| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-85031 | TOTOLINK CP450 cstecgi.cgi buffer overflow | TOTOLINK | CP450 | Critical | 9.9 | 2026-09-03 02:00:14 | Deep Dive |
| CVE-2026-19117 | Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability | Delinea | Secret Server (On-Prem) | Critical | 9.8 | 2026-09-02 18:04:51 | Deep Dive |
| CVE-2026-66786 | Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.17 | Critical | 9.1 | 2026-09-02 17:57:19 | Deep Dive |
| CVE-2026-53670 | PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification | vbpf | prevail | Critical | 9.3 | 2026-09-02 17:54:44 | Deep Dive |
| CVE-2026-53671 | PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification | vbpf | prevail | Critical | 9.3 | 2026-09-02 17:54:31 | Deep Dive |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | BishopFox | joro | Critical | 9.6 | 2026-09-02 17:21:40 | Deep Dive |
| CVE-2026-20279 | Cisco IOS XR Software Security Hardening Release: September 2026 | Cisco | Cisco IOS XR Software | Critical | 9.8 | 2026-09-02 16:13:58 | Deep Dive |
| CVE-2026-20274 | Cisco IOS XR Software Security Hardening Release: September 2026 | Cisco | Cisco IOS XR Software | Critical | 9.8 | 2026-09-02 16:13:35 | Deep Dive |
| CVE-2026-20212 | Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability | Cisco | Cisco NX-OS Software | Critical | 9.8 | 2026-09-02 16:13:09 | Deep Dive |
| CVE-2026-53611 | Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation | AS203038 | looking-glass | Critical | 9.8 | 2026-09-02 16:06:43 | Deep Dive |
| CVE-2026-82955 | Eclipse aeriOS 加密问题漏洞 | Eclipse Foundation | Eclipse aeriOS | Critical | 9.0 | 2026-09-02 14:43:10 | Deep Dive |
| CVE-2025-9314 | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload | Unknown | Developer Tools | Critical | 9.8 | 2026-09-02 14:25:51 | Deep Dive |
| CVE-2026-77009 | WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console | Unknown | WatchMan-Site7 | Critical | 9.9 | 2026-09-02 14:16:49 | Deep Dive |
| CVE-2026-4357 | Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload | Unknown | Embed HTML5 Game | Critical | 10.0 | 2026-09-02 14:16:48 | Deep Dive |
| CVE-2026-81294 | WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability | Paul Ryan | Authorizer | Critical | 9.8 | 2026-09-02 11:37:27 | Deep Dive |
| CVE-2026-81286 | WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability | WC Lovers | WCFM Marketplace | Critical | 9.3 | 2026-09-02 11:37:25 | Deep Dive |
| CVE-2026-84803 | SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist | siyuan-note | siyuan | Critical | 9.0 | 2026-09-02 11:11:17 | Deep Dive |
| CVE-2026-84795 | Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance | craftcms | cms | Critical | 9.8 | 2026-09-02 11:11:11 | Deep Dive |
| CVE-2026-78657 | SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field | bdthemes | SigmaForms Pro – AI Generated Forms | Critical | 9.8 | 2026-09-02 05:29:52 | Deep Dive |
| CVE-2026-9055 | Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' | melograno | Booking for Appointments and Events Calendar – Amelia | Critical | 9.8 | 2026-09-02 04:26:46 | Deep Dive |