Skip to content

2026-09-30 (Critical: 75, High: 153) #100

Description

@github-actions

CVE Daily Brief

Date: 2026-09-30

Summary

  • Total qualifying CVEs: 228
  • Critical: 75
  • High: 153
  • With GitHub PoC references: 76
  • In CISA KEV: 1

Critical

All Critical CVE details are preserved across this issue and managed follow-up comments.

High Index

  • 🟠 CVE-2026-97689 | CVSS 8.9 | urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can al… | PoC 3
  • 🟠 CVE-2026-102424 | CVSS 8.9 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2…
  • 🟠 CVE-2026-92222 | CVSS 8.9 | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside re…
  • 🟠 CVE-2026-92370 | CVSS 8.8 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows…
  • 🟠 CVE-2026-102712 | CVSS 8.8 | On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the t… | PoC 1
  • 🟠 CVE-2026-102713 | CVSS 8.8 | The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and… | PoC 1
  • 🟠 CVE-2026-84421 | CVSS 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validatio…
  • 🟠 CVE-2026-95282 | CVSS 8.8 | Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox v…
  • 🟠 CVE-2026-95286 | CVSS 8.8 | Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox v…
  • 🟠 CVE-2026-95304 | CVSS 8.8 | Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi…
  • 🟠 CVE-2026-95306 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a c…
  • 🟠 CVE-2026-95338 | CVSS 8.8 | Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via…
  • 🟠 CVE-2026-95343 | CVSS 8.8 | Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox v…
  • 🟠 CVE-2026-95345 | CVSS 8.8 | Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via…
  • 🟠 CVE-2026-95353 | CVSS 8.8 | Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox v…
  • 🟠 CVE-2026-95362 | CVSS 8.8 | Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to b…
  • 🟠 CVE-2026-95365 | CVSS 8.8 | Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside…
  • 🟠 CVE-2026-95369 | CVSS 8.8 | Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code…
  • 🟠 CVE-2026-95373 | CVSS 8.8 | Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbit…
  • 🟠 CVE-2026-95380 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute…
  • 🟠 CVE-2026-102299 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a c…
  • 🟠 CVE-2026-102302 | CVSS 8.8 | Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a…
  • 🟠 CVE-2026-102321 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a c…
  • 🟠 CVE-2026-102323 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a c…
  • 🟠 CVE-2026-102326 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a c…
  • 🟠 CVE-2026-102328 | CVSS 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a c…
  • 🟠 CVE-2026-67993 | CVSS 8.8 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credent… | PoC 2
  • 🟠 CVE-2026-71971 | CVSS 8.8 | U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in… | PoC 3
  • 🟠 CVE-2026-74220 | CVSS 8.8 | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memo… | PoC 3
  • 🟠 CVE-2026-74221 | CVSS 8.8 | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server respon… | PoC 3
  • 🟠 CVE-2026-74222 | CVSS 8.8 | U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When… | PoC 3
  • 🟠 CVE-2026-103105 | CVSS 8.8 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an atta…
  • 🟠 CVE-2026-85573 | CVSS 8.8 | The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files…
  • 🟠 CVE-2026-92994 | CVSS 8.8 | The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file stor…
  • 🟠 CVE-2026-94076 | CVSS 8.8 | Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
  • 🟠 CVE-2026-94121 | CVSS 8.8 | Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
  • 🟠 CVE-2026-94678 | CVSS 8.8 | Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
  • 🟠 CVE-2026-94683 | CVSS 8.8 | Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
  • 🟠 CVE-2026-95531 | CVSS 8.8 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
  • 🟠 CVE-2026-96831 | CVSS 8.8 | Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
  • 🟠 CVE-2026-96837 | CVSS 8.8 | Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
  • 🟠 CVE-2026-96838 | CVSS 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verificatio…
  • 🟠 CVE-2026-18783 | CVSS 8.8 | Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication… | PoC 1
  • 🟠 CVE-2022-51019 | CVSS 8.7 | Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter… | PoC 5
  • 🟠 CVE-2026-102634 | CVSS 8.7 | SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mo… | PoC 5
  • 🟠 CVE-2026-102716 | CVSS 8.7 | An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser ca… | PoC 1
  • 🟠 CVE-2026-102718 | CVSS 8.7 | hey, _nx_snmp_utility_object_id_get in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer si… | PoC 1
  • 🟠 CVE-2026-102810 | CVSS 8.7 | Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated atta… | PoC 4
  • 🟠 CVE-2026-102811 | CVSS 8.7 | Marmite through 0.4.2 contains missing authentication in the development server endpoints /marmite/content, /marmite/config, and /_… | PoC 5
  • 🟠 CVE-2026-100292 | CVSS 8.7 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing addi…
  • 🟠 CVE-2026-100293 | CVSS 8.7 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic…
  • 🟠 CVE-2026-100294 | CVSS 8.7 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed dev…
  • 🟠 CVE-2026-100298 | CVSS 8.7 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under co…
  • 🟠 CVE-2026-61519 | CVSS 8.7 | Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to inv… | PoC 3
  • 🟠 CVE-2026-102253 | CVSS 8.7 | iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the ser… | PoC 2
  • 🟠 CVE-2026-94204 | CVSS 8.7 | The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted acce… | PoC 1
  • 🟠 CVE-2026-103042 | CVSS 8.7 | LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allow… | PoC 5
  • 🟠 CVE-2026-103043 | CVSS 8.7 | anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic… | PoC 3
  • 🟠 CVE-2026-81433 | CVSS 8.7 | A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated atta…
  • 🟠 CVE-2026-86104 | CVSS 8.7 | An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to…
  • 🟠 CVE-2026-103055 | CVSS 8.7 | AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_… | PoC 4
  • 🟠 CVE-2026-86134 | CVSS 8.7 | A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to…
  • 🟠 CVE-2026-92867 | CVSS 8.7 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination…
  • 🟠 CVE-2026-92870 | CVSS 8.7 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process term…
  • 🟠 CVE-2026-92871 | CVSS 8.7 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of…
  • 🟠 CVE-2026-102509 | CVSS 8.7 | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation…
  • 🟠 CVE-2026-102510 | CVSS 8.7 | Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go impl…
  • 🟠 CVE-2026-103235 | CVSS 8.7 | MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation… | PoC 1
  • 🟠 CVE-2026-10764 | CVSS 8.7 | Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.
  • 🟠 CVE-2026-76992 | CVSS 8.7 | The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An un…
  • 🟠 CVE-2026-103270 | CVSS 8.7 | LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated a… | PoC 4
  • 🟠 CVE-2026-47097 | CVSS 8.7 | AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensi…
  • 🟠 CVE-2026-101127 | CVSS 8.6 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint va…
  • 🟠 CVE-2026-102556 | CVSS 8.6 | A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByte…
  • 🟠 CVE-2026-102557 | CVSS 8.6 | A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total messag…
  • 🟠 CVE-2026-102242 | CVSS 8.6 | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 thro… | PoC 1
  • 🟠 CVE-2026-102558 | CVSS 8.6 | A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray ba…
  • 🟠 CVE-2026-102559 | CVSS 8.6 | A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GBy…
  • 🟠 CVE-2026-102560 | CVSS 8.6 | A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calcu…
  • 🟠 CVE-2026-102730 | CVSS 8.6 | Mounting an attacker-controlled NAND flash image (lx_nand_flash_open()) triggers an unbounded out-of-bounds heap write in LevelX's NA… | PoC 1
  • 🟠 CVE-2026-102317 | CVSS 8.6 | Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute…
  • 🟠 CVE-2026-102876 | CVSS 8.6 | SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surrea… | PoC 5
  • 🟠 CVE-2026-102878 | CVSS 8.6 | mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS res… | PoC 3
  • 🟠 CVE-2026-18145 | CVSS 8.6 | A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker w…
  • 🟠 CVE-2026-103101 | CVSS 8.6 | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to…
  • 🟠 CVE-2026-103102 | CVSS 8.6 | Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigg…
  • 🟠 CVE-2026-102911 | CVSS 8.6 | A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_c… | PoC 5
  • 🟠 CVE-2026-97150 | CVSS 8.6 | When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP c… | PoC 1
  • 🟠 CVE-2026-102454 | CVSS 8.6 | EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell…
  • 🟠 CVE-2026-103239 | CVSS 8.6 | MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted… | PoC 1
  • 🟠 CVE-2026-103398 | CVSS 8.6 | OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specif… | PoC 4
  • 🟠 CVE-2026-102697 | CVSS 8.5 | Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mec… | PoC 5
  • 🟠 CVE-2026-102757 | CVSS 8.5 | An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode… | PoC 1
  • 🟠 CVE-2026-102875 | CVSS 8.5 | VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vl…
  • 🟠 CVE-2026-63713 | CVSS 8.5 | The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulne… | PoC 1
  • 🟠 CVE-2026-68068 | CVSS 8.5 | The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time… | PoC 1
  • 🟠 CVE-2026-68954 | CVSS 8.5 | The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vul… | PoC 1
  • 🟠 CVE-2026-72507 | CVSS 8.5 | The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind… | PoC 1
  • 🟠 CVE-2026-72510 | CVSS 8.5 | The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. | PoC 1
  • 🟠 CVE-2026-102792 | CVSS 8.5 | A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The… | PoC 1
  • 🟠 CVE-2026-102793 | CVSS 8.5 | A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_… | PoC 1
  • 🟠 CVE-2026-102794 | CVSS 8.5 | A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. S… | PoC 1
  • 🟠 CVE-2026-102511 | CVSS 8.5 | Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an…
  • 🟠 CVE-2026-10739 | CVSS 8.5 | Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper valida…
  • 🟠 CVE-2026-94115 | CVSS 8.5 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
  • 🟠 CVE-2026-94177 | CVSS 8.5 | Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
  • 🟠 CVE-2026-97287 | CVSS 8.5 | Contributor SQL Injection in Event Tickets <= 5.29.5 versions.
  • 🟠 CVE-2026-97293 | CVSS 8.5 | Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
  • 🟠 CVE-2026-100308 | CVSS 8.4 | Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to… | PoC 2
  • 🟠 CVE-2026-102709 | CVSS 8.4 | Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker execut… | PoC 1
  • 🟠 CVE-2026-102676 | CVSS 8.3 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, a… | PoC 5
  • 🟠 CVE-2026-102760 | CVSS 8.3 | When NetX Secure is built with NX_SECURE_KEY_CLEAR, every TLS record sent on an active session is wiped after it has been handed to TCP.… | PoC 1
  • 🟠 CVE-2026-95274 | CVSS 8.3 | Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer pro…
  • 🟠 CVE-2026-95276 | CVSS 8.3 | Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc…
  • 🟠 CVE-2026-95319 | CVSS 8.3 | Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po…
  • 🟠 CVE-2026-95322 | CVSS 8.3 | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer…
  • 🟠 CVE-2026-95334 | CVSS 8.3 | Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rend…
  • 🟠 CVE-2026-95335 | CVSS 8.3 | Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potenti…
  • 🟠 CVE-2026-95341 | CVSS 8.3 | Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer pro…
  • 🟠 CVE-2026-95348 | CVSS 8.3 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to p…
  • 🟠 CVE-2026-95351 | CVSS 8.3 | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execu…
  • 🟠 CVE-2026-95354 | CVSS 8.3 | Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po…
  • 🟠 CVE-2026-95355 | CVSS 8.3 | Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the r…
  • 🟠 CVE-2026-95372 | CVSS 8.3 | Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to…
  • 🟠 CVE-2026-95381 | CVSS 8.3 | Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer pr…
  • 🟠 CVE-2026-102301 | CVSS 8.3 | Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to po…
  • 🟠 CVE-2026-102324 | CVSS 8.3 | Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer proce…
  • 🟠 CVE-2026-96274 | CVSS 8.3 | In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contai…
  • 🟠 CVE-2026-103237 | CVSS 8.3 | MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribut… | PoC 1
  • 🟠 CVE-2026-103321 | CVSS 8.3 | MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was ac… | PoC 1
  • 🟠 CVE-2026-84782 | CVSS 8.2 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The re… | PoC 4
  • 🟠 CVE-2026-102633 | CVSS 8.2 | libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when comput… | PoC 4
  • 🟠 CVE-2026-102673 | CVSS 8.2 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.… | PoC 5
  • 🟠 CVE-2026-102674 | CVSS 8.2 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, a… | PoC 5
  • 🟠 CVE-2026-92227 | CVSS 8.2 | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature…
  • 🟠 CVE-2026-102555 | CVSS 8.2 | A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings…
  • 🟠 CVE-2026-102762 | CVSS 8.2 | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of pa… | PoC 1
  • 🟠 CVE-2026-13224 | CVSS 8.2 | A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary fi…
  • 🟠 CVE-2026-86128 | CVSS 8.2 | A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to ca…
  • 🟠 CVE-2026-86132 | CVSS 8.2 | An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the…
  • 🟠 CVE-2026-86133 | CVSS 8.2 | An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial I…
  • 🟠 CVE-2026-93621 | CVSS 8.2 | Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
  • 🟠 CVE-2026-96817 | CVSS 8.2 | Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
  • 🟠 CVE-2026-102984 | CVSS 8.2 | Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header,… | PoC 4
  • 🟠 CVE-2026-84842 | CVSS 8.1 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenti…
  • 🟠 CVE-2026-95301 | CVSS 8.1 | Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc…
  • 🟠 CVE-2026-95333 | CVSS 8.1 | Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox v…
  • 🟠 CVE-2026-102826 | CVSS 8.1 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScrip… | PoC 4
  • 🟠 CVE-2026-102827 | CVSS 8.1 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScrip… | PoC 4
  • 🟠 CVE-2026-102831 | CVSS 8.1 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From Jupyte… | PoC 5
  • 🟠 CVE-2026-76726 | CVSS 8.1 | An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to b…
  • 🟠 CVE-2026-93994 | CVSS 8.1 | Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schem…
  • 🟠 CVE-2026-95376 | CVSS 8.0 | Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineer…

Notes

  • PoC links are collected from NVD references and GitHub repository search. They are untrusted and may include unsafe code.
  • Critical CVE details may span multiple managed comments to guarantee completeness without exceeding GitHub issue size limits.

Activity

github-actions commented on Sep 30, 2026

@github-actions
Author

Critical Details (2026-09-30) - Part 1

🔴 CVE-2026-96587 | CVSS 10.0 | CRITICAL

Summary: The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
Published: 2026-09-29T21:19:39.987
Last Modified: 2026-09-29T22:19:05.860
Affected: Viidure Dashcam Android Application
CWE: CWE-798
GitHub PoC:


🔴 CVE-2026-71379 | CVSS 10.0 | CRITICAL

Summary: The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
Published: 2026-09-29T22:18:21.560
Last Modified: 2026-09-30T16:46:43.953
Affected: Toptech Systems TMS7, Toptech Systems TopHAT
CWE: CWE-552
GitHub PoC:


🔴 CVE-2026-96349 | CVSS 10.0 | CRITICAL

Summary: Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Published: 2026-09-30T13:17:29.967
Last Modified: 2026-09-30T14:18:09.253
Affected: SiteSkite SiteSkite
CWE: CWE-94
References:


🔴 CVE-2026-76570 | CVSS 10.0 | CRITICAL

Summary: Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated…
Published: 2026-09-30T15:22:34.903
Last Modified: 2026-09-30T16:44:39.840
Affected: joomcode.com JCTables extension for Joomla
CWE: CWE-89
GitHub PoC:


🔴 CVE-2026-77177 | CVSS 9.8 | CRITICAL

Summary: Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
Published: 2026-09-29T16:17:11.363
Last Modified: 2026-09-30T17:32:07.107
Affected: n/a n/a
CWE: CWE-94
GitHub PoC:


🔴 CVE-2026-39117 | CVSS 9.8 | CRITICAL

Summary: An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php
Published: 2026-09-29T20:17:20.130
Last Modified: 2026-09-29T21:28:02.477
Affected: n/a n/a
CWE: CWE-94
References:


🔴 CVE-2026-76721 | CVSS 9.8 | CRITICAL

Summary: Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
Published: 2026-09-29T20:17:24.073
Last Modified: 2026-09-29T21:39:02.570
Affected: Hewlett Packard Enterprise (HPE) Instant ON
References:


🔴 CVE-2026-76722 | CVSS 9.8 | CRITICAL

Summary: Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
Published: 2026-09-29T20:17:24.207
Last Modified: 2026-09-29T21:39:02.570
Affected: Hewlett Packard Enterprise (HPE) Instant ON
References:


🔴 CVE-2026-79538 | CVSS 9.8 | CRITICAL

Summary: metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
Published: 2026-09-29T20:17:27.510
Last Modified: 2026-09-29T21:28:02.477
Affected: n/a n/a
CWE: CWE-94
GitHub PoC:


🔴 CVE-2026-94952 | CVSS 9.8 | CRITICAL

Summary: A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition…
Published: 2026-09-29T21:19:39.433
Last Modified: 2026-09-30T17:16:51.753
Affected: n/a n/a
CWE: CWE-121
GitHub PoC:


🔴 CVE-2026-103110 | CVSS 9.8 | CRITICAL

Summary: Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
Published: 2026-09-30T04:18:29.077
Last Modified: 2026-09-30T16:44:39.840
Affected: Pexip Infinity
CWE: CWE-787
References:


🔴 CVE-2026-75873 | CVSS 9.8 | CRITICAL

Summary: The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.
Published: 2026-09-30T06:17:04.670
Last Modified: 2026-09-30T16:28:31.510
Affected: Unknown Zella Theme
CWE: CWE-434
References:


🔴 CVE-2026-88920 | CVSS 9.8 | CRITICAL

Summary: An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix…
Published: 2026-09-30T12:17:14.203
Last Modified: 2026-09-30T20:17:35.737
Affected: Apache Software Foundation Apache WSS4J
CWE: CWE-287
References:


🔴 CVE-2026-76504 | CVSS 9.8 | CRITICAL

Summary: A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request…
Published: 2026-09-30T13:17:20.247
Last Modified: 2026-09-30T19:02:05.223
Affected: Cisco Cisco Catalyst SD-WAN Manager
CWE: CWE-177
CISA KEV: Yes | Action due 2026-10-03
GitHub PoC:


🔴 CVE-2026-96350 | CVSS 9.8 | CRITICAL

Summary: Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
Published: 2026-09-30T13:17:30.090
Last Modified: 2026-09-30T14:18:09.523
Affected: Estatik Estatik
CWE: CWE-266
References:


🔴 CVE-2026-97248 | CVSS 9.8 | CRITICAL

Summary: Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
Published: 2026-09-30T13:17:36.830
Last Modified: 2026-09-30T14:18:15.890
Affected: Booking Activities Team Booking Activities
CWE: CWE-502
References:


🔴 CVE-2026-97274 | CVSS 9.8 | CRITICAL

Summary: Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
Published: 2026-09-30T13:17:38.293
Last Modified: 2026-09-30T14:18:17.173
Affected: miniOrange OAuth Single Sign On – SSO (OAuth Client)
CWE: CWE-290
References:


🔴 CVE-2026-82307 | CVSS 9.8 | CRITICAL

Summary: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
Published: 2026-09-30T14:17:31.257
Last Modified: 2026-09-30T16:18:57.403
Affected: Dolusoft Software Technologies SOPLOG
CWE: CWE-89
References:


🔴 CVE-2026-18782 | CVSS 9.8 | CRITICAL

Summary: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
Published: 2026-09-30T15:22:30.177
Last Modified: 2026-09-30T16:18:57.403
Affected: Trex Digital Smart Manufacturing Systems Inc. Trex MES
CWE: CWE-89
GitHub PoC:


🔴 CVE-2026-95277 | CVSS 9.6 | CRITICAL

Summary: Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T18:17:19.037
Last Modified: 2026-09-30T16:32:35.970
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95281 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:19.507
Last Modified: 2026-09-30T20:17:33.190
Affected: Google Chrome
CWE: CWE-122
References:


🔴 CVE-2026-95283 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T18:17:19.733
Last Modified: 2026-09-30T15:03:31.203
Affected: Google Chrome
CWE: CWE-122
References:


🔴 CVE-2026-95299 | CVSS 9.6 | CRITICAL

Summary: Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T18:17:21.837
Last Modified: 2026-09-30T19:52:52.697
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95310 | CVSS 9.6 | CRITICAL

Summary: Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:23.110
Last Modified: 2026-09-30T20:30:00.607
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95311 | CVSS 9.6 | CRITICAL

Summary: Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29T18:17:23.227
Last Modified: 2026-09-30T20:29:43.237
Affected: Google Chrome
CWE: CWE-590
References:


🔴 CVE-2026-95313 | CVSS 9.6 | CRITICAL

Summary: Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:23.463
Last Modified: 2026-09-30T16:29:46.163
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95318 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T18:17:24.060
Last Modified: 2026-09-30T16:29:20.837
Affected: Google Chrome
CWE: CWE-122
References:


🔴 CVE-2026-95325 | CVSS 9.6 | CRITICAL

Summary: Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29T18:17:24.873
Last Modified: 2026-09-30T16:28:25.810
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95329 | CVSS 9.6 | CRITICAL

Summary: Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:25.330
Last Modified: 2026-09-30T14:59:03.010
Affected: Google Chrome
CWE: CWE-787
References:


🔴 CVE-2026-95331 | CVSS 9.6 | CRITICAL

Summary: Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29T18:17:25.563
Last Modified: 2026-09-30T16:28:12.867
Affected: Google Chrome
CWE: CWE-787
References:


🔴 CVE-2026-95339 | CVSS 9.6 | CRITICAL

Summary: Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:26.480
Last Modified: 2026-09-30T16:27:32.400
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95347 | CVSS 9.6 | CRITICAL

Summary: Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29T18:17:27.580
Last Modified: 2026-09-30T16:27:01.180
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95349 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:27.807
Last Modified: 2026-09-30T13:41:47.087
Affected: Google Chrome
CWE: CWE-122
References:


🔴 CVE-2026-95350 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:27.920
Last Modified: 2026-09-30T14:05:58.473
Affected: Google Chrome
CWE: CWE-122
References:


🔴 CVE-2026-95356 | CVSS 9.6 | CRITICAL

Summary: Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:28.647
Last Modified: 2026-09-30T16:25:44.097
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-95357 | CVSS 9.6 | CRITICAL

Summary: Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T18:17:28.760
Last Modified: 2026-09-30T14:03:52.643
Affected: Google Chrome
CWE: CWE-787
References:


🔴 CVE-2026-102304 | CVSS 9.6 | CRITICAL

Summary: Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T20:17:13.327
Last Modified: 2026-09-30T04:18:23.210
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-102306 | CVSS 9.6 | CRITICAL

Summary: Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T20:17:13.573
Last Modified: 2026-09-30T16:32:11.237
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-102308 | CVSS 9.6 | CRITICAL

Summary: Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T20:17:13.810
Last Modified: 2026-09-30T16:25:33.630
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-102309 | CVSS 9.6 | CRITICAL

Summary: Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T20:17:13.933
Last Modified: 2026-09-30T16:25:23.430
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-102316 | CVSS 9.6 | CRITICAL

Summary: Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29T20:17:14.787
Last Modified: 2026-09-30T15:42:04.300
Affected: Google Chrome
CWE: CWE-416
References:


🔴 CVE-2026-102331 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29T20:17:16.587
Last Modified: 2026-09-30T13:15:08.430
Affected: Google Chrome
CWE: CWE-122
References:


🔴 CVE-2026-76723 | CVSS 9.6 | CRITICAL

Summary: Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Published: 2026-09-29T20:17:24.327
Last Modified: 2026-09-29T21:39:02.570
Affected: Hewlett Packard Enterprise (HPE) Instant ON
References:


🔴 CVE-2026-76724 | CVSS 9.6 | CRITICAL

Summary: A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on th…
Published: 2026-09-29T20:17:24.453
Last Modified: 2026-09-29T21:39:02.570
Affected: Hewlett Packard Enterprise (HPE) Instant ON
References:


🔴 CVE-2026-76725 | CVSS 9.6 | CRITICAL

Summary: A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code exec…
Published: 2026-09-29T20:17:24.580
Last Modified: 2026-09-29T21:39:02.570
Affected: Hewlett Packard Enterprise (HPE) Instant ON
References:


🔴 CVE-2026-102425 | CVSS 9.5 | CRITICAL

Summary: Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling eval(), the component replac…
Published: 2026-09-29T17:17:06.210
Last Modified: 2026-09-29T21:39:02.570
Affected: balbooa.com Balbooa Forms extension for Joomla
CWE: CWE-94
References:


🔴 CVE-2026-70356 | CVSS 9.4 | CRITICAL

Summary: The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
Published: 2026-09-29T22:18:16.140
Last Modified: 2026-09-30T16:46:43.953
Affected: Toptech Systems TMS7, Toptech Systems TopHAT
CWE: CWE-434
GitHub PoC:


🔴 CVE-2026-103056 | CVSS 9.4 | CRITICAL

Summary: AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_na…
Published: 2026-09-30T01:16:37.050
Last Modified: 2026-09-30T19:16:38.833
Affected: beenuar AiSOC
CWE: CWE-78
GitHub PoC:


🔴 CVE-2026-93903 | CVSS 9.4 | CRITICAL

Summary: LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
Published: 2026-09-30T14:17:37.060
Last Modified: 2026-09-30T17:23:08.953
Affected: litespeedtech LiteSpeed Web Server
CWE: CWE-174
References:


🔴 CVE-2023-54400 | CVSS 9.3 | CRITICAL

Summary: Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Micr…
Published: 2026-09-29T16:17:04.070
Last Modified: 2026-09-30T17:32:07.107
Affected: Fumasoft Fumeng Cloud
CWE: CWE-89
GitHub PoC:


🔴 CVE-2026-102710 | CVSS 9.3 | CRITICAL

Summary: Attacker model / Preconditions: a loaded TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION module issuing kernel dispatch calls, on a build with TX_ENABLE_EVENT_TRACE. A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly —…
Published: 2026-09-29T18:17:10.020
Last Modified: 2026-09-29T19:00:16.623
Affected: Eclipse Foundation eclipse-threadx/threadx
CWE: CWE-269, CWE-822
GitHub PoC:


🔴 CVE-2026-102761 | CVSS 9.3 | CRITICAL

Summary: NetX Duo's WebSocket client resets the unmasking cursor to the first NX_PACKET each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop thro…
Published: 2026-09-29T18:17:13.450
Last Modified: 2026-09-29T19:00:16.623
Affected: Eclipse Foundation NetX Duo
CWE: CWE-787
GitHub PoC:


🔴 CVE-2026-100291 | CVSS 9.3 | CRITICAL

Summary: In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
Published: 2026-09-29T20:17:09.300
Last Modified: 2026-09-29T22:17:04.057
Affected: Anjvision YSSD-RTMP-H5
CWE: CWE-1188
References:


🔴 CVE-2026-103040 | CVSS 9.3 | CRITICAL

Summary: LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to t…
Published: 2026-09-29T23:17:21.447
Last Modified: 2026-09-30T15:22:24.830
Affected: ModelTC LightLLM
CWE: CWE-502
GitHub PoC:


🔴 CVE-2026-103041 | CVSS 9.3 | CRITICAL

Summary: LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.
Published: 2026-09-29T23:17:21.630
Last Modified: 2026-09-30T14:17:26.160
Affected: ModelTC LightLLM
CWE: CWE-502
GitHub PoC:


🔴 CVE-2026-102455 | CVSS 9.3 | CRITICAL

Summary: EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Published: 2026-09-30T09:17:13.343
Last Modified: 2026-09-30T16:30:42.327
Affected: DigiWin EasyFlow .NET
CWE: CWE-502
References:


🔴 CVE-2026-102458 | CVSS 9.3 | CRITICAL

Summary: EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
Published: 2026-09-30T09:17:13.800
Last Modified: 2026-09-30T16:30:42.327
Affected: DigiWin EasyFlow .NET
CWE: CWE-306
References:


🔴 CVE-2026-74864 | CVSS 9.3 | CRITICAL

Summary: sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged…
Published: 2026-09-30T13:17:19.913
Last Modified: 2026-09-30T19:57:08.043
Affected: YunoHost-Apps sogo_yhn
CWE: CWE-639
References:


🔴 CVE-2026-96822 | CVSS 9.3 | CRITICAL

Summary: Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
Published: 2026-09-30T13:17:31.750
Last Modified: 2026-09-30T14:18:11.310
Affected: Hossni Mubarak Books Gallery
CWE: CWE-89
References:


🔴 CVE-2026-103395 | CVSS 9.3 | CRITICAL

Summary: LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with reduce methods to execute arbitrary code with service accou…
Published: 2026-09-30T15:22:27.710
Last Modified: 2026-09-30T20:17:30.840
Affected: ModelTC LightLLM
CWE: CWE-502
GitHub PoC:


🔴 CVE-2026-102828 | CVSS 9.2 | CRITICAL

Summary: simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer..cmd as unsafe configuration. An application that passes attacker-controlled va…
Published: 2026-09-29T19:17:25.207
Last Modified: 2026-09-30T19:56:45.443
Affected: steveukx git-js
CWE: CWE-78, CWE-184
GitHub PoC:


🔴 CVE-2026-102829 | CVSS 9.2 | CRITICAL

Summary: simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A…
Published: 2026-09-29T19:17:25.367
Last Modified: 2026-09-30T20:17:24.433
Affected: steveukx git-js
CWE: CWE-78, CWE-184
GitHub PoC:


🔴 CVE-2026-53988 | CVSS 9.2 | CRITICAL

Summary: Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests…
Published: 2026-09-29T20:17:20.403
Last Modified: 2026-09-30T17:32:07.107
Affected: Finsys dockhand
CWE: CWE-306
GitHub PoC:


🔴 CVE-2026-86131 | CVSS 9.2 | CRITICAL

Summary: A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Published: 2026-09-30T00:16:36.817
Last Modified: 2026-09-30T16:40:50.560
Affected: WatchGuard Fireware OS
CWE: CWE-94, CWE-295, CWE-829
References:


🔴 CVE-2026-102508 | CVSS 9.2 | CRITICAL

Summary: Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by t…
Published: 2026-09-30T08:16:31.903
Last Modified: 2026-09-30T16:14:10.347
Affected: Apache Software Foundation Apache PLC4X
CWE: CWE-295, CWE-347, CWE-757
References:


🔴 CVE-2026-74865 | CVSS 9.2 | CRITICAL

Summary: sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fix…
Published: 2026-09-30T13:17:20.083
Last Modified: 2026-09-30T19:57:08.043
Affected: YunoHost-Apps sogo_yhn
CWE: CWE-639
References:


🔴 CVE-2026-84436 | CVSS 9.1 | CRITICAL

Summary: IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
Published: 2026-09-29T18:17:17.823
Last Modified: 2026-09-30T04:18:33.010
Affected: IBM Guardium Data Protection
CWE: CWE-78
References:


🔴 CVE-2026-79537 | CVSS 9.1 | CRITICAL

Summary: metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint auth…
Published: 2026-09-29T20:17:27.383
Last Modified: 2026-09-30T17:32:07.107
Affected: n/a n/a
CWE: CWE-639
GitHub PoC:


🔴 CVE-2026-97196 | CVSS 9.1 | CRITICAL

Summary: Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
Published: 2026-09-30T07:16:31.320
Last Modified: 2026-09-30T14:18:14.160
Affected: Liquid Web / StellarWP GiveWP
CWE: CWE-1289
References:


🔴 CVE-2026-77185 | CVSS 9.1 | CRITICAL

Summary: Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authenticati…
Published: 2026-09-30T10:17:17.123
Last Modified: 2026-09-30T17:16:49.877
Affected: Apache Software Foundation Apache MINA SSHD
CWE: CWE-305
References:


🔴 CVE-2026-94052 | CVSS 9.1 | CRITICAL

Summary: A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and…
Published: 2026-09-30T10:17:18.147
Last Modified: 2026-09-30T16:13:13.493
Affected: Apache Software Foundation Apache MINA SSHD
CWE: CWE-304
References:


🔴 CVE-2026-94053 | CVSS 9.1 | CRITICAL

Summary: Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the s…
Published: 2026-09-30T10:17:18.283
Last Modified: 2026-09-30T16:13:13.493
Affected: Apache Software Foundation Apache MINA SSHD
CWE: CWE-90, CWE-305
References:


🔴 CVE-2026-87830 | CVSS 9.1 | CRITICAL

Summary: In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versi…
Published: 2026-09-30T12:17:14.087
Last Modified: 2026-09-30T20:17:35.183
Affected: Apache Software Foundation Apache WSS4J
CWE: CWE-917
References:


🔴 CVE-2026-89238 | CVSS 9.1 | CRITICAL

Summary: WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Published: 2026-09-30T13:17:21.587
Last Modified: 2026-09-30T20:17:35.917
Affected: Apache Software Foundation Apache WSS4J
CWE: CWE-345
References:


🔴 CVE-2026-94389 | CVSS 9.0 | CRITICAL

Summary: Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Published: 2026-09-30T13:17:26.840
Last Modified: 2026-09-30T14:17:49.070
Affected: AcyMailing Newsletter Team AcyMailing SMTP Newsletter
CWE: CWE-94
References:


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions