| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-102427 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 | ordasoft.com | OrdaSoft Joomla CCK | Critical | 10.0 | 2026-09-30 15:14:49 | Deep Dive |
| CVE-2026-94545 | Satori-generated SVG has improper escaping | vercel | satori | Medium | 5.3 | 2026-09-30 14:53:35 | Deep Dive |
| CVE-2026-103398 | OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save Path | Liquid-co | OpenSave | High | 8.1 | 2026-09-30 14:48:58 | Deep Dive |
| CVE-2026-103397 | OpenSave before 2.4.0-beta.1 Authentication Bypass via Spoofed Relay Sender | Liquid-co | OpenSave | Medium | 5.6 | 2026-09-30 14:48:57 | Deep Dive |
| CVE-2026-103396 | bbs-go through 4.4.6 Incorrect Authorization via /api/admin/user/synccount | mlogclub | bbs-go | Medium | 4.3 | 2026-09-30 14:48:56 | Deep Dive |
| CVE-2026-103395 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service | ModelTC | LightLLM | Critical | 9.8 | 2026-09-30 14:48:56 | Deep Dive |
| CVE-2026-103270 | LightLLM through 1.2.0 Missing Authentication on RL Control Routes | ModelTC | LightLLM | High | 7.5 | 2026-09-30 14:48:55 | Deep Dive |
| CVE-2026-103243 | LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints | ModelTC | LightLLM | Medium | 5.8 | 2026-09-30 14:48:54 | Deep Dive |
| CVE-2026-76570 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 | joomcode.com | JCTables extension for Joomla | Critical | 10.0 | 2026-09-30 14:47:49 | Deep Dive |
| CVE-2026-102984 | Astro: Malformed port in the Host header can crash the Node adapter | withastro | astro | High | 8.2 | 2026-09-30 14:35:22 | Deep Dive |
| CVE-2026-102983 | Astro: Netlify Image CDN allowlist bypass enables SSRF | withastro | astro | Medium | 6.3 | 2026-09-30 14:32:04 | Deep Dive |
| CVE-2026-102717 | MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash | Eclipse Foundation | NetX Duo | - | - | 2026-09-30 14:31:23 | Deep Dive |
| CVE-2026-47097 | AJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export Bundle | AJA Video Systems | HELO Plus | High | 7.5 | 2026-09-30 14:31:12 | Deep Dive |
| CVE-2026-103227 | GPAC DASH Client dash_client.c gf_dash_resolve_url buffer overflow | - | GPAC | Medium | 6.3 | 2026-09-30 14:30:09 | Deep Dive |
| CVE-2026-103389 | MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph | MISP | MISP | Medium | 6.2 | 2026-09-30 14:25:59 | Deep Dive |
| CVE-2026-103388 | MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field | MISP | MISP | Medium | 6.2 | 2026-09-30 14:22:36 | Deep Dive |
| CVE-2026-18782 | SQL Injection in Trex Digital Manufacturing's Trex MES | Trex Digital Smart Manufacturing Systems Inc. | Trex MES | Critical | 9.8 | 2026-09-30 14:15:15 | Deep Dive |
| CVE-2026-103226 | Artifex Ghostscript Pdfwrite gdevpsfx.c type1_callsubr stack-based overflow | Artifex | Ghostscript | Medium | 6.3 | 2026-09-30 14:15:06 | Deep Dive |
| CVE-2026-18783 | Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES | Trex Digital Smart Manufacturing Systems Inc. | Trex MES | High | 8.8 | 2026-09-30 14:12:02 | Deep Dive |
| CVE-2026-97259 | WordPress Pay with Vipps for WooCommerce plugin <= 6.2.4 - Insecure Direct Object References (IDOR) vulnerability | WP Hosting AS | Pay with Vipps for WooCommerce | Medium | 5.3 | 2026-09-30 14:10:25 | Deep Dive |