| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-80442 | IBM Guardium Data Protection is affected by multiple vulnerabilities. | IBM | Guardium Data Protection | Critical | 9.9 | 2026-09-18 19:25:34 | Deep Dive |
| CVE-2026-80441 | IBM Guardium Data Protection is affected by multiple vulnerabilities. | IBM | Guardium Data Protection | Critical | 9.8 | 2026-09-18 19:24:58 | Deep Dive |
| CVE-2026-75878 | IBM Sterling File Gateway is Vulnerable to Authentication Bypass | IBM | Sterling File Gateway | Critical | 9.1 | 2026-09-18 19:22:18 | Deep Dive |
| CVE-2026-93839 | LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint | ModelTC | LightLLM | Critical | 9.8 | 2026-09-18 19:06:05 | Deep Dive |
| CVE-2023-54399 | Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree | Hongjing | e-HR | Critical | 9.8 | 2026-09-18 18:58:29 | Deep Dive |
| CVE-2026-59163 | Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass | AxDSan | mnemosyne | Critical | 9.1 | 2026-09-18 17:57:50 | Deep Dive |
| CVE-2026-61550 | Icinga 2: Improper access control for JSON-RPC update certificate messages | Icinga | icinga2 | Critical | 9.8 | 2026-09-18 17:21:18 | Deep Dive |
| CVE-2026-93762 | Data deletion and attribute disclosure via field-name method injection in in-memory queries | MongoDB Inc. | Mongoid | Critical | 9.8 | 2026-09-18 17:15:17 | Deep Dive |
| CVE-2026-92701 | Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path | ultravioletrs | cocos | Critical | 9.1 | 2026-09-18 17:06:18 | Deep Dive |
| CVE-2025-66455 | LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py | InternLM | lmdeploy | Critical | 9.8 | 2026-09-18 17:03:37 | Deep Dive |
| CVE-2026-92702 | Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path | ultravioletrs | cocos | Critical | 9.1 | 2026-09-18 17:02:48 | Deep Dive |
| CVE-2026-93765 | Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation | MongoDB Inc. | Mongoid | Critical | 9.1 | 2026-09-18 17:01:09 | Deep Dive |
| CVE-2026-77240 | WACRM: Database-layer authorization bypasses | ArnasDon | wacrm | Critical | 9.9 | 2026-09-18 16:43:42 | Deep Dive |
| CVE-2026-81321 | CareCam CM2507 Cleartext Storage of Sensitive Information | CareCam | HMT.CM2507 Firmware | Critical | 9.8 | 2026-09-18 16:22:33 | Deep Dive |
| CVE-2026-85497 | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort | CareCam | HMT.CM2507 Firmware | Critical | 9.8 | 2026-09-18 16:19:23 | Deep Dive |
| CVE-2026-61682 | kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace | kcp-dev | kcp | Critical | 9.9 | 2026-09-18 16:11:46 | Deep Dive |
| CVE-2026-10858 | IBM MQ for HPE NonStop is vulnerable to a denial of service attack | IBM | MQ for HPE NonStop | Critical | 9.9 | 2026-09-18 16:08:38 | Deep Dive |
| CVE-2026-84383 | libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items | strukturag | libheif | Critical | 9.8 | 2026-09-18 15:55:47 | Deep Dive |
| CVE-2026-10747 | IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing | IBM | MQ Appliance | Critical | 10.0 | 2026-09-18 15:55:43 | Deep Dive |
| CVE-2025-15399 | Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent | IBM | Common Licensing | Critical | 10.0 | 2026-09-18 15:38:38 | Deep Dive |