| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-41451 🧪 | UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh | tclahr | uac | High | 7.8 | 2026-08-21 17:36:02 | Deep Dive |
| CVE-2026-41450 🧪 | UAC < 3.3.0 Command Injection via command_collector.sh | tclahr | uac | High | 7.8 | 2026-08-21 17:35:05 | Deep Dive |
| CVE-2026-41449 🧪 | UAC < 3.3.0 Command Injection via run_command.sh | tclahr | uac | High | 7.8 | 2026-08-21 17:33:51 | Deep Dive |
| CVE-2026-54789 🧪 | mod_auth_openidc has out-of-bounds read and write in state cookie parsing | OpenIDC | mod_auth_openidc | High | 7.5 | 2026-08-21 16:13:23 | Deep Dive |
| CVE-2026-22681 🧪 | OpenViking < 0.3.4 SSRF via /api/v1/resources | Volcengine | OpenViking | High | 8.5 | 2026-08-21 16:13:07 | Deep Dive |
| CVE-2026-49114 🧪 | ONNX symlink-following and path-traversal arbitrary file write | ONNX | ONNX | High | 7.1 | 2026-08-21 16:10:56 | Deep Dive |
| CVE-2026-77815 🧪 | Infinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape From Scanned Directories | zanllp | infinite-image-browsing | High | 7.5 | 2026-08-21 15:03:09 | Deep Dive |
| CVE-2026-77087 🧪 | Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding | paperclipai | paperclip | Critical | 9.6 | 2026-08-21 15:03:08 | Deep Dive |
| CVE-2026-63343 🧪 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | lxc | incus | Critical | 9.9 | 2026-08-21 14:53:26 | Deep Dive |
| CVE-2026-63125 🧪 | Incus vulnerable to root RCE via image backup.yaml symlink | lxc | incus | Critical | 9.9 | 2026-08-21 14:49:17 | Deep Dive |
| CVE-2026-62941 🧪 | Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge | lxc | incus | Critical | 9.9 | 2026-08-21 14:47:57 | Deep Dive |
| CVE-2026-62940 🧪 | Incus has a project restriction bypass via instance migration config override | lxc | incus | Critical | 9.9 | 2026-08-21 14:47:13 | Deep Dive |
| CVE-2026-62867 🧪 | Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution | lxc | incus | Critical | 9.9 | 2026-08-21 14:45:36 | Deep Dive |
| CVE-2026-55622 🧪 | Incus has a project restriction bypass in instance copy across projects | lxc | incus | High | 7.7 | 2026-08-21 14:40:35 | Deep Dive |
| CVE-2026-55621 🧪 | Incus has a project restriction bypass for custom volume copy across projects | lxc | incus | High | 7.7 | 2026-08-21 14:39:44 | Deep Dive |
| CVE-2026-48769 🧪 | Incus has an arbitrary file write on its client due to trusted image hash | lxc | incus | Critical | 9.9 | 2026-08-21 14:38:39 | Deep Dive |
| CVE-2026-48755 🧪 | Incus has an argument injection in backup compression algorithm leading to AFW and ACE | lxc | incus | Critical | 9.9 | 2026-08-21 14:37:25 | Deep Dive |
| CVE-2026-48753 🧪 | Incus has an arbitrary file write via path traversal in S3 multipart upload | lxc | incus | Critical | 9.9 | 2026-08-21 14:34:40 | Deep Dive |
| CVE-2026-48752 🧪 | Incus has arbitrary file read+write on host via templates/ symlink in malicious image | lxc | incus | Critical | 9.9 | 2026-08-21 14:31:58 | Deep Dive |
| CVE-2026-48751 🧪 | Incus has a restricted project bypass leading to arbitrary command execution | lxc | incus | Critical | 9.9 | 2026-08-21 14:21:03 | Deep Dive |