CVE Monitor
Today's Vulnerabilities, In Plain English
A CVE is a public ID assigned to one specific flaw in one specific piece of software — a serial number for a broken lock. Somebody found the flaw, the vendor confirmed it, and the ID lets everyone talk about the same problem without confusion.
Thousands are published every month, and almost none of them are about you. So this page sorts them by the kind of system a business owns: the browser on the front desk, the firewall in the closet, the box your backups land on. Find your shelf, skim it, and move on.
Records come from the NIST National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog. We write the explanation; we never write the facts. Every ID on this page is validated against the official CVE format and every link is rebuilt from that ID, so a row can only ever point at NVD's own record — check any line against the source yourself. Collection is automated and runs twice a day. Last refreshed Sep 21, 2026, 1:15 PM Central.
Business Software (2)
Accounting, CRM, HR, booking and other day-to-day business applications. If you recognise a name here, ask the vendor which version you are on.
- CVE-2023-54399CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categori…
Guide in progressNVD recordfor CVE-2023-54399, opens in a new tab - CVE-2026-75878CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated sessi…
Guide in progressNVD recordfor CVE-2026-75878, opens in a new tab
Websites & WordPress (16)
Your public website, its theme, and every plugin bolted onto it. Plugin flaws are the most common way a small-business site gets defaced.
- CVE-2026-82187CVSS 9.8/10CVSS 9.8, critical severity.Act on thisPublished Sep 21
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded fil…
Guide in progressNVD recordfor CVE-2026-82187, opens in a new tab - CVE-2026-84434CVSS 9.8/10CVSS 9.8, critical severity.Act on thisPublished Sep 18
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1…
Guide in progressNVD recordfor CVE-2026-84434, opens in a new tab - CVE-2026-86591CVSS 9.8/10CVSS 9.8, critical severity.Act on thisPublished Sep 19
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allow…
Guide in progressNVD recordfor CVE-2026-86591, opens in a new tab - CVE-2026-88856CVSS 9.4/10CVSS 9.4, critical severity.Act on thisPublished Sep 20
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension…
Guide in progressNVD recordfor CVE-2026-88856, opens in a new tab - CVE-2026-88857CVSS 9.4/10CVSS 9.4, critical severity.Act on thisPublished Sep 20
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension…
Guide in progressNVD recordfor CVE-2026-88857, opens in a new tab - CVE-2026-88854CVSS 9.3/10CVSS 9.3, critical severity.Act on thisPublished Sep 20
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla 6.2.7…
Guide in progressNVD recordfor CVE-2026-88854, opens in a new tab - CVE-2026-89274CVSS 9.1/10CVSS 9.1, critical severity.Act on thisPublished Sep 18
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and incl…
Guide in progressNVD recordfor CVE-2026-89274, opens in a new tab - CVE-2026-92229CVSS 9.1/10CVSS 9.1, critical severity.Act on thisPublished Sep 18
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbit…
Guide in progressNVD recordfor CVE-2026-92229, opens in a new tab - CVE-2026-4327CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 19
The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.…
Guide in progressNVD recordfor CVE-2026-4327, opens in a new tab - CVE-2026-85680CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 19
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names bef…
Guide in progressNVD recordfor CVE-2026-85680, opens in a new tab - CVE-2026-88824CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 19
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthe…
Guide in progressNVD recordfor CVE-2026-88824, opens in a new tab - CVE-2026-92807CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 18
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions…
Guide in progressNVD recordfor CVE-2026-92807, opens in a new tab - CVE-2026-93031CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 18
The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable…
Guide in progressNVD recordfor CVE-2026-93031, opens in a new tab - CVE-2026-88855CVSS 8.6/10CVSS 8.6, high severity.Act on thisPublished Sep 20
Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joom…
Guide in progressNVD recordfor CVE-2026-88855, opens in a new tab - CVE-2026-88926CVSS 8.6/10CVSS 8.6, high severity.Act on thisPublished Sep 19
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of i…
Guide in progressNVD recordfor CVE-2026-88926, opens in a new tab - CVE-2026-87067CVSS 8.5/10CVSS 8.5, high severity.Act on thisPublished Sep 20
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deser…
Guide in progressNVD recordfor CVE-2026-87067, opens in a new tab
Network Gear, Firewalls & Cameras (8)
Routers, firewalls, VPN boxes, Wi-Fi access points and IP cameras. A flaw here is not "someone reads a file" — it is "someone is inside the network".
- CVE-2026-93740CVSS 10.0/10CVSS 10.0, critical severity.Act on thisPublished Sep 18
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046.
Guide in progressNVD recordfor CVE-2026-93740, opens in a new tab - CVE-2026-93741CVSS 10.0/10CVSS 10.0, critical severity.Act on thisPublished Sep 19
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046.
Guide in progressNVD recordfor CVE-2026-93741, opens in a new tab - CVE-2026-94089CVSS 10.0/10CVSS 10.0, critical severity.Act on thisPublished Sep 20
A vulnerability was determined in D-Link DIR-868L 2.01b05.
Guide in progressNVD recordfor CVE-2026-94089, opens in a new tab - CVE-2026-93738CVSS 9.9/10CVSS 9.9, critical severity.Act on thisPublished Sep 18
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046.
Guide in progressNVD recordfor CVE-2026-93738, opens in a new tab - CVE-2026-93739CVSS 9.9/10CVSS 9.9, critical severity.Act on thisPublished Sep 18
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046.
Guide in progressNVD recordfor CVE-2026-93739, opens in a new tab - CVE-2026-93742CVSS 9.9/10CVSS 9.9, critical severity.Act on thisPublished Sep 19
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046.
Guide in progressNVD recordfor CVE-2026-93742, opens in a new tab - CVE-2026-93958CVSS 9.1/10CVSS 9.1, critical severity.Act on thisPublished Sep 19
A vulnerability was found in D-Link R95 BE9500_1.00.16.
Guide in progressNVD recordfor CVE-2026-93958, opens in a new tab - CVE-2026-94036CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 20
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402.
Guide in progressNVD recordfor CVE-2026-94036, opens in a new tab
Servers & Operating Systems (2)
Linux, Windows Server and the virtualisation hosts your systems run on. Usually your IT provider’s job, but worth knowing so you can ask whether it is handled.
- CVE-2026-79920CVSS 9.9/10CVSS 9.9, critical severity.Handled for youPublished Sep 21
Ajenti is a Linux & BSD modular server admin panel.
Guide in progressNVD recordfor CVE-2026-79920, opens in a new tab - CVE-2026-61674CVSS 9.2/10CVSS 9.2, critical severity.Handled for youPublished Sep 21
Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows.
Guide in progressNVD recordfor CVE-2026-61674, opens in a new tab
Security & Monitoring Tools (17)
The products meant to watch everything else — worth patching first when they are the thing that slipped.
- CVE-2026-80442CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCer…
Guide in progressNVD recordfor CVE-2026-80442, opens in a new tab - CVE-2026-84064CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to…
Guide in progressNVD recordfor CVE-2026-84064, opens in a new tab - CVE-2026-84075CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authenti…
Guide in progressNVD recordfor CVE-2026-84075, opens in a new tab - CVE-2026-84078CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet.
Guide in progressNVD recordfor CVE-2026-84078, opens in a new tab - CVE-2026-61550CVSS 9.8/10CVSS 9.8, critical severity.Handled for youPublished Sep 18
Icinga 2 is an open source monitoring system.
Guide in progressNVD recordfor CVE-2026-61550, opens in a new tab - CVE-2026-80441CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the g…
Guide in progressNVD recordfor CVE-2026-80441, opens in a new tab - CVE-2026-81657CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system…
Guide in progressNVD recordfor CVE-2026-81657, opens in a new tab - CVE-2026-82340CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled ref…
Guide in progressNVD recordfor CVE-2026-82340, opens in a new tab - CVE-2026-82967CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attac…
Guide in progressNVD recordfor CVE-2026-82967, opens in a new tab - CVE-2026-84082CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutr…
Guide in progressNVD recordfor CVE-2026-84082, opens in a new tab - CVE-2026-82832CVSS 9.6/10CVSS 9.6, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…
Guide in progressNVD recordfor CVE-2026-82832, opens in a new tab - CVE-2026-84073CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to…
Guide in progressNVD recordfor CVE-2026-84073, opens in a new tab - CVE-2026-84031CVSS 9.0/10CVSS 9.0, critical severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…
Guide in progressNVD recordfor CVE-2026-84031, opens in a new tab - CVE-2026-84070CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…
Guide in progressNVD recordfor CVE-2026-84070, opens in a new tab - CVE-2026-84074CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…
Guide in progressNVD recordfor CVE-2026-84074, opens in a new tab - CVE-2026-84106CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…
Guide in progressNVD recordfor CVE-2026-84106, opens in a new tab - CVE-2026-84084CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 18
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site req…
Guide in progressNVD recordfor CVE-2026-84084, opens in a new tab
Everything below this line sits inside other software rather than on anyone's desk — code libraries, databases, hosting plumbing. You do not install these and you cannot patch them directly. They reach you as an update from whoever built or hosts your software. They are listed because a monitor that hides things is not a monitor.
That used to make this the part you could skip. It is not any more — this is also the supply chain an AI coding assistant pulls into an application it writes for you. The panel below names the packages involved.
What your AI builds with
These are the packages we watch because an AI coding assistant reaches for them on its own. Ask a model for a small web service and an HTTP client, a web framework and a few utilities arrive with it. Ask for an AI feature and a model SDK and somewhere to keep embeddings arrive with that. If a generated application is running in your business, this is a fair description of what it is made of.
This is the watch-list itself, separate from today's advisories. A package appearing here does not mean it has a vulnerability. When one of them is actually the subject of an advisory, it shows up in the list below with its name on the row.
What an assistant writes into your app
Asked for an ordinary service, a model reaches for these without being told to.
- axios — HTTP client. The HTTP client models reach for by default in JavaScript, so it lands in almost any generated service that calls an API. Opens in a new tab.
- express — Web framework. The minimal Node web framework an assistant writes when the ask is "an API" or "a server". Opens in a new tab.
- next — Web framework. The React framework assistants scaffold when the ask is a web application rather than a bare API. Opens in a new tab.
- react — Web framework. The UI library most generated front-end code is written against. Opens in a new tab.
- lodash — Utility library. A general-purpose JavaScript helper library that assistants still pull in for small things like deep clone and grouping. Opens in a new tab.
- moment — Utility library. The older JavaScript date library; its own maintainers now point users elsewhere, but generated code still targets it. Opens in a new tab.
- dayjs — Utility library. A small date library with a moment-shaped API, suggested as the modern replacement for it. Opens in a new tab.
- node-fetch — HTTP client. Brings the browser fetch API to Node versions that lack it, so server code written in the browser idiom still runs. Opens in a new tab.
- ws — Realtime transport. The bare WebSocket implementation for Node that most generated realtime servers sit on. Opens in a new tab.
- socket.io — Realtime transport. The higher-level realtime library assistants reach for when the ask is live updates or chat. Opens in a new tab.
- cors — Utility library. The Express middleware that sets cross-origin headers, added almost reflexively when a generated API is called from a browser. Opens in a new tab.
- body-parser — Utility library. Parses JSON and form bodies for Express, which older generated handlers still require explicitly. Opens in a new tab.
- multer — Utility library. The Express middleware for multipart file uploads, which is what a generated upload endpoint uses. Opens in a new tab.
- jsonwebtoken — Authentication. Signs and verifies JWTs, and it is what generated Node login code almost always issues tokens with. Opens in a new tab.
- bcrypt — Authentication. Hashes and checks passwords, which is the step generated sign-up code reaches for first. Opens in a new tab.
- passport — Authentication. The pluggable authentication middleware for Express, used whenever generated code needs "log in with" strategies. Opens in a new tab.
- helmet — Utility library. Sets common security response headers on an Express app, and is what an assistant adds when asked to harden a server. Opens in a new tab.
- dotenv — Utility library. Loads environment variables out of a .env file, which is how nearly every generated Node app reads its configuration and its API keys. Opens in a new tab.
- uuid — Utility library. Generates standard unique identifiers, the default whenever generated code needs an id it did not get from a database. Opens in a new tab.
- zod — Input validation. A TypeScript-first schema validator, now the usual choice for checking request bodies and for describing tool arguments to a model. Opens in a new tab.
- joi — Input validation. An older object-schema validator still generated for Express request validation. Opens in a new tab.
- yup — Input validation. A schema validator that turns up in generated React form code. Opens in a new tab.
- mongoose — Database driver or ORM. The MongoDB object-modelling layer generated Node code declares its schemas in. Opens in a new tab.
- prisma — Database driver or ORM. A typed ORM and schema tool that assistants pick for new TypeScript projects backed by SQL. Opens in a new tab.
- sequelize — Database driver or ORM. A long-standing SQL ORM for Node that still shows up in generated CRUD code. Opens in a new tab.
- pg — Database driver or ORM. The PostgreSQL driver for Node, sitting underneath most generated code that talks to Postgres directly. Opens in a new tab.
- mysql2 — Database driver or ORM. The MySQL driver generated Node code uses, usually through its promise API. Opens in a new tab.
- ioredis — Database driver or ORM. A widely used Node client for Redis, pulled in when generated code needs a cache or a job queue. Opens in a new tab.
- sharp — Media handling. The Node image-processing library generated upload and thumbnail code resizes with. Opens in a new tab.
- puppeteer — Scraping and parsing. Drives a headless Chrome, which is what gets generated for scraping, screenshots, PDF rendering and browser-using agents. Opens in a new tab.
- cheerio — Scraping and parsing. Parses HTML with a jQuery-shaped API, the usual dependency in generated scraping scripts and page-to-text steps. Opens in a new tab.
- nodemailer — Utility library. Sends mail from Node, which is what generated contact forms and notification code use. Opens in a new tab.
- vite — Build tooling. The dev server and bundler new generated front-end projects are scaffolded with. Opens in a new tab.
- webpack — Build tooling. The older bundler still sitting in plenty of generated build configs and existing projects. Opens in a new tab.
- esbuild — Build tooling. A fast bundler that ends up in the tree indirectly, underneath other build tooling rather than by direct choice. Opens in a new tab.
- requests — HTTP client. The HTTP client Python code reaches for by default, including the hand-rolled code that calls a model API. Opens in a new tab.
- urllib3 — HTTP client. The HTTP layer underneath requests, so it is in the tree even when nothing imports it directly. Opens in a new tab.
- flask — Web framework. The small Python web framework used to wrap a script in an API, including a model inference endpoint. Opens in a new tab.
- fastapi — Web framework. The async Python framework generated model-serving endpoints are usually written in. Opens in a new tab.
- django — Web framework. The batteries-included Python web framework generated full-stack apps are built on. Opens in a new tab.
- sqlalchemy — Database driver or ORM. The Python ORM and SQL toolkit generated database code is written against. Opens in a new tab.
- pydantic — Input validation. Declares and validates typed data models, and it is also how most Python AI libraries describe tool and response schemas. Opens in a new tab.
- jinja2 — Utility library. The Python template engine behind Flask pages, and a common way prompt text gets templated too. Opens in a new tab.
- pillow — Media handling. The Python imaging library, used for thumbnails in ordinary apps and for preparing images before a model sees them. Opens in a new tab.
- numpy — Data handling. The array library nearly every Python data or model script imports, directly or through something else. Opens in a new tab.
- pandas — Data handling. The dataframe library generated Python data-handling code loads and reshapes tables with. Opens in a new tab.
- pyyaml — Utility library. Parses YAML in Python, which is how a lot of generated services and AI tooling read their configuration. Opens in a new tab.
- cryptography — Authentication. Provides Python with real primitives for hashing, tokens and TLS, and is pulled in by many packages that never say so. Opens in a new tab.
- gin — Web framework. The HTTP framework generated Go services are usually routed with. Opens in a new tab.
- gorm — Database driver or ORM. The ORM generated Go code talks to SQL through. Opens in a new tab.
- rails — Web framework. The Ruby web framework generated Ruby applications are scaffolded in. Opens in a new tab.
- mongoid — Database driver or ORM. The Ruby object mapper for MongoDB, filling the slot mongoose fills in Node. Opens in a new tab.
- nokogiri — Scraping and parsing. Parses HTML and XML in Ruby, and is the usual dependency in generated scraping and feed code. Opens in a new tab.
- devise — Authentication. The authentication gem generated Rails apps handle sign-up and login with. Opens in a new tab.
- puma — Utility library. The application server generated Rails apps are served behind. Opens in a new tab.
- spring-boot — Web framework. The Java framework generated Java services are built on. Opens in a new tab.
- jackson-databind — Data handling. Turns JSON into Java objects and back, and is in nearly every Java service an assistant writes. Opens in a new tab.
- Newtonsoft.Json — Data handling. The JSON library generated C# code still serializes with most often. Opens in a new tab.
- Microsoft.EntityFrameworkCore — Database driver or ORM. The ORM generated .NET code reaches the database through. Opens in a new tab.
- serde — Data handling. The serialization framework nearly every generated Rust program derives its types from. Opens in a new tab.
- tokio — Utility library. The async runtime generated Rust services run on. Opens in a new tab.
- reqwest — HTTP client. The HTTP client generated Rust code calls APIs with. Opens in a new tab.
- docker — Build tooling. The container runtime generated projects are packaged into, usually via a Dockerfile the assistant writes alongside the code. Opens in a new tab.
- kubernetes — Build tooling. The orchestrator those containers land on once the application outgrows a single box. Opens in a new tab.
- helm — Build tooling. The packaging and templating layer for Kubernetes deployments. Opens in a new tab.
- nginx — Utility library. The reverse proxy and static file server generated deployment configs put in front of the application. Opens in a new tab.
- postgres — Database driver or ORM. The SQL database generated code assumes by default, usually added as a container in the compose file written with it. Opens in a new tab.
- redis — Database driver or ORM. The cache and queue added beside a generated application, and the store a lot of AI tooling keeps sessions and embeddings in. Opens in a new tab.
What you build AI features with
The pieces that show up once the application itself has to call a model.
- vm2 — Code sandbox. A Node sandbox used to run model-generated or user-supplied code inside the host process, with a long enough run of escapes that it should not be the only thing standing between generated code and your server. Opens in a new tab.
- openai — Model SDK. The official SDK for OpenAI's API, and usually the first dependency added when a feature calls a hosted model. Opens in a new tab.
- anthropic — Model SDK. The official SDK for Anthropic's API, filling the same slot when the app calls Claude. Opens in a new tab.
- langchain — Model SDK. A framework for chaining model calls, tools and retrieval together, common in first-draft AI features. Opens in a new tab.
- langchain-community — Model SDK. The community integration package for LangChain, which is where most third-party connectors actually live. Opens in a new tab.
- llama-index — Model SDK. A framework for indexing your own documents and answering questions over them with a model. Opens in a new tab.
- litellm — Model SDK. Puts one API shape in front of many model providers so application code can switch between them. Opens in a new tab.
- tiktoken — Model SDK. Splits and counts text as tokens the way the model does, so a prompt can be measured before it is sent. Opens in a new tab.
- huggingface-hub — Model SDK. Downloads models and datasets from the Hugging Face Hub, and is pulled in by most code that runs an open model. Opens in a new tab.
- transformers — Machine-learning runtime. Hugging Face's library for loading, running and fine-tuning open models. Opens in a new tab.
- sentence-transformers — Machine-learning runtime. Turns text into embeddings locally, which is the first step in most retrieval features. Opens in a new tab.
- torch — Machine-learning runtime. The tensor and training runtime most open models are loaded through. Opens in a new tab.
- tensorflow — Machine-learning runtime. The other major ML runtime, still underneath a lot of existing model code. Opens in a new tab.
- vllm — Machine-learning runtime. A high-throughput server for hosting open models behind an OpenAI-shaped API. Opens in a new tab.
- lightllm — Machine-learning runtime. A Python server for hosting open models in the same slot as vLLM, distributed from its repository rather than as a published package. Opens in a new tab.
- lmdeploy — Machine-learning runtime. A toolkit for compressing, deploying and serving large language models. Opens in a new tab.
- chromadb — Vector store. An embedded vector database, and the default local store in a lot of retrieval examples. Opens in a new tab.
- pinecone — Vector store. The current client library for the hosted Pinecone vector database, replacing the older pinecone-client package that is now marked deprecated. Opens in a new tab.
- weaviate-client — Vector store. The client library for the Weaviate vector database. Opens in a new tab.
- qdrant-client — Vector store. The client library for the Qdrant vector database, which is usually run as a container beside the app. Opens in a new tab.
- faiss — Vector store. An in-process similarity index, used when the embeddings stay on one machine instead of in a database. Opens in a new tab.
- ollama — Machine-learning runtime. Runs open models locally and serves them over HTTP, which is how most on-premises AI features get prototyped. Opens in a new tab.
Nothing in this panel is being reported as vulnerable. It is the list of packages we watch. Today's actual advisories are the entries below, and any that involve one of these packages carry its name on the row.
Developer & Hosting Components (10)
Code libraries, databases and hosting plumbing. These reach you as an update from whoever built your software — you do not install them yourself.
- CVE-2026-61781CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesOn our AI build watch-list, postgres.postgresPublished Sep 18
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID.
Guide in progressNVD recordfor CVE-2026-61781, opens in a new tab - CVE-2026-93985CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 19
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template…
Guide in progressNVD recordfor CVE-2026-93985, opens in a new tab - CVE-2025-66455CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, lmdeploy.lmdeployPublished Sep 18
LMDeploy is a toolkit for compressing, deploying, and serving large language models.
Guide in progressNVD recordfor CVE-2025-66455, opens in a new tab - CVE-2026-58264CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18
FluidSynth is a software synthesizer based on the SoundFont 2 specifications.
Guide in progressNVD recordfor CVE-2026-58264, opens in a new tab - CVE-2026-78030CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 19
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.
Guide in progressNVD recordfor CVE-2026-78030, opens in a new tab - CVE-2026-85751CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, docker.dockerPublished Sep 21
Mailu is a mail server distributed as a set of Docker images.
Guide in progressNVD recordfor CVE-2026-85751, opens in a new tab - CVE-2026-93762CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, mongoid.mongoidPublished Sep 18
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents.
Guide in progressNVD recordfor CVE-2026-93762, opens in a new tab - CVE-2026-93839CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, lightllm.lightllmPublished Sep 18
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allo…
Guide in progressNVD recordfor CVE-2026-93839, opens in a new tab - CVE-2026-53940CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
Conda is a system-level binary package and environment manager that runs on major operating systems and platforms.
Guide in progressNVD recordfor CVE-2026-53940, opens in a new tab - CVE-2026-16651CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose content…
Guide in progressNVD recordfor CVE-2026-16651, opens in a new tab
Everything Else (45)
Published this cycle, but not a clean fit for anything a business runs. Listed rather than dropped.
- CVE-2026-94097CVSS 10.0/10CVSS 10.0, critical severity.Background noise for most businessesPublished Sep 20
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246.
- CVE-2026-94095CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246.
- CVE-2026-94096CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246.
- CVE-2026-94099CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246.
- CVE-2026-94100CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246.
- CVE-2026-94098CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 20
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246.
- CVE-2026-94003CVSS 10.0/10CVSS 10.0, critical severity.Background noise for most businessesPublished Sep 20
A vulnerability has been found in Comfast CF-N1-S 2.6.0.1.
Guide in progressNVD recordfor CVE-2026-94003, opens in a new tab - CVE-2026-94101CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246.
Guide in progressNVD recordfor CVE-2026-94101, opens in a new tab - CVE-2026-90817CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 20
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import proc…
Guide in progressNVD recordfor CVE-2026-90817, opens in a new tab - CVE-2026-94301CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 21
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.re…
Guide in progressNVD recordfor CVE-2026-94301, opens in a new tab - CVE-2026-94083CVSS 9.4/10CVSS 9.4, critical severity.Background noise for most businessesPublished Sep 19
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 stat…
Guide in progressNVD recordfor CVE-2026-94083, opens in a new tab - CVE-2026-94084CVSS 9.4/10CVSS 9.4, critical severity.Background noise for most businessesPublished Sep 19
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.…
Guide in progressNVD recordfor CVE-2026-94084, opens in a new tab - CVE-2026-63647CVSS 9.3/10CVSS 9.3, critical severity.Background noise for most businessesPublished Sep 18
CordysCRM is an open source AI-powered customer relationship management system that supports private deployment.
Guide in progressNVD recordfor CVE-2026-63647, opens in a new tab - CVE-2026-75885CVSS 9.3/10CVSS 9.3, critical severity.Background noise for most businessesPublished Sep 18
A flaw was found in the OpenShift console.
Guide in progressNVD recordfor CVE-2026-75885, opens in a new tab - CVE-2025-12999CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 21
UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forw…
Guide in progressNVD recordfor CVE-2025-12999, opens in a new tab - CVE-2026-59163CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18
Mnemosyne is a memory layer for artificial intelligence agents.
Guide in progressNVD recordfor CVE-2026-59163, opens in a new tab - CVE-2026-92701CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments.
Guide in progressNVD recordfor CVE-2026-92701, opens in a new tab - CVE-2026-92702CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments.
Guide in progressNVD recordfor CVE-2026-92702, opens in a new tab - CVE-2026-55563CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 21
Feast is the open source feature store for AI and machine learning.
Guide in progressNVD recordfor CVE-2026-55563, opens in a new tab - CVE-2026-88807CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 21
A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject co…
Guide in progressNVD recordfor CVE-2026-88807, opens in a new tab - CVE-2026-62371CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…
Guide in progressNVD recordfor CVE-2026-62371, opens in a new tab - CVE-2026-63116CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale.
Guide in progressNVD recordfor CVE-2026-63116, opens in a new tab - CVE-2026-82412CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
ntopng is a web-based network traffic monitoring application.
Guide in progressNVD recordfor CVE-2026-82412, opens in a new tab - CVE-2026-84285CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacke…
Guide in progressNVD recordfor CVE-2026-84285, opens in a new tab - CVE-2026-84990CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
ntopng is a web-based network traffic monitoring application.
Guide in progressNVD recordfor CVE-2026-84990, opens in a new tab - CVE-2026-86553CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 19
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process.
Guide in progressNVD recordfor CVE-2026-86553, opens in a new tab - CVE-2026-92574CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container…
Guide in progressNVD recordfor CVE-2026-92574, opens in a new tab - CVE-2026-93922CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 18
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stor…
Guide in progressNVD recordfor CVE-2026-93922, opens in a new tab - CVE-2026-93923CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 18
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing s…
Guide in progressNVD recordfor CVE-2026-93923, opens in a new tab - CVE-2026-93993CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 19
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that execute…
Guide in progressNVD recordfor CVE-2026-93993, opens in a new tab - CVE-2026-94104CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails…
Guide in progressNVD recordfor CVE-2026-94104, opens in a new tab - CVE-2026-94106CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames…
Guide in progressNVD recordfor CVE-2026-94106, opens in a new tab - CVE-2026-94109CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation d…
Guide in progressNVD recordfor CVE-2026-94109, opens in a new tab - CVE-2026-94128CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500.
Guide in progressNVD recordfor CVE-2026-94128, opens in a new tab - CVE-2026-94129CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800.
Guide in progressNVD recordfor CVE-2026-94129, opens in a new tab - CVE-2026-94142CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200.
Guide in progressNVD recordfor CVE-2026-94142, opens in a new tab - CVE-2026-94146CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3.
Guide in progressNVD recordfor CVE-2026-94146, opens in a new tab - CVE-2026-65651CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstr…
Guide in progressNVD recordfor CVE-2026-65651, opens in a new tab - CVE-2026-65652CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames.
Guide in progressNVD recordfor CVE-2026-65652, opens in a new tab - CVE-2026-65653CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-pre…
Guide in progressNVD recordfor CVE-2026-65653, opens in a new tab - CVE-2026-65654CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's l…
Guide in progressNVD recordfor CVE-2026-65654, opens in a new tab - CVE-2026-89139CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compu…
Guide in progressNVD recordfor CVE-2026-89139, opens in a new tab - CVE-2026-94381CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21
MISP has a security issue that can let a user gain more access than their API key is supposed to allow.
Guide in progressNVD recordfor CVE-2026-94381, opens in a new tab - CVE-2026-68928CVSS 8.6/10CVSS 8.6, high severity.Background noise for most businessesPublished Sep 18
Acode is a powerful text and code editor for Android.
Guide in progressNVD recordfor CVE-2026-68928, opens in a new tab - CVE-2026-94383CVSS 8.6/10CVSS 8.6, high severity.Background noise for most businessesPublished Sep 21
The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file ex…
Guide in progressNVD recordfor CVE-2026-94383, opens in a new tab
Reading this list is the easy part
Knowing a flaw exists is not the same as knowing whether it is yours. The real questions come next: do you run the affected version, on which machines, who installed it, is anything else depending on it, and did last month's patch quietly break the one application your billing runs on? None of that is in a CVE record.
Those answers come out of an inventory — a current list of what you run and where — and most small offices have never had one. Building it is the first half of a vulnerability assessment; the second half is deciding, with you, which findings are worth a Tuesday and which are noise. 20+ years of doing it, 100% Texas-based support.