| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-103044 | EasyTimeline should not serve image maps as application/xml | The Wikimedia Foundation | Mediawiki - EasyTimeline extension | - | - | 2026-09-29 22:46:46 | Deep Dive |
| CVE-2026-102792 | Ziroom ZHOME A0101 set_syslog command injection | Ziroom | ZHOME A0101 | Critical | 9.1 | 2026-09-29 22:45:16 | Deep Dive |
| CVE-2026-103046 | WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML | The Wikimedia Foundation | Mediawiki - WikiLambda Extension | - | - | 2026-09-29 22:41:36 | Deep Dive |
| CVE-2026-102771 | Naichen ThinkCMF Email Template MailController.php templatePut special elements in template engine | Naichen | ThinkCMF | Medium | 4.7 | 2026-09-29 22:00:14 | Deep Dive |
| CVE-2026-71189 | Toptech TMS7 and TopHAT Cross-site Scripting | Toptech Systems | TMS7 | Low | 3.5 | 2026-09-29 21:46:48 | Deep Dive |
| CVE-2026-69662 | Toptech TMS7 and TopHAT Eval Injection | Toptech Systems | TMS7 | Low | 3.7 | 2026-09-29 21:44:08 | Deep Dive |
| CVE-2026-71302 | Toptech TMS7 and TopHAT Session Fixation | Toptech Systems | TMS7 | High | 7.1 | 2026-09-29 21:41:11 | Deep Dive |
| CVE-2026-72507 | Toptech TMS7 and TopHAT SQL Injection | Toptech Systems | TMS7 | Critical | 9.0 | 2026-09-29 21:36:54 | Deep Dive |
| CVE-2026-68068 | Toptech TMS7 and TopHAT SQL Injection | Toptech Systems | TMS7 | Critical | 9.0 | 2026-09-29 21:33:47 | Deep Dive |
| CVE-2026-68954 | Toptech TMS7 and TopHAT SQL Injection | Toptech Systems | TMS7 | Critical | 9.0 | 2026-09-29 21:32:06 | Deep Dive |
| CVE-2026-63713 | Toptech TMS7 and TopHAT SQL Injection | Toptech Systems | TMS7 | Critical | 9.0 | 2026-09-29 21:30:33 | Deep Dive |
| CVE-2026-102621 | Freedesktop Poppler SplashClip.cc clipToPath integer overflow | Freedesktop | Poppler | Low | 3.3 | 2026-09-29 21:30:12 | Deep Dive |
| CVE-2026-74225 | U-Boot before 2026.10-rc5 Out-of-Bounds Write via DHCPv6 | u-boot | u-boot | High | 7.1 | 2026-09-29 21:29:25 | Deep Dive |
| CVE-2026-74222 | U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:24 | Deep Dive |
| CVE-2026-74221 | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:23 | Deep Dive |
| CVE-2026-74220 | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:23 | Deep Dive |
| CVE-2026-71974 | U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition Read | u-boot | u-boot | Medium | 4.8 | 2026-09-29 21:29:22 | Deep Dive |
| CVE-2026-71973 | U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation | u-boot | u-boot | Medium | 5.2 | 2026-09-29 21:29:21 | Deep Dive |
| CVE-2026-71972 | U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder | u-boot | u-boot | Medium | 5.9 | 2026-09-29 21:29:21 | Deep Dive |
| CVE-2026-71971 | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:20 | Deep Dive |