2011/LPC2211 | Critical | 9.4 | 2026-09-10 08:24:16 | Deep Dive |
| CVE-2026-88278 | GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay | GeoVision Inc. | GV-LPCLPC2011/2211 | Critical | 9.8 | 2026-09-10 08:21:59 | Deep Dive |
| CVE-2026-44950 | fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 | SUSE | Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 | Critical | 9.0 | 2026-09-10 08:19:55 | Deep Dive |
| CVE-2026-59679 | fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 | SUSE | Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 | Critical | 9.0 | 2026-09-10 08:15:25 | Deep Dive |
| CVE-2026-7188 | SQLi in Armiya Information Technologies' Access Control System | Armiya Information Technologies Ltd. Co. | Access Control System | Critical | 9.8 | 2026-09-10 07:49:15 | Deep Dive |
| CVE-2026-19583 | Velociraptor Required Permissions bypass by using client monitoring queries | Rapid7 | Velociraptor | Critical | 9.9 | 2026-09-10 02:58:12 | Deep Dive |
| CVE-2026-18351 | Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter | addonsorg | Drag and Drop File Upload for Elementor Forms | Critical | 9.8 | 2026-09-10 01:26:54 | Deep Dive |
| CVE-2026-87931 | Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow | Behavioral Technology Group | Pavlok Behavioral Conditioning Wearable | Critical | 9.6 | 2026-09-09 23:45:09 | Deep Dive |
| CVE-2026-88069 | Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis | pandora-analysis | pandora | Critical | 9.3 | 2026-09-09 21:37:52 | Deep Dive |
| CVE-2026-87911 | Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server | AWS | AWS Labs postgres MCP Server | Critical | 9.6 | 2026-09-09 19:35:46 | Deep Dive |
| CVE-2026-54694 | NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover | NationalSecurityAgency | skills-service | Critical | 9.6 | 2026-09-09 18:44:15 | Deep Dive |
| CVE-2026-87929 | MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key | MaxSite | MaxSite CMS | Critical | 9.8 | 2026-09-09 16:45:00 | Deep Dive |
| CVE-2026-47156 | MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator | mantisbt | mantisbt | Critical | 9.3 | 2026-09-09 16:06:40 | Deep Dive |
| CVE-2026-68484 | Sage AR Automation 授权问题漏洞 | Sage | Sage AR Automation | Critical | 9.0 | 2026-09-09 15:49:40 | Deep Dive |
| CVE-2026-67403 | Sage AR Automation 授权问题漏洞 | Sage | Sage AR Automation | Critical | 9.0 | 2026-09-09 15:49:40 | Deep Dive |
| CVE-2026-22590 | Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage | eProsima | Fast-DDS | Critical | 9.1 | 2026-09-09 15:43:29 | Deep Dive |
| CVE-2026-85103 | Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding | checkpoint | Quantum Security Gateway | Critical | 9.8 | 2026-09-09 13:00:42 | Deep Dive |