search
EUVD
Trends
- 1Moderate vulnerability disclosed in Docling document parsing toolโผ๐จ EUVD-2026-92803 ๐ Score: 4.0/10 (CVSS v3.1) ๐ฆ Product: docling, docling-slim ๐ข Vendor: docling-project ๐ Updated: 2026
A new vulnerability, EUVD-2026-92803, has been catalogued affecting the docling and docling-slim packages maintained by the docling-project. The flaw carries a moderate severity score of 4.0 out of 10 under CVSS v3.1 and affects versions from 2.91.0 onward. Docling is widely used to parse document formats and connect them with generative AI tools, so affected users are advised to check versions and apply fixes.
- 2Security flaw flagged in Docling document processing toolโผ๐จ EUVD-2026-92804 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: docling, docling-slim ๐ข Vendor: docling-project ๐ Updated: 2026
A vulnerability tracked as EUVD-2026-92804 has been published for Docling and Docling-slim, open-source document parsing tools from the docling-project used in generative AI pipelines. The flaw carries a CVSS v3.1 score of 7.5, considered high severity, and affects versions from 2.94.0 onward. Users are advised to check for patched releases.
- 3Medium-severity vulnerability disclosed in Docling document parserโผ๐จ EUVD-2026-92805 ๐ Score: 6.7/10 (CVSS v3.1) ๐ฆ Product: docling, docling-slim ๐ข Vendor: docling-project ๐ Updated: 2026
A vulnerability tracked as EUVD-2026-92805 has been recorded against Docling and Docling-slim, open-source tools from the docling-project used to parse documents for generative AI workflows. The flaw carries a CVSS v3.1 score of 6.7 out of 10, a medium severity, and affects versions from 2.27.0 onward. Users are being advised to check for patched releases.
- 4Critical vulnerability disclosed in openSIS Classic softwareโผ๐จ EUVD-2026-92806 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: openSIS-Classic ๐ข Vendor: OS4ED ๐ Updated: 2026-10-05 ๐ openSIS
A high-severity vulnerability, tracked as EUVD-2026-92806 with a CVSS score of 9.3, has been disclosed in openSIS Classic 9.3, the open-source student information system from vendor OS4ED. The flaw allows an authenticated user with the built-in teacher role to select an arbitrary staff record via the staff_id parameter and trigger harmful actions within the School module. Schools running the platform are being urged to review the advisory and apply fixes.
- 5Moderate vulnerability disclosed in Docling document toolโ๐จ EUVD-2026-92802 ๐ Score: 3.7/10 (CVSS v3.1) ๐ฆ Product: docling-slim, docling ๐ข Vendor: docling-project ๐ Updated: 2026
A new vulnerability, EUVD-2026-92802, has been catalogued affecting the docling and docling-slim packages from the docling-project, with a moderate CVSS v3.1 score of 3.7 out of 10. Docling is an open-source tool that parses diverse document formats and integrates with the generative AI ecosystem. Versions from 2.95.0 onward are referenced in the advisory, updated 5 October 2026. Details of the flaw remain limited, and security watchers are monitoring the listing.
- 6Atlassian products hit by critical vulnerability scoring 9.3โผ๐จ EUVD-2026-92807 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: Bitbucket Data Center, Crowd Server, Crucible Data Center (+13
Atlassian has a critical vulnerability, tracked as EUVD-2026-92807, affecting a range of its enterprise products including Bitbucket Data Center, Crowd Server, Crucible Data Center, Confluence Data Center and Jira Service Management. The flaw carries a CVSS v3.1 severity score of 9.3 out of 10, putting it in the critical range. The advisory was updated on 5 October 2026, and security teams are being urged to check whether their deployments of the affected Atlassian products are exposed.
- 7High-severity vulnerability disclosed in Dify AI platformโ๐จ EUVD-2026-92866 ๐ Score: 8.3/10 (CVSS v3.1) ๐ฆ Product: dify ๐ข Vendor: langgenius ๐ Updated: 2026-10-05 ๐ Dify is an op
A security advisory, EUVD-2026-92866, flags a high-severity vulnerability (CVSS 8.3) in Dify, the open-source LLM application development platform by LangGenius. The flaw affects versions prior to 1.13.0 and involves the /console/api/remote-files/upload endpoint, which accepted improper input. Users are urged to update their deployments to the patched release.
- 8High-severity vulnerability disclosed in Plane project management toolโผ๐จ EUVD-2026-92533 ๐ Score: 8.7/10 (CVSS v3.1) ๐ฆ Product: plane ๐ข Vendor: makeplane ๐ Updated: 2026-10-05 ๐ Plane is an o
A high-severity vulnerability, EUVD-2026-92533, has been disclosed in Plane, the open-source project management tool from vendor Makeplane. The flaw carries a CVSS v3.1 score of 8.7 out of 10 and affects versions prior to 1.4.0. Plane only validates the GITEA_HOST setting's URL scheme and does not reject hosts resolving to private networks, potentially exposing users to server-side request forgery. Users are advised to update to version 1.4.0.
- 9New moderate vulnerability disclosed in Moby's BuildKitโผ๐จ EUVD-2026-92534 ๐ Score: 5.7/10 (CVSS v3.1) ๐ฆ Product: buildkit ๐ข Vendor: moby ๐ Updated: 2026-10-05 ๐ A malicious ext
A medium-severity vulnerability, tracked as EUVD-2026-92534 with a CVSS v3.1 score of 5.7, has been disclosed in BuildKit, the build engine maintained by the Moby project. According to the advisory, a malicious external BuildKit frontend can use the internal API to trigger a data race that causes the BuildKit daemon to panic, potentially disrupting container build services. The advisory was updated on 5 October 2026.
- 10Low-severity vulnerability disclosed in Docling document parserโ๐จ EUVD-2026-92808 ๐ Score: 2.2/10 (CVSS v3.1) ๐ฆ Product: docling-slim, docling ๐ข Vendor: docling-project ๐ Updated: 2026
A vulnerability tracked as EUVD-2026-92808 has been recorded against docling and docling-slim, document parsing tools from the docling-project used to convert formats for generative AI workflows. The flaw carries a CVSS v3.1 score of 2.2 out of 10, indicating minimal severity, and affects versions from 2.83.0 onward. The advisory was updated on 5 October 2026.
- 11High-severity SSRF vulnerability disclosed in Plane project management toolโผ๐จ EUVD-2026-92535 ๐ Score: 7.7/10 (CVSS v3.1) ๐ฆ Product: plane ๐ข Vendor: makeplane ๐ Updated: 2026-10-05 ๐ Plane is an o
A new vulnerability, EUVD-2026-92535, has been catalogued in Plane, the open-source project management tool from Makeplane, with a CVSS v3.1 score of 7.7 out of 10. The flaw involves an SSRF in work-item link unfurling; earlier fixes for related issues CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw shipped in v1.2.2 were incomplete before version 1.4.0.
- 12Moderate vulnerability disclosed in Rapid7's Velociraptorโ๐จ EUVD-2026-92536 ๐ Score: 5.5/10 (CVSS v3.1) ๐ฆ Product: Velociraptor ๐ข Vendor: Rapid7 ๐ Updated: 2026-10-05 ๐ Velocirap
A vulnerability tracked as EUVD-2026-92536 has been documented in Velociraptor, the endpoint monitoring and forensics tool owned by Rapid7. The flaw carries a CVSS v3.1 score of 5.5, a moderate severity rating. Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints, and these artifacts can be used to do essentially anything on a system, typically running with elevated privileges, which is why the disclosure is drawing attention from the security community.
- 13Medium-severity vulnerability disclosed in feelec-yishu feelcrm-osโผ๐จ EUVD-2026-92392 ๐ Score: 5.3/10 (CVSS v3.1) ๐ฆ Product: feelcrm-os ๐ข Vendor: feelec-yishu ๐ Updated: 2026-10-05 ๐ A vul
A vulnerability has been catalogued as EUVD-2026-92392 in feelec-yishu's feelcrm-os software, version 1.0.0. The flaw sits in the IndexController::index function and carries a CVSS v3.1 score of 5.3 out of 10, marking it as medium severity. The entry was updated on 5 October 2026. Details on exploitation and fixes remain limited, so administrators running the product are advised to watch the vendor for a patch.
- 14Medium-severity vulnerability disclosed in feelec-yishu feelcrm-osโผ๐จ EUVD-2026-92393 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: feelcrm-os ๐ข Vendor: feelec-yishu ๐ Updated: 2026-10-05 ๐ A vul
A new vulnerability, tracked as EUVD-2026-92393, has been published for feelec-yishu's feelcrm-os software version 1.0.0. The flaw, rated 5.1 out of 10 under CVSS v3.1, involves the htmlspecialchars_decode function, and the advisory was updated on 5 October 2026. Security watchers are urged to review the vendor's product for patch availability.
- 15New MediaTek modem vulnerability flagged in EU vulnerability databaseโ๐จ EUVD-2026-92210 ๐ Score: n/a ๐ฆ Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+54 more) ๐ข Vendor: Medi
A vulnerability tracked as EUVD-2026-92210 has been listed for MediaTek chipsets, affecting dozens of products. The flaw sits in the modem, where a missing bounds check allows a possible out of bounds write that could lead to remote escalation of privileges. No severity score has been published yet. MediaTek chipsets power a huge share of Android phones worldwide, so security watchers are monitoring the advisory for patch details.
- 16MediaTek modem flaw flagged in new vulnerability advisoryโ๐จ EUVD-2026-92209 ๐ Score: n/a ๐ฆ Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+54 more) ๐ข Vendor: Medi
A newly catalogued vulnerability, EUVD-2026-92209, affects MediaTek chipsets across more than fifty product entries. The flaw sits in the modem component, where a missing bounds check allows a possible out-of-bounds write, potentially leading to remote escalation of privileges. The advisory was updated on 5 October 2026, and no severity score has been assigned yet.
- 17New vulnerability flagged in MediaTek chipset video decoderโ๐จ EUVD-2026-92208 ๐ Score: n/a ๐ฆ Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+22 more) ๐ข Vendor: Medi
A new vulnerability, EUVD-2026-92208, has been recorded affecting MediaTek chipsets across more than 20 product entries. The flaw sits in the video decoder, where a missing bounds check allows a possible out-of-bounds write that could lead to remote escalation of privileges. A severity score has not yet been assigned, so the real-world risk remains to be assessed.
- 18New vulnerability disclosed in MediaTek chipsetsโ๐จ EUVD-2026-92207 ๐ Score: n/a ๐ฆ Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+22 more) ๐ข Vendor: Medi
A vulnerability tracked as EUVD-2026-92207 has been published affecting MediaTek chipsets across more than 20 product entries. The flaw involves a possible out-of-bounds write caused by type confusion in the venc component, which could allow local escalation of privilege on affected devices. MediaTek, the Taiwanese chip designer whose silicon powers many Android smartphones and other devices, has not been assigned a severity score yet. Security watchers are tracking whether the issue is being patched in firmware updates.
- 19Privilege escalation flaw flagged in MediaTek video HALโ๐จ EUVD-2026-92206 ๐ Score: n/a ๐ฆ Product: MediaTek chipset, MediaTek chipset, MediaTek chipset (+45 more) ๐ข Vendor: Medi
A new vulnerability, EUVD-2026-92206, has been catalogued affecting MediaTek chipsets across roughly 50 product entries. The flaw sits in the Video HAL component, where a missing bounds check could allow local escalation of privilege. No severity score has been assigned yet. Security watchers are tracking the disclosure as it touches a vendor whose chips power large numbers of Android devices worldwide.