| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55765 🧪 | CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod | cloudnative-pg | cloudnative-pg | High | 8.5 | 2026-08-20 21:38:48 | Deep Dive |
| CVE-2026-72860 🧪 | 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable | decolua | 9router | High | 8.5 | 2026-08-20 21:35:15 | Deep Dive |
| CVE-2026-46355 🧪 | BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser | bigbluebutton | bigbluebutton | High | 7.1 | 2026-08-20 21:34:41 | Deep Dive |
| CVE-2026-46682 🧪 | BigBlueButton: Blind SQL Injection AUTH (Moderator) | bigbluebutton | bigbluebutton | High | 8.5 | 2026-08-20 21:33:56 | Deep Dive |
| CVE-2026-55893 🧪 | Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode | capstone-engine | capstone | High | 7.3 | 2026-08-20 21:32:47 | Deep Dive |
| CVE-2026-74836 🧪 | HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit | mtrudel | bandit | High | 8.7 | 2026-08-20 21:11:19 | Deep Dive |
| CVE-2026-69242 🧪 | libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident write | libvips | libvips | High | 8.4 | 2026-08-20 21:02:58 | Deep Dive |
| CVE-2026-71485 🧪 | Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends | centrifugal | centrifugo | Critical | 9.1 | 2026-08-20 21:01:01 | Deep Dive |
| CVE-2026-73040 🧪 | Dockge Path Traversal via Unvalidated Stack Name Allows Arbitrary Compose and .env Disclosure and Arbitrary Directory Deletion | louislam | dockge | High | 8.8 | 2026-08-20 20:29:00 | Deep Dive |
| CVE-2026-50190 🧪 | Shaarli vulnerable to stored XSS via raw bookmark title in document <title> element on public permalink page | shaarli | Shaarli | High | 8.6 | 2026-08-20 18:49:49 | Deep Dive |
| CVE-2026-66001 🧪 | Frappe: Improper Authorization in OAuth2 Consent Endpoint | frappe | frappe | High | 8.5 | 2026-08-20 18:27:32 | Deep Dive |
| CVE-2026-62315 🧪 | Frappe: Mass assignment via set_value | frappe | frappe | High | 7.1 | 2026-08-20 18:25:01 | Deep Dive |
| CVE-2026-72852 🧪 | darknet Integer Overflow in Convolutional Layer Buffer Sizing Leads to Heap Buffer Overflow | hank-ai | darknet | High | 7.8 | 2026-08-20 18:19:24 | Deep Dive |
| CVE-2026-77148 🧪 | Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow | Comfast | CF-N1-S | Critical | 9.9 | 2026-08-20 18:15:09 | Deep Dive |
| CVE-2026-2334 🧪 | ) Missing Server-Side File Extension Validation in vsDesk | vsDesk | vsDesk | Critical | 9.4 | 2026-08-20 18:03:39 | Deep Dive |
| CVE-2026-54623 🧪 | django CMS: Plugin move endpoint allows cyclic reparenting (DoS) | django-cms | django-cms | High | 7.1 | 2026-08-20 18:02:46 | Deep Dive |
| CVE-2026-63385 🧪 | Libevent: HTTP header handling bugs create risk of access control bypass. | libevent | libevent | Critical | 9.2 | 2026-08-20 17:55:36 | Deep Dive |
| CVE-2026-63387 🧪 | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response | libevent | libevent | High | 7.0 | 2026-08-20 17:53:42 | Deep Dive |
| CVE-2026-63384 🧪 | Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value. | libevent | libevent | High | 8.7 | 2026-08-20 17:53:08 | Deep Dive |
| CVE-2026-63382 🧪 | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling | libevent | libevent | Critical | 9.2 | 2026-08-20 17:51:15 | Deep Dive |