| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-53532 🧪 | OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS) | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-24 22:24:03 | Deep Dive |
| CVE-2026-78267 🧪 | WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability | Cozmoslabs | TranslatePress | Critical | 9.8 | 2026-08-24 21:31:34 | Deep Dive |
| CVE-2026-77337 🧪 | CakePHP: Potential Authentication bypass with CookieAuthenticator | cakephp | authentication | Critical | 9.1 | 2026-08-24 21:30:07 | Deep Dive |
| CVE-2026-77384 🧪 | libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion | libp2p | js-libp2p | High | 7.5 | 2026-08-24 21:06:40 | Deep Dive |
| CVE-2026-77634 🧪 | CakePHP: SmtpTransport vulnerable to CRLF header injection | cakephp | cakephp | High | 8.2 | 2026-08-24 20:33:47 | Deep Dive |
| CVE-2026-77635 🧪 | CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver | cakephp | cakephp | Critical | 9.2 | 2026-08-24 20:30:34 | Deep Dive |
| CVE-2026-75542 🧪 | OAuth token exchange grants repository scopes for organizations the principal cannot access | hexpm | hexpm | High | 8.3 | 2026-08-24 20:14:30 | Deep Dive |
| CVE-2026-77567 🧪 | Filament: App-based MFA can be bypassed when recovery codes are enabled | filamentphp | filament | High | 8.1 | 2026-08-24 20:10:58 | Deep Dive |
| CVE-2026-76098 🧪 | Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown | lepture | mistune | High | 7.5 | 2026-08-24 20:05:01 | Deep Dive |
| CVE-2026-78555 🧪 | RansomLook API Key Disclosure Through /admin/apikeys HTML Source | ransomlook | ransomlook | Critical | 9.4 | 2026-08-24 19:38:50 | Deep Dive |
| CVE-2026-78553 🧪 | Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in RansomLook | ransomlook | ransomlook | High | 7.0 | 2026-08-24 19:28:49 | Deep Dive |
| CVE-2026-78551 🧪 | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication Attempts | ransomlook | ransomlook | High | 8.8 | 2026-08-24 19:20:03 | Deep Dive |
| CVE-2026-76835 🧪 | OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set | oauth2-proxy | oauth2-proxy | Critical | 9.1 | 2026-08-24 17:55:40 | Deep Dive |
| CVE-2026-76072 🧪 | Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headless and Auto Mode | continuedev | continue | High | 7.4 | 2026-08-24 17:55:39 | Deep Dive |
| CVE-2026-76838 🧪 | Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webhook Redirects | HiEventsDev | Hi.Events | High | 8.5 | 2026-08-24 17:36:03 | Deep Dive |
| CVE-2026-76836 🧪 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | AzuraCast | High | 8.8 | 2026-08-24 17:36:02 | Deep Dive |
| CVE-2026-77915 🧪 | rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php | rconfig | rconfig | Critical | 9.8 | 2026-08-24 16:11:45 | Deep Dive |
| CVE-2026-76071 🧪 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | Netis Systems | NC63 | Critical | 9.8 | 2026-08-24 15:42:33 | Deep Dive |
| CVE-2026-76070 🧪 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter | Netis Systems | NC63 | Critical | 9.8 | 2026-08-24 15:41:17 | Deep Dive |
| CVE-2026-78416 🧪 | Authenticated RCE via `condition.config` JSON cleanse bypass | craftcms | cms | High | 8.7 | 2026-08-24 15:36:08 | Deep Dive |