| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-74222 | U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:24 | Deep Dive |
| CVE-2026-74221 | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:23 | Deep Dive |
| CVE-2026-74220 | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:23 | Deep Dive |
| CVE-2026-71974 | U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition Read | u-boot | u-boot | Medium | 4.8 | 2026-09-29 21:29:22 | Deep Dive |
| CVE-2026-71973 | U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation | u-boot | u-boot | Medium | 5.2 | 2026-09-29 21:29:21 | Deep Dive |
| CVE-2026-71972 | U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder | u-boot | u-boot | Medium | 5.9 | 2026-09-29 21:29:21 | Deep Dive |
| CVE-2026-71971 | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly | u-boot | u-boot | High | 8.2 | 2026-09-29 21:29:20 | Deep Dive |
| CVE-2026-72510 | Toptech TMS7 and TopHAT SQL Injection | Toptech Systems | TMS7 | Critical | 9.0 | 2026-09-29 21:28:27 | Deep Dive |
| CVE-2026-70356 | Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type | Toptech Systems | TMS7 | Critical | 9.1 | 2026-09-29 21:26:23 | Deep Dive |
| CVE-2026-71379 | Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties | Toptech Systems | TMS7 | Critical | 10.0 | 2026-09-29 21:23:25 | Deep Dive |
| CVE-2026-91191 | Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature | Lantronix | G520 Series | High | 7.5 | 2026-09-29 21:04:53 | Deep Dive |
| CVE-2026-84409 | Lantronix G520 Series Cellular Gateway Cross-site Scripting | Lantronix | G520 Series | High | 7.5 | 2026-09-29 21:02:10 | Deep Dive |
| CVE-2026-102938 | virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection | pypa | virtualenv | Medium | 5.8 | 2026-09-29 20:58:21 | Deep Dive |
| CVE-2026-102937 | virtualenv: Command injection via --prompt in activate.bat (batch activator) | pypa | virtualenv | High | 7.3 | 2026-09-29 20:56:14 | Deep Dive |
| CVE-2026-93853 | Barman snapshot backup deletion trusts unverified backup catalog metadata | EnterpriseDB | Barman | High | 7.2 | 2026-09-29 20:55:52 | Deep Dive |
| CVE-2026-102930 | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use | pypa | virtualenv | High | 7.7 | 2026-09-29 20:53:36 | Deep Dive |
| CVE-2026-102925 | virtualenv bash and fish activation scripts execute commands embedded in paths | pypa | virtualenv | High | 7.8 | 2026-09-29 20:50:57 | Deep Dive |
| CVE-2026-81842 | Library panel can be moved into a folder without library panel create permission | Grafana | Grafana Enterprise | Medium | 4.3 | 2026-09-29 20:50:01 | Deep Dive |
| CVE-2026-102904 | JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs | jupyterlab | jupyterlab | Medium | 5.4 | 2026-09-29 20:47:43 | Deep Dive |
| CVE-2026-96587 | Use of Hard-coded Credentials in Viidure Dashcam Android Application | Viidure | Dashcam Android Application | Critical | 10.0 | 2026-09-29 20:42:38 | Deep Dive |