Daily digest · in progress
Tuesday 29 September 2026
A quiet day: only 28 new CVEs against a recent average of about 407 so far. Of those, 5 critical and 5 high. gz-yami was the most-affected vendor with 7.
New this day, ranked by depth score
The 12 that matter most of the 28 published.
CVE-2026-102240Critical· 10.0A vulnerability was found in Netcore NAP930 0.1.241010.141410
A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection…
CVE-2026-101354Critical· 9.6A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must…
CVE-2026-102361Critical· 9.1mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request …
CVE-2026-101264Critical· 9.1A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0
A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remote…
CVE-2026-101263Critical· 9.1A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0
A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the…
CVE-2026-101860High· 8.8A vulnerability was found in RaspAP raspap-webgui up to 3.5.5
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipu…
CVE-2026-101878High· 7.5Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO…
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO…
CVE-2026-96326High· 7.2The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitiza…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitiza…
CVE-2026-101281High· 7.3A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This ma…
CVE-2026-101280High· 7.3A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing.…
CVE-2026-18747Medium· 6.8The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt…
The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt…
CVE-2026-18417Medium· 6.5The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_conne…
The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_conne…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2019-9901EnvoyProxy Envoy Missing HTTP URL path normalizationseverity, cvss56
- CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_configexploit_available45
- CVE-2014-6407Arbitrary Code Execution in Dockercvss41
- CVE-2026-96754orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literalsexploit_available66
- CVE-2026-96759orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objectsexploit_available66
- CVE-2026-95844Moquette is a lightweight Java MQTT brokerexploit_available53
- CVE-2026-92164Streamlink is a CLI utility which pipes video streams from various services into a video playerexploit_available48
- CVE-2026-63000REDAXO is a PHP-based content management systemexploit_available47
Most-affected vendors
By CVEs published in the period.