| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103589 | QloApps through 1.7.0 Reflected XSS via Room Type Editor | Webkul | QloApps | Medium | 5.4 | 2026-09-30 23:02:34 | Deep Dive |
| CVE-2026-103588 | QloApps through 1.7.0 Reflected XSS via exceptions field | Webkul | QloApps | Medium | 5.4 | 2026-09-30 23:02:34 | Deep Dive |
| CVE-2026-103587 | QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters | Webkul | QloApps | Medium | 5.4 | 2026-09-30 23:02:33 | Deep Dive |
| CVE-2026-103585 | attacker-controlled javascript license URL via XSS | The Wikimedia Foundation | MediaWiki MediaSearch extension | Low | 1.2 | 2026-09-30 22:17:38 | Deep Dive |
| CVE-2026-103584 | attacker-controlled javascript license URL via XSS | The Wikimedia Foundation | MediaWiki CommonsMetadata extension | Low | 1.1 | 2026-09-30 22:14:27 | Deep Dive |
| CVE-2026-47096 | AJA HELO Plus < 2.1.7 Stored XSS via System Name Parameter | AJA Video Systems | HELO Plus | Medium | 6.1 | 2026-09-30 22:02:09 | Deep Dive |
| CVE-2026-101283 | iperf3 3.20-3.21 RSA解密堆溢出漏洞 | esnet | iperf3 | Critical | 9.2 | 2026-09-30 21:32:15 | Deep Dive |
| CVE-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | jpadilla | pyjwt | Medium | 6.5 | 2026-09-30 21:15:13 | Deep Dive |
| CVE-2026-101276 | iperf3 3.21远程堆释放后使用漏洞 | esnet | iperf3 | Critical | 9.2 | 2026-09-30 21:11:52 | Deep Dive |
| CVE-2026-92172 | Meta Horizon OS 66前特权PendingIntent伪造漏洞 | Meta Platforms, Inc | Meta Horizon OS | - | - | 2026-09-30 20:26:50 | Deep Dive |
| CVE-2026-92173 | Meta Horizon OS 74前MediaSyncJobReceiver权限提升漏洞 | Meta Platforms, Inc | Meta Horizon OS | - | - | 2026-09-30 20:26:33 | Deep Dive |
| CVE-2023-54403 | Yonyou U8 CRM Arbitrary File Read via getemaildata.php | Yonyou | U8 CRM | High | 7.5 | 2026-09-30 20:25:40 | Deep Dive |
| CVE-2026-102105 | Kiteworks Email Protection Gateway server-side request forgery | Kiteworks | Email Protection Gateway | Critical | 9.1 | 2026-09-30 20:25:03 | Deep Dive |
| CVE-2026-102106 | Kiteworks Email Protection Gateway improper authentication | Kiteworks | Email Protection Gateway | Critical | 9.1 | 2026-09-30 20:24:47 | Deep Dive |
| CVE-2026-102107 | Kiteworks Core user impersonation in a file-request feature | Kiteworks | Core | Medium | 4.6 | 2026-09-30 20:24:30 | Deep Dive |
| CVE-2024-58387 | Inspur HCM Cloud Arbitrary File Read via file/download Endpoint | Inspur | Haiyue HCM Cloud | High | 7.5 | 2026-09-30 20:24:26 | Deep Dive |
| CVE-2026-102108 | Kiteworks Email Protection Gateway deserialization of untrusted data | Kiteworks | Email Protection Gateway | High | 7.2 | 2026-09-30 20:24:08 | Deep Dive |
| CVE-2026-102109 | Kiteworks Secure Data Forms SQL injection | Kiteworks | Secure Data Forms | High | 7.1 | 2026-09-30 20:23:36 | Deep Dive |
| CVE-2023-54402 | iDocView SSRF via /doc/upload Endpoint Hardcoded Token | iDocView | iDocView | High | 7.5 | 2026-09-30 20:22:33 | Deep Dive |
| CVE-2026-102110 | Missing authentication on a Kiteworks appliance setup function | Kiteworks | Core | Medium | 5.9 | 2026-09-30 20:21:42 | Deep Dive |