search
CVSS
Trends
- 1Citrix patches two actively exploited NetScaler zero-daysโ๐จ CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37
Citrix has released fixes for two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated critical at CVSS 9.5 and both reportedly already exploited in the wild. Administrators are urged to update to NetScaler 14.1-73.37 or 13.1-64.23 and to check their systems for signs of compromise. Security teams worldwide are discussing the patch as urgent.
- 2D-Link DIR-895L routers hit by unpatched critical flawโผD-Link DIR-895L routers hit by CVE-2026-100740, a CVSS 9.9 vulnerability. No patch coming: the series reached end-of-lif
A critical vulnerability, CVE-2026-100740 with a CVSS score of 9.9, has been reported in D-Link DIR-895L routers. The company will not release a fix because the product line reached end-of-life in 2019. Security watchers are warning that affected devices remain exposed, with no vendor support available, and are urging users of the model to consider replacement or mitigation.
- 3Critical LightLLM flaw exposes AI servers to remote code executionโ๐จ CVE-2026-103041 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
- 4Two memory flaws found in CTranslate2 inference engineโผ๐จ CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in it
Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.
- 5Critical RCE vulnerability disclosed in LightLLMโ๐จ CVE-2026-103040 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the route
A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.
- 6RaspAP hit with three unpatched CVE disclosuresโผ๐จ RaspAP Mass Disclosure โ 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) โ privilege escalation via sudoers manipulation โ
Security researchers have disclosed three vulnerabilities in RaspAP, the popular router software for Raspberry Pi, with no patches available. The most severe, CVE-2026-101860 with a CVSS score of 8.8, allows privilege escalation to root via sudoers manipulation. Two further flaws, CVE-2026-101859 (5.4) and CVE-2026-101858 (4.7), involve OS command injection, including through the OpenVPN handler and WiFiManager SSID handling.
- 7CPython vulnerability EUVD-2026-89183 disclosed with moderate severityโผ๐จ EUVD-2026-89183 ๐ Score: 5.9/10 (CVSS v3.1) ๐ฆ Product: CPython ๐ข Vendor: Python Software Foundation ๐ Updated: 2026-09
A vulnerability tracked as EUVD-2026-89183 has been disclosed in CPython, the reference implementation of the Python language maintained by the Python Software Foundation. The flaw concerns cleanup of tempfile.TemporaryDirectory, where a race condition could let an attacker who can modify the directory tree during cleanup swap in a directory in place of the intended one. It is rated 5.9 out of 10 on the CVSS v3.1 scale, a moderate severity score.
- 8Critical CVSS 10 flaw CVE-2026-71379 allows unauthenticated data exportโ๐จ CVE-2026-71379 โ CVSS 10 CRITICAL The file export endpoint allows any unauthenticated attacker to export arbitrary dat
A vulnerability tracked as CVE-2026-71379, rated CVSS 10, is drawing attention in the cybersecurity community. The flaw lies in a file export endpoint that lets any unauthenticated attacker export arbitrary database tables via a crafted POST request. Security feeds are flagging it as maximum-severity, urging organizations to check whether their systems are affected and patch promptly.
- 9Microsoft patches high-severity Visual Studio heap overflow flawโผ๐จ EUVD-2026-73170 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: .NET 10.0, Microsoft Visual Studio 2022 version 17.14, Microsof
Microsoft's Visual Studio 2022 version 17.14, .NET 10.0 and .NET Framework 4.8 are affected by a vulnerability tracked as EUVD-2026-73170, rated 8.8 out of 10 on the CVSS v3.1 scale. The flaw is a heap-based buffer overflow in Visual Studio, and the advisory was published on 8 September 2026 with an update issued on 29 September 2026. Security trackers are flagging the high severity rating, urging developers using affected Microsoft products to check whether they need to update.
- 10Medium-severity vulnerability found in Naichen ThinkCMFโผ๐จ EUVD-2026-89477 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: ThinkCMF, ThinkCMF, ThinkCMF (+5 more) ๐ข Vendor: Naichen ๐ Upda
A security vulnerability, tracked as EUVD-2026-89477, has been identified in Naichen's ThinkCMF content management framework in versions up to 8.0.7. The flaw carries a CVSS v3.1 score of 5.1 out of 10, marking it as moderate severity. The advisory was updated on 29 September 2026, and multiple ThinkCMF product entries are listed as affected. Details of the vulnerable function remain limited in the published notice.
- 11High-Severity Flaw Reported in Pexip Infinity Video Conferencing Platformโ๐ CVE-2026-103101 - High (8.6) Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in
A high-severity vulnerability, CVE-2026-103101 with a CVSS score of 8.6, affects Pexip Infinity versions 30.0 through 40.x before 41.0. The flaw stems from improper input validation in the web server component and could allow a malicious attacker to render a Pexip Infinity node inaccessible, disrupting video conferencing services. Administrators are being urged to update to version 41.0 or later to close the gap.
- 12Critical CVE-2026-70356 flagged in TMS file upload endpointโ๐จ CVE-2026-70356 โ CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, a
A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.
- 13High-severity command injection flaw fixed in Renovateโผ๐จ EUVD-2024-55728 ๐ Score: 8.4/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.
- 14IBM patches high-severity code execution flaw in DataStageโผ๐จ EUVD-2026-89197 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: DataStage on Cloud Pak for Data ๐ข Vendor: IBM ๐ Updated: 2026-0
A new vulnerability, tracked as EUVD-2026-89197, has been disclosed in IBM DataStage on Cloud Pak for Data 5.4.0.0. Rated 8.8 out of 10 on the CVSS v3.1 scale, the flaw could let a remote authenticated attacker execute arbitrary code because of improper path validation. Security teams monitoring IBM products are flagging the advisory as organisations assess whether their deployments are affected and await a fix.
- 15Critical command injection flaw found in Ziroom ZHOME smart home appโCVE-2026-102794: Ziroom ZHOME A0101 v1.0.1.0 is affected by a CRITICAL command injection flaw (CVSS 9.1) in /api/ZRnetwo
A critical vulnerability, tracked as CVE-2026-102794, has been disclosed in Ziroom ZHOME A0101 version 1.0.1.0. The command injection flaw, rated 9.1 on the CVSS scale, sits in the /api/ZRnetwork/ping endpoint. No patch is available and a public exploit already exists, so users are being urged to restrict access to affected devices and monitor their usage while awaiting a fix from Ziroom.
- 16Critical buffer overflow flaw reported in Chrome for Androidโ๐จ CVE-2026-95281 โ CVSS 9.6 CRITICAL Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allo
A critical vulnerability, tracked as CVE-2026-95281, has been disclosed in Google Chrome on Android. The buffer overflow in the ANGLE graphics library, carrying a CVSS score of 9.6, affected Chrome versions before 154.0.8037.57 and could let a remote attacker run arbitrary code outside the sandbox through a crafted HTML page. Security researchers are urging Android users to update Chrome immediately.
- 17Benchmark finds AI models inflate security vulnerability severityโEvery model (incl. Jev) we tested inflates security finding severity
Security firm Casco reports that every large language model it tested, including its own Jev model, inflated the severity of security findings when scoring vulnerabilities, overstating risk compared to expected CVSS ratings. The company published a benchmark detailing the results, prompting discussion about how far AI-generated severity scores can be trusted in security workflows.
- 18High-severity vulnerability disclosed in MobilityDBโผ๐จ EUVD-2026-89198 ๐ Score: 7.1/10 (CVSS v3.1) ๐ฆ Product: MobilityDB, MobilityDB, MobilityDB ๐ข Vendor: MobilityDB ๐ Updat
A security advisory, EUVD-2026-89198, flags an out-of-bounds read vulnerability in MobilityDB version 1.3.0 and earlier, located in the MEOS binary and library WKB deserialization logic. The flaw carries a CVSS v3.1 score of 7.1, marking it as high severity. The advisory was updated on 2026-09-29, and users of the open-source moving-object database extension are being urged to check for patched releases.
- 19Medium-severity FTP flaw disclosed in Eclipse NetX Duoโผ๐จ EUVD-2026-89199 ๐ Score: 6.0/10 (CVSS v3.1) ๐ฆ Product: NetX Duo ๐ข Vendor: Eclipse Foundation ๐ Updated: 2026-09-29 ๐ F
A medium-severity vulnerability, EUVD-2026-89199, has been catalogued in Eclipse Foundation's NetX Duo embedded network stack. Rated 6.0 out of 10 under CVSS v3.1, the flaw lies in the FTP component, where passive data connections are not bound to the authenticated control peer, potentially allowing session mixing. The entry was updated on 29 September 2026 via the EU vulnerability database maintained by ENISA.
- 20Netatalk vulnerability report flags 31 CVEs, all patchedโผNetatalk: 31 CVEs, max CVSS 9.9, avg 7.49. Zero unpatched, zero KEV, but trend up 20 into 2026. Trust score B. Legacy AF
A new security assessment of Netatalk, the open-source implementation of Apple's legacy AFP file-sharing protocol, counts 31 known CVEs with a maximum CVSS score of 9.9 and an average of 7.49. All vulnerabilities are reportedly patched, none appear in the CISA KEV catalogue, but tracking suggests around 20 more disclosures into 2026. The vendor's trust score is rated B.
- 21Critical CVE-2026-102829 flaw reported in simple-gitโ๐จ CVE-2026-102829 โ CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.
- 22Critical vulnerability CVE-2026-102828 found in simple-git libraryโ๐จ CVE-2026-102828 โ CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102828 with a CVSS score of 9.2, has been disclosed in simple-git, a widely used Node.js library for running Git commands from JavaScript. Versions 3.15.0 through 4.0.1 are affected because the default blockUnsafeOperationsPlugin fails to classify certain trailer .cmd values, potentially allowing unsafe Git operations. Developers are being urged to check their dependency versions and update promptly.
- 23Renovate tool patched over remote code execution flawโ๐จ EUVD-2026-62467 ๐ Score: 6.8/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A medium-severity vulnerability, tracked as EUVD-2026-62467 with a CVSS score of 6.8, was disclosed in Renovate, the dependency update tool maintained by renovatebot. Versions from 43.65.0 before 43.102.11 contain a remote code execution flaw affecting the bazel-module and bazelisk managers. The advisory was published on 19 August 2026 and updated on 29 September, and administrators are urged to upgrade to a fixed release.
- 24Critical Chrome GPU flaw CVE-2026-95357 flagged on Androidโ๐จ CVE-2026-95357 โ CVSS 9.6 CRITICAL Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 al
A critical vulnerability, CVE-2026-95357, has been disclosed affecting Google Chrome on Android versions prior to 154.0.8037.57. The out-of-bounds write in the GPU component carries a CVSS score of 9.6 and could let a remote attacker execute arbitrary code outside the browser sandbox via a crafted HTML page. Security experts are urging users to update Chrome immediately.
- 25Critical Chrome vulnerability CVE-2026-95356 flaggedโ๐จ CVE-2026-95356 โ CVSS 9.6 CRITICAL Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a re
Security researchers are flagging CVE-2026-95356, a critical use-after-free flaw in the WindowDialog component of Google Chrome. Versions prior to 154.0.8037.57 are affected. The bug carries a CVSS score of 9.6 and could let a remote attacker, using social engineering and a crafted HTML page, run arbitrary code outside the browser sandbox. Users are being urged to update Chrome promptly.
- 26Critical Chrome for Android flaw allows code execution outside sandboxโ๐จ CVE-2026-95350 โ CVSS 9.6 CRITICAL Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allo
A critical vulnerability, CVE-2026-95350, has been disclosed in Google Chrome on Android. The buffer overflow in ANGLE, affecting versions before 154.0.8037.57, carries a CVSS score of 9.6 and could let a remote attacker execute arbitrary code outside the browser sandbox via a crafted HTML page. Chromium rates it Critical. Users are urged to update Chrome on Android to the latest version.
- 27Critical Chrome WebGL flaw allows code execution on Androidโ๐จ CVE-2026-95349 โ CVSS 9.6 CRITICAL Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allo
A critical vulnerability, CVE-2026-95349, has been disclosed in Google Chrome on Android. The buffer overflow in WebGL, rated CVSS 9.6, affects versions prior to 154.0.8037.57 and could let a remote attacker run arbitrary code outside the sandbox through a crafted HTML page. Chromium has classified the flaw as a critical security issue, and users are urged to update their browsers promptly.
- 28High-severity TeamViewer flaw lets attackers bypass permission settingsโ๐ CVE-2026-92370 - High (8.8) An improper access control vulnerability in TeamViewer Full Client, Host, and related affe
A high-severity vulnerability, CVE-2026-92370 with a CVSS score of 8.8, has been disclosed in TeamViewer Full Client, Host and related modules on Windows, Linux and macOS. The improper access control flaw allows an authenticated remote attacker to bypass user-configured permission settings during remote sessions, potentially gaining unauthorized access to a user's system. Security teams are urged to review the advisory and apply fixes.
- 29TDengine vulnerability lets unauthenticated packets crash serversโ๐ค CVE-2026-42542 (CVSS 7.5): integer underflow in TDengine's pre-auth RPC message parsing. A single crafted packet to TC
A new vulnerability, CVE-2026-42542 with a CVSS score of 7.5, has been disclosed in TDengine, an open-source time-series database used in OT and IoT deployments. The flaw is an integer underflow in pre-authentication RPC message parsing: a single crafted packet sent to TCP port 6030 can crash unauthenticated servers. Versions 3.4.0.0 through 3.4.1.5 are affected, with a fix released in version 3.4.1.6. No exploitation in the wild has been reported so far, and a proof-of-concept has been withheld.
- 30Zephyr RTOS vulnerability risks nonce reuse in encrypted storageโCVE-2026-15890 Zephyr: unsynchronized static nonce counter in the ITS AEAD transform. Concurrent writes can reuse an AES
A new vulnerability, CVE-2026-15890, has been disclosed in the Zephyr operating system's ITS AEAD transform. The static nonce counter is not synchronized, so concurrent writes can reuse an AES-GCM or ChaCha20-Poly1305 nonce, potentially compromising data integrity. The flaw carries a CVSS score of 5.3, and a patch is reportedly under review.
- 31GitLab patches high-severity stored XSS flaw CVE-2026-84739โ๐ CVE-2026-84739 - High (8.7) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19
GitLab has released fixes for CVE-2026-84739, a high-severity vulnerability (CVSS 8.7) affecting all versions of GitLab CE/EE from 13.11 onwards. Under certain conditions, the flaw could have let an authenticated user execute arbitrary JavaScript in another user's browser. Patches are available in versions 19.2.7, 19.3.3 and 19.4.1, and self-hosted installations are urged to upgrade promptly.