| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-100256 | IntelliJ IDEA 2026.2.3前结构搜索RCE漏洞 | JetBrains | IntelliJ IDEA | High | 7.8 | 2026-09-30 15:17:47 | Deep Dive |
| CVE-2026-100257 | JetBrains YouTrack 2026.2前PDF导出存储型SSRF漏洞 | JetBrains | YouTrack | Medium | 4.3 | 2026-09-30 15:17:47 | Deep Dive |
| CVE-2026-100258 | JetBrains YouTrack 2026.2.18991前越权读取项目设置 | JetBrains | YouTrack | Medium | 4.3 | 2026-09-30 15:17:47 | Deep Dive |
| CVE-2026-100255 | JetBrains TeamCity多版本管理员账户接管漏洞 | JetBrains | TeamCity | High | 8.1 | 2026-09-30 15:17:46 | Deep Dive |
| CVE-2026-100253 | TeamCity多版本Kotlin DSL沙箱逃逸致代码执行 | JetBrains | TeamCity | High | 8.8 | 2026-09-30 15:17:45 | Deep Dive |
| CVE-2026-100254 | TeamCity多版本Git配置CRLF注入致命令执行 | JetBrains | TeamCity | High | 8.8 | 2026-09-30 15:17:45 | Deep Dive |
| CVE-2026-103229 | AdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysqli_query sql injection | AdithyaYelloju | Restaurant-Management-System | High | 7.3 | 2026-09-30 15:15:12 | Deep Dive |
| CVE-2026-102427 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 | ordasoft.com | OrdaSoft Joomla CCK | Critical | 10.0 | 2026-09-30 15:14:49 | Deep Dive |
| CVE-2026-94545 | Satori-generated SVG has improper escaping | vercel | satori | Medium | 5.3 | 2026-09-30 14:53:35 | Deep Dive |
| CVE-2026-103398 | OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path | Liquid-co | OpenSave | High | 8.1 | 2026-09-30 14:48:58 | Deep Dive |
| CVE-2026-103397 | OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender | Liquid-co | OpenSave | Medium | 5.6 | 2026-09-30 14:48:57 | Deep Dive |
| CVE-2026-103396 | bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount | mlogclub | bbs-go | Medium | 4.3 | 2026-09-30 14:48:56 | Deep Dive |
| CVE-2026-103395 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service | ModelTC | LightLLM | Critical | 9.8 | 2026-09-30 14:48:56 | Deep Dive |
| CVE-2026-103270 | LightLLM through 1.2.0 Missing Authentication on RL Control Routes | ModelTC | LightLLM | High | 7.5 | 2026-09-30 14:48:55 | Deep Dive |
| CVE-2026-103243 | LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints | ModelTC | LightLLM | Medium | 5.8 | 2026-09-30 14:48:54 | Deep Dive |
| CVE-2026-76570 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 | joomcode.com | JCTables extension for Joomla | Critical | 10.0 | 2026-09-30 14:47:49 | Deep Dive |
| CVE-2026-102984 | Astro: Malformed port in the Host header can crash the Node adapter | withastro | astro | High | 8.2 | 2026-09-30 14:35:22 | Deep Dive |
| CVE-2026-102983 | Astro: Netlify Image CDN allowlist bypass enables SSRF | withastro | astro | Medium | 6.3 | 2026-09-30 14:32:04 | Deep Dive |
| CVE-2026-102717 | MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash | Eclipse Foundation | NetX Duo | - | - | 2026-09-30 14:31:23 | Deep Dive |
| CVE-2026-47097 | AJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export Bundle | AJA Video Systems | HELO Plus | High | 7.5 | 2026-09-30 14:31:12 | Deep Dive |