| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-48050 🧪 | Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS | Basekick-Labs | arc | High | 8.8 | 2026-08-21 22:40:13 | Deep Dive |
| CVE-2026-53499 🧪 | FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning | NICMx | FORT-validator | High | 7.2 | 2026-08-21 22:29:49 | Deep Dive |
| CVE-2026-53525 🧪 | WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication | weechat | weechat | High | 7.4 | 2026-08-21 22:19:21 | Deep Dive |
| CVE-2026-53528 🧪 | FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter | perber | leafwiki | High | 8.8 | 2026-08-21 21:26:58 | Deep Dive |
| CVE-2026-53527 🧪 | LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update | perber | leafwiki | High | 8.8 | 2026-08-21 21:25:16 | Deep Dive |
| CVE-2026-49849 🧪 | xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution | 4xmen | xshop | Critical | 9.1 | 2026-08-21 21:14:24 | Deep Dive |
| CVE-2026-50538 🧪 | libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write | LibVNC | libvncserver | High | 8.8 | 2026-08-21 21:03:58 | Deep Dive |
| CVE-2026-77415 🧪 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | jsonata-js | jsonata | Critical | 9.3 | 2026-08-21 21:01:09 | Deep Dive |
| CVE-2026-77414 🧪 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | jsonata-js | jsonata | Critical | 9.3 | 2026-08-21 20:51:44 | Deep Dive |
| CVE-2026-77413 🧪 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | jsonata-js | jsonata | Critical | 9.3 | 2026-08-21 20:47:08 | Deep Dive |
| CVE-2026-77354 🧪 | kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decoding | getkin | kin-openapi | High | 8.7 | 2026-08-21 20:44:48 | Deep Dive |
| CVE-2026-63135 🧪 | YOURLS: Stored XSS in referrer statistics chart via crafted Referer header | YOURLS | YOURLS | High | 8.2 | 2026-08-21 20:40:08 | Deep Dive |
| CVE-2026-61539 🧪 | Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing | xorbitsai | inference | Critical | 10.0 | 2026-08-21 20:37:03 | Deep Dive |
| CVE-2026-54457 🧪 | TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint | tensorzero | tensorzero | High | 7.7 | 2026-08-21 20:34:04 | Deep Dive |
| CVE-2026-64679 🧪 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation | runatlantis | atlantis | High | 8.1 | 2026-08-21 20:29:55 | Deep Dive |
| CVE-2026-59989 🧪 | Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) | phalcon | cphalcon | Critical | 9.2 | 2026-08-21 20:25:45 | Deep Dive |
| CVE-2026-62283 🧪 | Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check | nezhahq | nezha | Critical | 9.9 | 2026-08-21 20:21:29 | Deep Dive |
| CVE-2026-77219 🧪 | GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader | GNU | Emacs | High | 7.1 | 2026-08-21 20:20:45 | Deep Dive |
| CVE-2026-62316 🧪 | Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution | microsoft | UFO | High | 8.8 | 2026-08-21 20:17:21 | Deep Dive |
| CVE-2026-63421 🧪 | Keystone: `graphql.maxTake` bypass with negative `take` | keystonejs | keystone | High | 7.5 | 2026-08-21 20:15:16 | Deep Dive |