| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-78387 🧪 | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification | ransomlook | ransomlook | Critical | 9.4 | 2026-08-24 14:04:17 | Deep Dive |
| CVE-2026-67602 🧪 | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache | phpipam | phpipam | Critical | 9.1 | 2026-08-24 13:57:42 | Deep Dive |
| CVE-2026-78386 🧪 | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook API | ransomlook | ransomlook | High | 8.7 | 2026-08-24 13:55:57 | Deep Dive |
| CVE-2026-78385 🧪 | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File Access | ransomlook | ransomlook | High | 8.2 | 2026-08-24 13:49:51 | Deep Dive |
| CVE-2026-78367 🧪 | Rpm: rpmbuild gettarspec() crafted tar member name → macro injection | Red Hat | Red Hat Enterprise Linux 10 | High | 7.0 | 2026-08-24 13:48:52 | Deep Dive |
| CVE-2026-78381 🧪 | RansomLook Arbitrary File Read via Path Traversal in Post screen Field | ransomlook | ransomlook | High | 8.2 | 2026-08-24 13:32:55 | Deep Dive |
| CVE-2026-78380 🧪 | Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLook | ransomlook | ransomlook | High | 8.7 | 2026-08-24 13:26:56 | Deep Dive |
| CVE-2026-76847 🧪 | act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend | nektos | act | High | 8.8 | 2026-08-24 13:12:02 | Deep Dive |
| CVE-2026-76844 🧪 | webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPath | webpack | webpack-dev-middleware | High | 7.4 | 2026-08-24 13:12:01 | Deep Dive |
| CVE-2026-76842 🧪 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients | mercadopago | mercadopago | High | 8.2 | 2026-08-24 13:12:00 | Deep Dive |
| CVE-2026-76843 🧪 | Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel.load | flairNLP | flair | High | 7.8 | 2026-08-24 13:12:00 | Deep Dive |
| CVE-2026-76841 🧪 | Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Model Loaders | xorbitsai | inference | High | 8.8 | 2026-08-24 13:11:59 | Deep Dive |
| CVE-2026-76840 🧪 | RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileContentsResponse Length | rustdesk | rustdesk | Critical | 9.6 | 2026-08-24 13:11:58 | Deep Dive |
| CVE-2026-78372 🧪 | RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data | ransomlook | ransomlook | Critical | 9.2 | 2026-08-24 13:09:23 | Deep Dive |
| CVE-2026-78370 🧪 | RansomLook Unauthenticated Database Export Exposes Private Data | ransomlook | ransomlook | Critical | 9.2 | 2026-08-24 13:03:24 | Deep Dive |
| CVE-2026-78248 🧪 | SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection | SourceCodester | Simple Online Food Ordering System | High | 7.3 | 2026-08-24 13:00:10 | Deep Dive |
| CVE-2026-78369 🧪 | Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook | ransomlook | ransomlook | High | 8.8 | 2026-08-24 12:58:02 | Deep Dive |
| CVE-2026-78365 🧪 | IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification | Roskus | Prospero Flow CRM | Critical | 9.3 | 2026-08-24 12:49:37 | Deep Dive |
| CVE-2026-78247 🧪 | SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection | SourceCodester | Simple Online Food Ordering System | High | 7.3 | 2026-08-24 12:45:10 | Deep Dive |
| CVE-2026-78246 🧪 | itsourcecode Online Clinic Management System Admin Login login.php sql injection | itsourcecode | Online Clinic Management System | High | 7.3 | 2026-08-24 11:30:10 | Deep Dive |