| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63421 🧪 | Keystone: `graphql.maxTake` bypass with negative `take` | keystonejs | keystone | High | 7.5 | 2026-08-21 20:15:16 | Deep Dive |
| CVE-2026-76904 📌 💣 | GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers | geotools | geotools | Critical | 9.8 | 2026-08-21 20:13:21 | Deep Dive |
| CVE-2026-61824 🧪 | Defuddle: XSS via unescaped attribute interpolation in site extractors | kepano | defuddle | High | 8.2 | 2026-08-21 20:12:53 | Deep Dive |
| CVE-2026-68508 🧪 | Hydra: hydra.utils.instantiate with untrusted config can lead to code execution | facebookresearch | hydra | High | 7.8 | 2026-08-21 20:09:26 | Deep Dive |
| CVE-2026-77811 🧪 | Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards | AWS | Amazon OpenSearch Service | High | 8.7 | 2026-08-21 20:09:19 | Deep Dive |
| CVE-2026-62960 🧪 | Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows | git-for-windows | git | High | 7.4 | 2026-08-21 20:05:45 | Deep Dive |
| CVE-2026-77810 🧪 | Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector | AWS | Athena Federated Query Neptune Connector | Critical | 9.9 | 2026-08-21 19:34:06 | Deep Dive |
| CVE-2026-54071 🧪 | BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py | funstory-ai | BabelDOC | High | 7.8 | 2026-08-21 18:55:42 | Deep Dive |
| CVE-2026-53762 🧪 | VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-default WOLFCRYPT=1 builds) | veracrypt | VeraCrypt | Medium | 6.2 | 2026-08-21 18:50:58 | Deep Dive |
| CVE-2026-54682 🧪 | DiscordChatExporter: Stored XSS in HTML export when markdown formatting is disabled | Tyrrrz | DiscordChatExporter | High | 8.2 | 2026-08-21 18:40:05 | Deep Dive |
| CVE-2026-54134 🧪 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | OctoPrint | OctoPrint | High | 7.0 | 2026-08-21 18:28:16 | Deep Dive |
| CVE-2026-63462 🧪 | Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter | Unleash | unleash | High | 7.5 | 2026-08-21 18:12:33 | Deep Dive |
| CVE-2026-71862 🧪 | Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is Enabled | bluewave-labs | Checkmate | High | 7.5 | 2026-08-21 18:00:33 | Deep Dive |
| CVE-2026-55241 🧪 | Checkmate: Pre-auth Denial of Service via File Upload on Registration | bluewave-labs | Checkmate | High | 7.5 | 2026-08-21 17:57:10 | Deep Dive |
| CVE-2026-62675 🧪 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | omnigent-ai | omnigent | High | 8.8 | 2026-08-21 17:49:00 | Deep Dive |
| CVE-2026-77236 🧪 | Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel | FreeRTOS | FreeRTOS-Kernel | High | 7.3 | 2026-08-21 17:47:50 | Deep Dive |
| CVE-2026-62674 🧪 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent-ai | omnigent | Critical | 9.0 | 2026-08-21 17:47:38 | Deep Dive |
| CVE-2026-62677 🧪 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE | omnigent-ai | omnigent | High | 8.8 | 2026-08-21 17:44:37 | Deep Dive |
| CVE-2026-62676 🧪 | Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py | omnigent-ai | omnigent | High | 7.1 | 2026-08-21 17:42:22 | Deep Dive |
| CVE-2026-77235 🧪 | Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel | FreeRTOS | FreeRTOS-Kernel | High | 7.3 | 2026-08-21 17:42:12 | Deep Dive |