| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102129 | Kiteworks Core Incorrect Privilege Assignment | Kiteworks | Core | High | 7.2 | 2026-09-30 20:14:14 | Deep Dive |
| CVE-2026-102130 | Kiteworks Email Protection Gateway Remote Code Execution | Kiteworks | Email Protection Gateway | High | 7.2 | 2026-09-30 20:13:59 | Deep Dive |
| CVE-2026-102131 | Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity | Kiteworks | Email Protection Gateway | High | 7.2 | 2026-09-30 20:13:43 | Deep Dive |
| CVE-2026-102132 | Kiteworks Core Privilege Escalation through Improper Access Control | Kiteworks | Core | High | 7.2 | 2026-09-30 20:13:28 | Deep Dive |
| CVE-2026-102133 | Kiteworks Core Arbitrary File Write through Command Injection | Kiteworks | Core | Medium | 6.6 | 2026-09-30 20:13:10 | Deep Dive |
| CVE-2026-103000 | pypdf: Possible large memory usage when retrieving alphabetical page labels | py-pdf | pypdf | High | 8.7 | 2026-09-30 20:13:00 | Deep Dive |
| CVE-2026-102102 | Kiteworks Email Protection Gateway server-side request forgery | Kiteworks | Email Protection Gateway | Critical | 9.1 | 2026-09-30 20:12:42 | Deep Dive |
| CVE-2026-102134 | Kiteworks Core Unprotected Alternate Channel | Kiteworks | Core | Medium | 5.4 | 2026-09-30 20:12:40 | Deep Dive |
| CVE-2026-102135 | Kiteworks Email Protection Gateway Deserialization of Untrusted Data | Kiteworks | Email Protection Gateway | Medium | 6.6 | 2026-09-30 20:12:22 | Deep Dive |
| CVE-2026-102136 | Kiteworks Core Command Execution through Configuration Injection | Kiteworks | Core | Medium | 6.3 | 2026-09-30 20:12:07 | Deep Dive |
| CVE-2026-102137 | Kiteworks Core Unrestricted Upload of File with Dangerous Type | Kiteworks | Core | Medium | 4.1 | 2026-09-30 20:11:52 | Deep Dive |
| CVE-2026-102138 | Kiteworks Core Server-Side Request Forgery (SSRF) | Kiteworks | Core | Low | 3.3 | 2026-09-30 20:11:32 | Deep Dive |
| CVE-2026-102101 | Kiteworks Core deserialization of untrusted data | Kiteworks | Core | High | 8.1 | 2026-09-30 20:11:24 | Deep Dive |
| CVE-2026-102139 | Kiteworks Email Protection Gateway Incorrect Authorization | Kiteworks | Email Protection Gateway | Medium | 6.5 | 2026-09-30 20:11:18 | Deep Dive |
| CVE-2026-102140 | Kiteworks Core Insufficient Verification of Data Authenticity | Kiteworks | Core | Medium | 4.9 | 2026-09-30 20:11:08 | Deep Dive |
| CVE-2026-102141 | Kiteworks Core Privilege Escalation through External Control of File Name or Path | Kiteworks | Core | Medium | 6.7 | 2026-09-30 20:10:56 | Deep Dive |
| CVE-2026-102999 | pypdf: Possible long runtimes with large amount of embedded files | py-pdf | pypdf | High | 8.7 | 2026-09-30 20:10:38 | Deep Dive |
| CVE-2026-102142 | Kiteworks Core Remote Code Execution through Server-Side Template Injection | Kiteworks | Core | High | 7.2 | 2026-09-30 20:10:30 | Deep Dive |
| CVE-2026-102143 | Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type | Kiteworks | Email Protection Gateway | High | 7.5 | 2026-09-30 20:10:09 | Deep Dive |
| CVE-2026-102100 | Kiteworks Core stored XSS | Kiteworks | Core | High | 8.7 | 2026-09-30 20:10:05 | Deep Dive |