| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-94052 | Apache MINA SSHD: LDAP password authentication ineffective | Apache Software Foundation | Apache MINA SSHD | Critical | 9.1 | 2026-09-30 09:34:44 | Deep Dive |
| CVE-2026-79625 | Improper Synchronization in Monitoring in CODESYS Control Runtime | CODESYS | Control RTE (SL) | High | 8.1 | 2026-09-30 09:23:17 | Deep Dive |
| CVE-2026-103235 | MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events | MISP | MISP | High | 8.7 | 2026-09-30 09:09:37 | Deep Dive |
| CVE-2026-102588 | Moodle: csrf in xml grade import | - | - | Medium | 6.5 | 2026-09-30 08:36:24 | Deep Dive |
| CVE-2026-102587 | Moodle: user list filters bypass profile field visibility | - | - | Low | 2.7 | 2026-09-30 08:36:21 | Deep Dive |
| CVE-2026-102586 | Moodle: xss via password reset link due to insufficient username escaping | - | - | Medium | 4.3 | 2026-09-30 08:36:19 | Deep Dive |
| CVE-2026-102585 | Moodle: group validation missing when enrolling user to course | - | - | Medium | 4.3 | 2026-09-30 08:36:17 | Deep Dive |
| CVE-2026-102584 | Moodle: missing capability check allows unauthorised grade penalty recalculation | - | - | Medium | 4.3 | 2026-09-30 08:36:15 | Deep Dive |
| CVE-2026-102583 | Moodle: incorrect capability check in ai generate image web service | - | - | Low | 2.7 | 2026-09-30 08:36:13 | Deep Dive |
| CVE-2026-102582 | Moodle: manual enrolment page accessible when plugin disabled | - | - | Low | 2.2 | 2026-09-30 08:36:11 | Deep Dive |
| CVE-2026-102581 | Moodle: xss in forum post templates due to insufficient escaping | - | - | Medium | 4.6 | 2026-09-30 08:36:08 | Deep Dive |
| CVE-2026-102580 | Moodle: arbitrary class instantiation via report builder audience classname | - | - | Low | 2.2 | 2026-09-30 08:36:06 | Deep Dive |
| CVE-2026-102579 | Moodle: user profile information disclosure via grade web service | - | - | Medium | 4.3 | 2026-09-30 08:36:04 | Deep Dive |
| CVE-2026-102578 | Moodle: sql injection in question bank web service | - | - | Medium | 5.5 | 2026-09-30 08:36:02 | Deep Dive |
| CVE-2026-102577 | Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass | - | - | Medium | 4.3 | 2026-09-30 08:36:00 | Deep Dive |
| CVE-2026-102459 | DigiWin|EasyFlow .NET - Reflected Cross-site Scripting | DigiWin | EasyFlow .NET | Medium | 6.1 | 2026-09-30 08:35:41 | Deep Dive |
| CVE-2026-102458 | DigiWin|EasyFlow .NET - Missing Authentication | DigiWin | EasyFlow .NET | Critical | 9.8 | 2026-09-30 08:34:10 | Deep Dive |
| CVE-2026-102457 | DigiWin|EasyFlow .NET - Arbitrary File Read | DigiWin | EasyFlow .NET | Medium | 6.5 | 2026-09-30 08:32:38 | Deep Dive |
| CVE-2026-102456 | DigiWin|EasyFlow .NET - SQL Injection | DigiWin | EasyFlow .NET | Medium | 6.5 | 2026-09-30 08:30:48 | Deep Dive |
| CVE-2026-102455 | DigiWin|EasyFlow .NET - Insecure Deserialization | DigiWin | EasyFlow .NET | Critical | 9.8 | 2026-09-30 08:29:30 | Deep Dive |