| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-76732 | Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON | Hewlett Packard Enterprise (HPE) | Instant ON | Medium | 6.4 | 2026-09-29 19:28:50 | Deep Dive |
| CVE-2026-76731 | Authentication Bypass in the Captive Portal of HPE Networking Instant On | Hewlett Packard Enterprise (HPE) | Instant ON | Medium | 6.5 | 2026-09-29 19:28:48 | Deep Dive |
| CVE-2026-76730 | Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs | Hewlett Packard Enterprise (HPE) | Instant ON | Medium | 6.5 | 2026-09-29 19:28:46 | Deep Dive |
| CVE-2026-76729 | Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint | Hewlett Packard Enterprise (HPE) | Instant ON | Medium | 6.6 | 2026-09-29 19:28:45 | Deep Dive |
| CVE-2026-76728 | Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs | Hewlett Packard Enterprise (HPE) | Instant ON | High | 7.2 | 2026-09-29 19:28:43 | Deep Dive |
| CVE-2026-76727 | Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON | Hewlett Packard Enterprise (HPE) | Instant ON | High | 7.2 | 2026-09-29 19:28:42 | Deep Dive |
| CVE-2026-76726 | Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint | Hewlett Packard Enterprise (HPE) | Instant ON | High | 8.1 | 2026-09-29 19:28:40 | Deep Dive |
| CVE-2026-76725 | Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs | Hewlett Packard Enterprise (HPE) | Instant ON | Critical | 9.6 | 2026-09-29 19:28:39 | Deep Dive |
| CVE-2026-76724 | Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol | Hewlett Packard Enterprise (HPE) | Instant ON | Critical | 9.6 | 2026-09-29 19:28:38 | Deep Dive |
| CVE-2026-76723 | Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS | Hewlett Packard Enterprise (HPE) | Instant ON | Critical | 9.6 | 2026-09-29 19:28:36 | Deep Dive |
| CVE-2026-76722 | Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs | Hewlett Packard Enterprise (HPE) | Instant ON | Critical | 9.8 | 2026-09-29 19:28:34 | Deep Dive |
| CVE-2026-76721 | Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs | Hewlett Packard Enterprise (HPE) | Instant ON | Critical | 9.8 | 2026-09-29 19:28:33 | Deep Dive |
| CVE-2026-61519 | Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember() | Liberu Software | Liberu CRM | High | 8.8 | 2026-09-29 19:13:14 | Deep Dive |
| CVE-2026-102831 | JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard | jupyterlab | jupyterlab | High | 8.1 | 2026-09-29 18:58:04 | Deep Dive |
| CVE-2026-102830 | JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) | jupyterlab | jupyterlab | Medium | 6.8 | 2026-09-29 18:53:19 | Deep Dive |
| CVE-2026-102829 | simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection | steveukx | git-js | Critical | 9.2 | 2026-09-29 18:46:58 | Deep Dive |
| CVE-2026-102616 | risesoft-y9 WorkFlow-Engine OAuth2 Resource Filter CustomHistoricProcessServiceImpl.java getByIdAndYear sql injection | risesoft-y9 | WorkFlow-Engine | High | 7.3 | 2026-09-29 18:45:09 | Deep Dive |
| CVE-2026-102828 | simple-git unsafe-operation guard does not block trailer command configuration | steveukx | git-js | Critical | 9.2 | 2026-09-29 18:43:19 | Deep Dive |
| CVE-2026-102827 | simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291) | steveukx | git-js | High | 8.1 | 2026-09-29 18:39:58 | Deep Dive |
| CVE-2026-102826 | simple-git allows command execution through unblocked Git configuration includes | steveukx | git-js | High | 8.1 | 2026-09-29 18:37:10 | Deep Dive |