MikeTrendsTrends right now

search

CVSS

Trends

  1. 1
    GitLab patches critical AI Gateway flaw allowing command executionโ—๐Ÿค– GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform accessMmastodonTechnologyCybersecurity12 h ago

    GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.

  2. 2
    OpenTelemetry JavaScript instrumentation libraries flagged in new vulnerability advisoryโ–ผ๐Ÿšจ EUVD-2026-91788 ๐Ÿ“Š Score: 5.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: instrumentation-cassandra-driver, instrumentation-pg, instrumenMmastodonTechnologyCybersecurity09 h ago

    A medium-severity vulnerability, EUVD-2026-91788, has been catalogued affecting several OpenTelemetry JavaScript Contrib instrumentation packages, including instrumentation-cassandra-driver, instrumentation-pg and instrumentation-tedious. The flaw carries a CVSS v3.1 score of 5.8 out of 10 and was updated on 2 October 2026. Security teams monitoring dependencies in Node.js applications are likely reviewing whether their projects use the affected OpenTelemetry packages.

  3. 3
    Low-severity directory traversal flaw patched in Trivy scannerโ–ผ๐Ÿšจ EUVD-2026-91789 ๐Ÿ“Š Score: 2.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: trivy ๐Ÿข Vendor: aquasec ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ Trivy before 0.MmastodonTechnologyCybersecurity09 h ago

    A new vulnerability listing, EUVD-2026-91789, describes a directory traversal issue in Aqua Security's Trivy vulnerability scanner. Versions before 0.71.0 allow path traversal in Terraform filesystem functions that access pathnames above the scan root, with risk arising in misconfiguration scanning. The flaw carries a CVSS v3.1 score of 2.5, indicating low severity, and the advisory was updated on 2 October 2026. Users are advised to upgrade to 0.71.0 or later.

  4. 4
    High-severity SQL injection flaw reported in UTMStackโ–ผ๐Ÿšจ EUVD-2026-91790 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: UTMStack ๐Ÿข Vendor: UTMStack ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ UTMStack beMmastodonTechnologyCybersecurity09 h ago

    A newly catalogued vulnerability, EUVD-2026-91790, affects UTMStack versions before 11.2.16. The flaw is a SQL injection in the UtmAssetGroupService.searchQueryBuilder() component, allowing authenticated attackers to inject arbitrary SQL commands. The issue carries a CVSS v3.1 severity score of 8.7 out of 10, placing it in the high-severity range. The advisory record was updated on 2 October 2026, and users are expected to patch to version 11.2.16 or later.

  5. 5
    Critical vulnerability flagged in CISA's Malcolm network toolโ—๐Ÿšจ EUVD-2026-76738 ๐Ÿ“Š Score: 9.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Malcolm ๐Ÿข Vendor: CISA ๐Ÿ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity07 h ago

    A high-severity vulnerability, EUVD-2026-76738, has been published for Malcolm, the open-source network traffic analysis toolkit distributed by CISA. The flaw, scored 9.2 out of 10 on the CVSS v3.1 scale, stems from an example environment-configuration file for a bundled inventory-management component that ships with a fixed, publicly known administrative password. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  6. 6
    Malcolm vulnerability EUVD-2026-76736 rated medium severityโ—๐Ÿšจ EUVD-2026-76736 ๐Ÿ“Š Score: 6.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Malcolm ๐Ÿข Vendor: CISA ๐Ÿ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity07 h ago

    A vulnerability tracked as EUVD-2026-76736 has been published for Malcolm, with a CVSS v3.1 score of 6.3 out of 10. According to the advisory, a prior update that raised a bundled HTTP client library to a version fixing known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  7. 7
    Newly published flaw hits AVEZ Electronics learning platformโ–ผ๐Ÿšจ EUVD-2026-91567 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Learning Management System (LMS) ๐Ÿข Vendor: AVEZ Electronics ComMmastodonTechnologyCybersecurity015 h ago

    A medium-severity missing authorization vulnerability, tracked as EUVD-2026-91567 and scored 6.5 out of 10 under CVSS v3.1, has been published for the Learning Management System from Turkish vendor AVEZ Electronics Communication Training and Consultancy Trade Inc. The advisory was updated on 2 October 2026. Missing authorization flaws can let users perform actions without proper permissions, so administrators of the LMS are being urged to review the advisory and apply any available fixes.

  8. 8
    High-severity infinite loop flaw reported in Apache Thrift Python bindingsโ–ผ๐Ÿšจ EUVD-2026-91568 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity015 h ago

    A vulnerability tracked as EUVD-2026-91568 has been disclosed in Apache Thrift, the Apache Software Foundation's cross-language RPC framework. The flaw, an infinite loop with an unreachable exit condition in the Python bindings, carries a CVSS v3.1 score of 8.2. Details on affected versions remain incomplete pending an update from the vendor.

  9. 9
    High-severity vulnerability disclosed in Apache Thrift Lua bindingsโ–ผ๐Ÿšจ EUVD-2026-91569 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity015 h ago

    A high-severity vulnerability, EUVD-2026-91569, has been catalogued affecting the Lua bindings of Apache Thrift, the cross-language RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.2 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling combined with inefficient algorithmic complexity, which could allow denial-of-service conditions. The advisory was updated on 2 October 2026.

  10. 10
    Dell patches two CVSS 10.0 flaws in Kubernetes storage softwareโ—๐Ÿค– Dell patches two max-severity (CVSS 10.0) flaws in Container Storage Modules (CSM) Authorization v2.4.0, which connectMmastodonTechnologyCybersecurity114 h ago

    Dell has released Container Storage Modules Authorization v2.4.0 to fix two maximum-severity flaws, both rated CVSS 10.0, in the software that connects Dell storage arrays to Kubernetes clusters. The bugs stem from missing authentication, allowing unauthenticated remote attackers to retrieve backend admin credentials across all tenants. Security teams running Dell storage with Kubernetes are urged to update immediately, as the flaws expose sensitive credentials without requiring valid accounts.

  11. 11
    Critical 10/10 vulnerability disclosed in Tenda routersโ—๐Ÿšจ EUVD-2026-91570 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HG9, HG7, HG10 ๐Ÿข Vendor: Tenda ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ A securMmastodonTechnologyCybersecurity015 h ago

    A maximum-severity security flaw, tracked as EUVD-2026-91570 with a CVSS score of 10.0, has been disclosed in Tenda HG7, HG9 and HG10 routers running the 300001138_en_xpon firmware. The vulnerability lies in the boaGetVar function in the /boaform/formLoopBack file. The advisory was updated on 2 October 2026, and security watchers are sharing the disclosure.

  12. 12
    New vulnerability disclosed in Dynamic Web Lab Team Manager pluginโ–ผ๐Ÿšจ EUVD-2025-30618 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Team Manager ๐Ÿข Vendor: Dynamic Web Lab ๐Ÿ“… Published: 2025-09-22MmastodonTechnologyCybersecurity020 h ago

    A medium-severity vulnerability, tracked as EUVD-2025-30618, was published on 22 September 2025 affecting the Team Manager plugin for WordPress by vendor Dynamic Web Lab. The flaw, scored 5.3 out of 10 under CVSS v3.1, is a missing authorization issue that could let attackers exploit incorrectly configured access controls. An update to the entry was recorded on 2 October 2026.

  13. 13
    Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3โ—Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a paMmastodonTechnologyMobile222 h ago

    A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.

  14. 14
    High-severity SQL injection flaw reported in HAVELSAN Sef chatbotโ–ผ๐Ÿšจ EUVD-2026-91329 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity020 h ago

    A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.

  15. 15
    Zitadel IAM flagged with D trust score over unpatched flawsโ—Zitadel IAM carries a D trust score: 41 CVEs, max CVSS 9.3, and 97% left unpatched. Auth flaws (CWE-287) recur. Know youMmastodonTechnologyCybersecurity018 h ago

    Security analyst Hugo Valters reports that Zitadel, the open-source identity and access management platform, carries a D trust score based on 41 published CVEs, a maximum severity of 9.3, and 97% of vulnerabilities left unpatched. Authentication flaws classified under CWE-287 recur in the vendor's history. He urges organisations to assess their exposure before deploying the software.

  16. 16
    Keycloak Kerberos flaw lets network attackers hijack accountsโ—CVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take overMmastodonTechnologyCybersecurity018 h ago

    A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.

  17. 17
    High-severity vulnerability disclosed in Apache Thrift Lua libraryโ—๐Ÿšจ EUVD-2026-91330 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity020 h ago

    A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.

  18. 18
    SSRF Vulnerability Disclosed in HAVELSAN Sef AI Chatbot Platformโ—๐Ÿšจ EUVD-2026-91323 ๐Ÿ“Š Score: 4.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity020 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-91323 with a CVSS v3.1 score of 4.9, has been recorded for the Sef AI Chatbot Platform developed by Turkish defence technology company HAVELSAN Inc. The flaw is a server-side request forgery (SSRF) issue, which can allow an attacker to make the server send arbitrary requests. The advisory was updated on 2 October 2026; affected versions have not been fully detailed in the published record.