| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-44511 | Katalyst Koi: Session cookies can be replayed after user logout | katalyst | koi | High | 7.4 | 2026-05-14 16:17:29 | Deep Dive |
| CVE-2026-44312 | css_parser allows to MITM included https css urls | premailer | css_parser | Medium | 5.8 | 2026-05-14 16:15:05 | Deep Dive |
| CVE-2026-6923 | Nuvoton - CWE-1300: Improper Protection of Physical Side Channels | Nuvoton | NPCT7xx | Low | 3.8 | 2026-05-14 16:14:34 | Deep Dive |
| CVE-2025-62317 | HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. | HCL | AION | Low | 2.6 | 2026-05-14 16:13:35 | Deep Dive |
| CVE-2025-62308 | HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed | HCL | AION | Medium | 5.1 | 2026-05-14 16:12:40 | Deep Dive |
| CVE-2025-62309 | HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. | HCL | AION | Low | 2.6 | 2026-05-14 16:10:50 | Deep Dive |
| CVE-2025-62312 | HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication | HCL | AION | Low | 3.0 | 2026-05-14 16:09:36 | Deep Dive |
| CVE-2025-62316 | HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured | HCL | AION | Low | 2.3 | 2026-05-14 16:08:59 | Deep Dive |
| CVE-2026-20224 | Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability | Cisco | Cisco Catalyst SD-WAN Manager | High | 8.6 | 2026-05-14 16:08:47 | Deep Dive |
| CVE-2026-20210 | Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability | Cisco | Cisco Catalyst SD-WAN Manager | Medium | 5.4 | 2026-05-14 16:08:46 | Deep Dive |
| CVE-2026-20209 | Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability | Cisco | Cisco Catalyst SD-WAN Manager | Medium | 5.4 | 2026-05-14 16:08:27 | Deep Dive |
| CVE-2026-20182KEV💣 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | Cisco | Cisco Catalyst SD-WAN Manager | Critical | 10.0 | 2026-05-14 16:08:26 | Deep Dive |
| CVE-2025-62313 | HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. | HCL | AION | Medium | 5.4 | 2026-05-14 16:07:54 | Deep Dive |
| CVE-2025-62311 | HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. | HCL | AION | Medium | 4.3 | 2026-05-14 16:06:57 | Deep Dive |
| CVE-2025-62310 | HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations | HCL | AION | Medium | 5.4 | 2026-05-14 16:05:43 | Deep Dive |
| CVE-2026-44503 | Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect | microsoft | kiota-java | - | - | 2026-05-14 15:58:58 | Deep Dive |
| CVE-2026-44504 | Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR) | aegra | aegra | - | - | 2026-05-14 15:52:31 | Deep Dive |
| CVE-2026-42281📌💣 | MagicMirror²: Unauthenticated SSRF via /cors endpoint | MagicMirrorOrg | MagicMirror | - | - | 2026-05-14 15:46:41 | Deep Dive |
| CVE-2026-42283 | DevSpace UI Server WebSocket CheckOrigin does not validate source | devspace-sh | devspace | High | 7.7 | 2026-05-14 15:44:22 | Deep Dive |
| CVE-2026-44501 | DataHub OIDC REDIRECT_URL Cookie Deserialization Vulnerability | datahub-project | datahub | Medium | 4.3 | 2026-05-14 15:41:44 | Deep Dive |