| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-85391 | Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml | Peppermint-Lab | peppermint | Critical | 9.8 | 2026-09-03 18:54:25 | Deep Dive |
| CVE-2026-82526 | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint | SciPhi-AI | R2R | Critical | 9.8 | 2026-09-03 18:12:49 | Deep Dive |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | geonetwork | core-geonetwork | Critical | 9.1 | 2026-09-03 17:06:18 | Deep Dive |
| CVE-2026-84834 | WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability | eyecix | JobSearch | Critical | 9.8 | 2026-09-03 16:31:59 | Deep Dive |
| CVE-2026-84814 | WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability | Bricksforge. | Bricksforge | Critical | 9.8 | 2026-09-03 16:31:59 | Deep Dive |
| CVE-2026-84813 | WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability | Paolo | GeoDirectory | Critical | 9.3 | 2026-09-03 16:31:58 | Deep Dive |
| CVE-2026-84768 | WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability | e4jvikwp | VikAppointments Services Booking Calendar | Critical | 9.3 | 2026-09-03 16:31:51 | Deep Dive |
| CVE-2026-84753 | WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability | WPFunnels | Mail Mint | Critical | 9.8 | 2026-09-03 16:31:43 | Deep Dive |
| CVE-2026-84238 | WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability | YITH | YITH Request a Quote for WooCommerce Premium | Critical | 9.8 | 2026-09-03 16:31:42 | Deep Dive |
| CVE-2026-85183 | Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS | Avaiga | taipy | Critical | 9.3 | 2026-09-03 14:12:21 | Deep Dive |
| CVE-2026-85181 | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum | dianping | cat | Critical | 9.8 | 2026-09-03 14:12:20 | Deep Dive |
| CVE-2026-85216 | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials | misp | misp | Critical | 9.5 | 2026-09-03 13:59:35 | Deep Dive |
| CVE-2026-85109 | Tenda HG10 Boa Web Server formLogin buffer overflow | Tenda | HG10 | Critical | 9.8 | 2026-09-03 13:30:12 | Deep Dive |
| CVE-2026-82180 | Eclipse Arrowhead 授权问题漏洞 | Eclipse Foundation | Eclipse Arrowhead | Critical | 9.5 | 2026-09-03 13:20:02 | Deep Dive |
| CVE-2026-78080 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 | joodb.feenders.de | JooDatabase Lite extension for Joomla | Critical | 9.3 | 2026-09-03 12:24:03 | Deep Dive |
| CVE-2026-78069 | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 | j2commerce.com | J2Store extension for Joomla | Critical | 9.5 | 2026-09-03 11:59:13 | Deep Dive |
| CVE-2026-85154 | WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash | WWBN | AVideo | Critical | 9.8 | 2026-09-03 11:22:08 | Deep Dive |
| CVE-2026-76178 | Multiple vulnerabilities in Ocsreports for OCS Inventory NG | OCS Inventory NG | Ocsreports | Critical | 9.2 | 2026-09-03 10:20:19 | Deep Dive |
| CVE-2026-76174 | Multiple vulnerabilities in Ocsreports for OCS Inventory NG | OCS Inventory NG | Ocsreports | Critical | 9.4 | 2026-09-03 09:38:05 | Deep Dive |
| CVE-2026-80726 | KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page | Linux | Linux | Critical | 9.3 | 2026-09-03 08:21:46 | Deep Dive |