search
CVSS
Trends
- 1Three unpatched critical flaws disclosed in LightLLMโผ๐จ LightLLM Mass Disclosure โ 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) โ unauthenticated RCE, router profiler RPyC CVE
Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.
- 2Google Chrome patches critical memory flawโผ๐จ EUVD-2026-89143 ๐ Score: 9.6/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-09-29 | Updated: 2026
A critical vulnerability, EUVD-2026-89143, has been disclosed in Google Chrome with a CVSS score of 9.6. The flaw involves non-heap memory handling in the browser's Fonts component and could allow a remote attacker, working alongside social engineering, to potentially compromise systems. The fix is included in Chrome 154.0.8037.57, published 29 September 2026 and updated the following day. Security watchers are flagging the severity rating and urging users to update their browsers promptly.
- 3Two memory flaws found in CTranslate2 inference engineโผ๐จ CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in it
Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.
- 4Critical LightLLM flaw exposes AI servers to remote code executionโ๐จ CVE-2026-103041 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
- 5Estonian software vendor Iqbal praised for flawless patch recordโIqbal (Estonia) holds 34 CVEs, max CVSS 9.9, yet 0 percent unpatched and zero CISA KEV. Trust score A. Vulnerability vol
Estonia-based software vendor Iqbal has accumulated 34 CVEs, including vulnerabilities with severity scores as high as 9.9, yet shows zero unpatched issues and no entries in CISA's Known Exploited Vulnerabilities catalog. Security observers highlight its A trust score and declining vulnerability volume as evidence of unusually disciplined patch hygiene, noting few vendors maintain such a record.
- 6High-Severity Flaw Reported in Pexip Infinity Video Conferencing Platformโ๐ CVE-2026-103101 - High (8.6) Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in
A high-severity vulnerability, CVE-2026-103101 with a CVSS score of 8.6, affects Pexip Infinity versions 30.0 through 40.x before 41.0. The flaw stems from improper input validation in the web server component and could allow a malicious attacker to render a Pexip Infinity node inaccessible, disrupting video conferencing services. Administrators are being urged to update to version 41.0 or later to close the gap.
- 7Critical command injection flaw found in Ziroom ZHOME smart home appโCVE-2026-102794: Ziroom ZHOME A0101 v1.0.1.0 is affected by a CRITICAL command injection flaw (CVSS 9.1) in /api/ZRnetwo
A critical vulnerability, tracked as CVE-2026-102794, has been disclosed in Ziroom ZHOME A0101 version 1.0.1.0. The command injection flaw, rated 9.1 on the CVSS scale, sits in the /api/ZRnetwork/ping endpoint. No patch is available and a public exploit already exists, so users are being urged to restrict access to affected devices and monitor their usage while awaiting a fix from Ziroom.
- 8Critical RCE vulnerability disclosed in LightLLMโ๐จ CVE-2026-103040 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the route
A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.
- 9Critical CVSS 10 flaw CVE-2026-71379 allows unauthenticated data exportโ๐จ CVE-2026-71379 โ CVSS 10 CRITICAL The file export endpoint allows any unauthenticated attacker to export arbitrary dat
A vulnerability tracked as CVE-2026-71379, rated CVSS 10, is drawing attention in the cybersecurity community. The flaw lies in a file export endpoint that lets any unauthenticated attacker export arbitrary database tables via a crafted POST request. Security feeds are flagging it as maximum-severity, urging organizations to check whether their systems are affected and patch promptly.
- 10Critical CVE-2026-70356 flagged in TMS file upload endpointโ๐จ CVE-2026-70356 โ CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, a
A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.
- 11Critical buffer overflow flaw reported in Chrome for Androidโ๐จ CVE-2026-95281 โ CVSS 9.6 CRITICAL Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allo
A critical vulnerability, tracked as CVE-2026-95281, has been disclosed in Google Chrome on Android. The buffer overflow in the ANGLE graphics library, carrying a CVSS score of 9.6, affected Chrome versions before 154.0.8037.57 and could let a remote attacker run arbitrary code outside the sandbox through a crafted HTML page. Security researchers are urging Android users to update Chrome immediately.
- 12Microsoft patches high-severity Visual Studio heap overflow flawโผ๐จ EUVD-2026-73170 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: .NET 10.0, Microsoft Visual Studio 2022 version 17.14, Microsof
Microsoft's Visual Studio 2022 version 17.14, .NET 10.0 and .NET Framework 4.8 are affected by a vulnerability tracked as EUVD-2026-73170, rated 8.8 out of 10 on the CVSS v3.1 scale. The flaw is a heap-based buffer overflow in Visual Studio, and the advisory was published on 8 September 2026 with an update issued on 29 September 2026. Security trackers are flagging the high severity rating, urging developers using affected Microsoft products to check whether they need to update.
- 13Medium-severity vulnerability found in Naichen ThinkCMFโผ๐จ EUVD-2026-89477 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: ThinkCMF, ThinkCMF, ThinkCMF (+5 more) ๐ข Vendor: Naichen ๐ Upda
A security vulnerability, tracked as EUVD-2026-89477, has been identified in Naichen's ThinkCMF content management framework in versions up to 8.0.7. The flaw carries a CVSS v3.1 score of 5.1 out of 10, marking it as moderate severity. The advisory was updated on 29 September 2026, and multiple ThinkCMF product entries are listed as affected. Details of the vulnerable function remain limited in the published notice.
- 14High-severity command injection flaw fixed in Renovateโผ๐จ EUVD-2024-55728 ๐ Score: 8.4/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.
- 15Benchmark finds AI models inflate security vulnerability severityโEvery model (incl. Jev) we tested inflates security finding severity
Security firm Casco reports that every large language model it tested, including its own Jev model, inflated the severity of security findings when scoring vulnerabilities, overstating risk compared to expected CVSS ratings. The company published a benchmark detailing the results, prompting discussion about how far AI-generated severity scores can be trusted in security workflows.
- 16Renovate tool patched over remote code execution flawโ๐จ EUVD-2026-62467 ๐ Score: 6.8/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A medium-severity vulnerability, tracked as EUVD-2026-62467 with a CVSS score of 6.8, was disclosed in Renovate, the dependency update tool maintained by renovatebot. Versions from 43.65.0 before 43.102.11 contain a remote code execution flaw affecting the bazel-module and bazelisk managers. The advisory was published on 19 August 2026 and updated on 29 September, and administrators are urged to upgrade to a fixed release.
- 17Critical CVE-2026-102829 flaw reported in simple-gitโ๐จ CVE-2026-102829 โ CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.
- 18Critical vulnerability CVE-2026-102828 found in simple-git libraryโ๐จ CVE-2026-102828 โ CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102828 with a CVSS score of 9.2, has been disclosed in simple-git, a widely used Node.js library for running Git commands from JavaScript. Versions 3.15.0 through 4.0.1 are affected because the default blockUnsafeOperationsPlugin fails to classify certain trailer .cmd values, potentially allowing unsafe Git operations. Developers are being urged to check their dependency versions and update promptly.
- 19Critical Chrome GPU flaw CVE-2026-95357 flagged on Androidโ๐จ CVE-2026-95357 โ CVSS 9.6 CRITICAL Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 al
A critical vulnerability, CVE-2026-95357, has been disclosed affecting Google Chrome on Android versions prior to 154.0.8037.57. The out-of-bounds write in the GPU component carries a CVSS score of 9.6 and could let a remote attacker execute arbitrary code outside the browser sandbox via a crafted HTML page. Security experts are urging users to update Chrome immediately.
- 20Critical Chrome vulnerability CVE-2026-95356 flaggedโ๐จ CVE-2026-95356 โ CVSS 9.6 CRITICAL Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a re
Security researchers are flagging CVE-2026-95356, a critical use-after-free flaw in the WindowDialog component of Google Chrome. Versions prior to 154.0.8037.57 are affected. The bug carries a CVSS score of 9.6 and could let a remote attacker, using social engineering and a crafted HTML page, run arbitrary code outside the browser sandbox. Users are being urged to update Chrome promptly.
- 21Critical Chrome for Android flaw allows code execution outside sandboxโ๐จ CVE-2026-95350 โ CVSS 9.6 CRITICAL Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allo
A critical vulnerability, CVE-2026-95350, has been disclosed in Google Chrome on Android. The buffer overflow in ANGLE, affecting versions before 154.0.8037.57, carries a CVSS score of 9.6 and could let a remote attacker execute arbitrary code outside the browser sandbox via a crafted HTML page. Chromium rates it Critical. Users are urged to update Chrome on Android to the latest version.
- 22Critical Chrome WebGL flaw allows code execution on Androidโ๐จ CVE-2026-95349 โ CVSS 9.6 CRITICAL Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allo
A critical vulnerability, CVE-2026-95349, has been disclosed in Google Chrome on Android. The buffer overflow in WebGL, rated CVSS 9.6, affects versions prior to 154.0.8037.57 and could let a remote attacker run arbitrary code outside the sandbox through a crafted HTML page. Chromium has classified the flaw as a critical security issue, and users are urged to update their browsers promptly.