| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-95675 | D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface | D-LINK | DAP-1360 | Critical | 9.8 | 2026-09-22 13:49:12 | Deep Dive |
| CVE-2026-93616 | Directory Traversal and File upload allows execution of arbitrary script on the Management Server | checkpoint | Quantum Security Management | Critical | 9.8 | 2026-09-22 12:59:01 | Deep Dive |
| CVE-2026-74849 | Remote code execution vulnerability | Zohocorp | ManageEngine ADSelfService Plus | Critical | 9.8 | 2026-09-22 11:55:33 | Deep Dive |
| CVE-2026-25254 | Improper authorization in Qualcomm Software Center | Qualcomm, Inc. | Snapdragon | Critical | 9.8 | 2026-09-22 09:45:13 | Deep Dive |
| CVE-2026-93556 | Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini | Kompini | Tankuam Places | Critical | 9.3 | 2026-09-22 08:57:31 | Deep Dive |
| CVE-2026-89422 | TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension | Erlang | OTP | Critical | 9.3 | 2026-09-22 08:49:16 | Deep Dive |
| CVE-2026-93952 | Security Advisory 0183 | Arista Networks | VeloCloud Orchestrator (VCO) On-Prem | Critical | 10.0 | 2026-09-22 07:37:24 | Deep Dive |
| CVE-2026-19658 | Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter | LiquidWeb | Give Tributes | Critical | 9.8 | 2026-09-22 04:27:39 | Deep Dive |
| CVE-2026-13355 | Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter | Meta Box | Meta Box Frontend Submission | Critical | 9.8 | 2026-09-22 04:27:37 | Deep Dive |
| CVE-2026-94493 | Gigatech PDV5701 WebSocket Service index.html missing authentication | Gigatech | PDV5701 | Critical | 10.0 | 2026-09-22 01:00:19 | Deep Dive |
| CVE-2026-46649 | Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint | laurent22 | joplin | Critical | 9.1 | 2026-09-21 20:58:04 | Deep Dive |
| CVE-2026-77521 | MaxKB: Prompt-injectable agent can lead to command execution | 1Panel-dev | MaxKB | Critical | 10.0 | 2026-09-21 20:45:15 | Deep Dive |
| CVE-2026-79916 | MaxKB AWS Bedrock model credential injection leads to remote code execution | 1Panel-dev | MaxKB | Critical | 9.1 | 2026-09-21 20:34:48 | Deep Dive |
| CVE-2026-94572 | CVE-2026-94572 | OpenStack | Octavia | Critical | 9.4 | 2026-09-21 20:13:36 | Deep Dive |
| CVE-2026-94571 | CVE-2026-94571 | OpenStack | Octavia | Critical | 9.4 | 2026-09-21 20:09:17 | Deep Dive |
| CVE-2026-58491 | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter | warp-tech | warpgate | Critical | 9.3 | 2026-09-21 18:48:04 | Deep Dive |
| CVE-2026-79920 | Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task | ajenti | ajenti | Critical | 9.9 | 2026-09-21 16:35:03 | Deep Dive |
| CVE-2026-61674 | Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handler | fluent | fluent-bit | Critical | 9.2 | 2026-09-21 16:10:15 | Deep Dive |
| CVE-2026-85751 | Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust | Mailu | Mailu | Critical | 9.8 | 2026-09-21 15:39:25 | Deep Dive |
| CVE-2026-94301 | Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 | Apache Software Foundation | Apache MINA | Critical | 9.8 | 2026-09-21 14:36:00 | Deep Dive |