| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-96587 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These cr | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-71379 | The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted PO | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-96349 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-76570 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The fron | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-102427 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader. | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-55107 | Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-101148 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, tre | CRITICAL | 10.0 | NVD | 2026-10-01 |
| CVE-2026-55393 | Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLo | CRITICAL | 10.0 | NVD | 2026-10-01 |
| CVE-2026-103956 | Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remot | CRITICAL | 10.0 | NVD | 2026-10-02 |
| CVE-2026-100103 | Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented de | CRITICAL | 10.0 | NVD | 2026-10-05 |
| CVE-2026-69085 | SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| GHSA-v2f8-6655-7grj | Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain | CRITICAL | 10.0 | GitHub | 2026-10-02 |
| GHSA-jqmf-mx4f-hfr6 | Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF | CRITICAL | 10.0 | GitHub | 2026-10-02 |
| CVE-2026-100721 | vm2: NodeVM custom resolution bypasses external path boundaries | CRITICAL | 10.0 | GitHub | 2026-10-05 |
| CVE-2026-92955 | vm2: Sandbox Escape (NodeVM) | CRITICAL | 10.0 | GitHub | 2026-10-05 |
| CVE-2026-92953 | vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix | CRITICAL | 10.0 | GitHub | 2026-10-05 |
| CVE-2026-92946 | vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RC | CRITICAL | 10.0 | GitHub | 2026-10-05 |
| CVE-2026-92947 | vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool | CRITICAL | 10.0 | GitHub | 2026-10-05 |
| CVE-2026-92956 | vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass | CRITICAL | 10.0 | GitHub | 2026-10-05 |
| CVE-2026-92940 | vm2 exposes host HTTPS credentials and TLS traffic through globalAgent | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| CVE-2026-92937 | vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| CVE-2026-92941 | vm2 NodeVM can replace the host process TLS trust store | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| CVE-2025-29813 | Azure DevOps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-05-13 |
| CVE-2025-54914 | Azure Networking Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-09-09 |
| CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-09-09 |
| CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-03-10 |
| CVE-2022-49043 | xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. | CRITICAL | 10.0 | Microsoft | 2025-01-14 |
| CVE-2024-56719 | net: stmmac: fix TSO DMA API usage causing oops | CRITICAL | 10.0 | Microsoft | 2024-12-10 |
| CVE-2025-68121 | Unexpected session resumption in crypto/tls | CRITICAL | 10.0 | Microsoft | 2026-02-10 |
| CVE-2026-27211 | Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CRITICAL | 10.0 | Microsoft | 2026-02-10 |
| CVE-2025-65041 | Microsoft Partner Center Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-12-09 |
| CVE-2025-65037 | Azure Container Apps Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-12-09 |
| CVE-2026-84154 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release | CRITICAL | 9.9 | NVD | 2026-09-29 |
| CVE-2026-79901 | In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-accoun | CRITICAL | 9.9 | NVD | 2026-10-01 |
| CVE-2026-96658 | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE | CRITICAL | 9.9 | NVD | 2026-10-01 |
| CVE-2026-93698 | Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin. | CRITICAL | 9.9 | NVD | 2026-10-02 |
| CVE-2026-90970 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1 | CRITICAL | 9.9 | NVD | 2026-10-02 |
| CVE-2026-105636 | Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/web | CRITICAL | 9.9 | NVD | 2026-10-05 |
| CVE-2026-105691 | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlle | CRITICAL | 9.9 | NVD | 2026-10-05 |
| CVE-2026-105697 | Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio tra | CRITICAL | 9.9 | NVD | 2026-10-05 |