| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-70009 | Azure Arc Elevation of Privilege Vulnerability | Microsoft | Azure ARC | Critical | 9.3 | 2026-09-17 22:55:53 | Deep Dive |
| CVE-2026-54734 | Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction | prebid | prebid-server-java | Critical | 10.0 | 2026-09-17 21:59:46 | Deep Dive |
| CVE-2026-76949 | Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement | team-alembic | ash_authentication | Critical | 9.1 | 2026-09-17 21:57:50 | Deep Dive |
| CVE-2026-54767 | WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php | LabRedesCefetRJ | WeGIA | Critical | 9.1 | 2026-09-17 21:56:29 | Deep Dive |
| CVE-2026-54670 | WeGIA: Unauthenticated Auth Bypass + Local File Inclusion | LabRedesCefetRJ | WeGIA | Critical | 9.1 | 2026-09-17 21:54:43 | Deep Dive |
| CVE-2026-54501 | Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors | webrecorder | browsertrix | Critical | 9.4 | 2026-09-17 20:15:14 | Deep Dive |
| CVE-2026-54237 | Wavelog: Unauthenticated Remote Code Execution | wavelog | wavelog | Critical | 9.3 | 2026-09-17 20:14:10 | Deep Dive |
| CVE-2026-45140 | Chamilo LMS CStudio upload flow allows unauthenticated remote code execution | chamilo | chamilo-lms | Critical | 9.8 | 2026-09-17 20:11:52 | Deep Dive |
| CVE-2026-45143 | Chamilo LMS: Student-to-admin stored XSS in private messages via v-html | chamilo | chamilo-lms | Critical | 9.0 | 2026-09-17 20:09:58 | Deep Dive |
| CVE-2026-54460 | OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover | open-reception | appointment-booking-software | Critical | 9.8 | 2026-09-17 20:07:25 | Deep Dive |
| CVE-2026-54752 | NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request | netbox-community | devicetype-library | Critical | 9.6 | 2026-09-17 19:56:16 | Deep Dive |
| CVE-2026-54627 | SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) | HappySeaFox | sail | Critical | 9.8 | 2026-09-17 19:47:14 | Deep Dive |
| CVE-2026-54626 | SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) | HappySeaFox | sail | Critical | 9.8 | 2026-09-17 19:46:20 | Deep Dive |
| CVE-2026-54618 | Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user | jimprosser | obsidian-web-mcp | Critical | 9.4 | 2026-09-17 19:45:15 | Deep Dive |
| CVE-2026-54617 | GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler | GravitLauncher | Launcher | Critical | 9.8 | 2026-09-17 18:34:41 | Deep Dive |
| CVE-2026-47252 | Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) | julien040 | anyquery | Critical | 9.0 | 2026-09-17 18:17:44 | Deep Dive |
| CVE-2026-54053 | Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults | brufdev | many-notes | Critical | 9.6 | 2026-09-17 17:11:40 | Deep Dive |
| CVE-2026-92489 | xfrm: Fix skb double-free in xfrm_dev_direct_output() | Linux | Linux | Critical | 9.8 | 2026-09-17 16:10:04 | Deep Dive |
| CVE-2026-90414 | IB/isert: reject PDUs declaring more data than was received | Linux | Linux | Critical | 9.1 | 2026-09-17 16:09:40 | Deep Dive |
| CVE-2026-90413 | IB/isert: reject login PDUs declaring more data than was received | Linux | Linux | Critical | 9.1 | 2026-09-17 16:09:39 | Deep Dive |