| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102142 | Kiteworks Core Remote Code Execution through Server-Side Template Injection | Kiteworks | Core | High | 7.2 | 2026-09-30 20:10:30 | Deep Dive |
| CVE-2026-102143 | Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type | Kiteworks | Email Protection Gateway | High | 7.5 | 2026-09-30 20:10:09 | Deep Dive |
| CVE-2026-102100 | Kiteworks Core stored XSS | Kiteworks | Core | High | 8.7 | 2026-09-30 20:10:05 | Deep Dive |
| CVE-2026-102144 | Kiteworks Email Protection Gateway Uncontrolled Resource Consumption | Kiteworks | Email Protection Gateway | Medium | 5.3 | 2026-09-30 20:09:54 | Deep Dive |
| CVE-2026-102150 | Kiteworks Secure Data Forms Missing Authentication for Critical Function | Kiteworks | Secure Data Forms | High | 7.2 | 2026-09-30 20:09:36 | Deep Dive |
| CVE-2026-102149 | Kiteworks Email Protection Gateway Improper Access Control | Kiteworks | Email Protection Gateway | Critical | 9.4 | 2026-09-30 20:09:22 | Deep Dive |
| CVE-2026-102998 | pypdf: Possible long runtimes when generating appearance streams | py-pdf | pypdf | High | 8.7 | 2026-09-30 20:09:14 | Deep Dive |
| CVE-2026-102147 | Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) | Kiteworks | Core | Critical | 9.3 | 2026-09-30 20:09:08 | Deep Dive |
| CVE-2026-102146 | Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side Template Injection | Kiteworks | Email Protection Gateway | Medium | 6.5 | 2026-09-30 20:08:52 | Deep Dive |
| CVE-2026-102145 | Kiteworks Core Server-Side Request Forgery through CRLF Injection | Kiteworks | Core | Medium | 6.6 | 2026-09-30 20:08:34 | Deep Dive |
| CVE-2026-102097 | Kiteworks Email Protection Gateway remote code execution | Kiteworks | Email Protection Gateway | High | 7.2 | 2026-09-30 20:07:48 | Deep Dive |
| CVE-2026-102096 | Kiteworks Core OS command injection | Kiteworks | Core | High | 7.2 | 2026-09-30 20:07:36 | Deep Dive |
| CVE-2026-102099 | Kiteworks Core arbitrary file write | Kiteworks | Core | High | 7.2 | 2026-09-30 20:07:30 | Deep Dive |
| CVE-2026-102095 | Kiteworks Email Protection Gateway server-side request forgery | Kiteworks | Email Protection Gateway | Critical | 9.1 | 2026-09-30 20:07:23 | Deep Dive |
| CVE-2026-102094 | Kiteworks Email Protection Gateway unsafe reflection | Kiteworks | Email Protection Gateway | High | 7.2 | 2026-09-30 20:07:07 | Deep Dive |
| CVE-2026-102093 | Kiteworks Core improper privilege management | Kiteworks | Core | High | 7.2 | 2026-09-30 20:06:49 | Deep Dive |
| CVE-2026-102092 | Kiteworks Core stored XSS | Kiteworks | Core | High | 8.7 | 2026-09-30 20:06:03 | Deep Dive |
| CVE-2026-102997 | pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) | py-pdf | pypdf | High | 8.7 | 2026-09-30 20:05:52 | Deep Dive |
| CVE-2026-102091 | Kiteworks Secure Data Forms server-side request forgery | Kiteworks | Secure Data Forms | High | 7.5 | 2026-09-30 20:05:47 | Deep Dive |
| CVE-2026-102090 | Kiteworks Core content injection | Kiteworks | Core | Medium | 4.3 | 2026-09-30 20:05:32 | Deep Dive |