| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-52767 🧪 | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` | YesWiki | yeswiki | High | 8.2 | 2026-09-04 23:40:40 | Deep Dive |
| CVE-2026-53757 🧪 | Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE | emlog | emlog | Medium | 6.9 | 2026-09-04 17:47:39 | Deep Dive |
| CVE-2026-44402 🧪 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | Voltronic Power | SNMP Web Pro | Critical | 9.8 | 2026-09-04 15:31:12 | Deep Dive |
| CVE-2026-85688 📌 💣 | TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer | TEN-framework | ten-framework | Critical | 9.8 | 2026-09-04 14:32:33 | Deep Dive |
| CVE-2026-85381 🧪 | light0011 cms Chapter Controller ChapterController.class.php authorization | light0011 | cms | Medium | 5.3 | 2026-09-04 01:00:10 | Deep Dive |
| CVE-2026-71963 🧪 | Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection | NousResearch | hermes-agent | High | 8.8 | 2026-09-03 15:19:30 | Deep Dive |
| CVE-2026-81199 📌 💣 | MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route | Unknown | MasterStudy LMS WordPress Plugin | - | - | 2026-09-02 06:00:22 | Deep Dive |
| CVE-2023-54391 📌 💣 | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter | Proxmox Server Solutions GmbH | Proxmox Virtual Environment (VE) | Critical | 9.8 | 2026-09-01 21:59:13 | Deep Dive |
| CVE-2026-83548 KEV 📌 💣 | SonicWALL SMA1000 服务端请求伪造漏洞 | SonicWall | SMA1000 | 超危 | - | 2026-09-01 21:25:45 | Deep Dive |
| CVE-2026-76657 🧪 | Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access | Hewlett Packard Enterprise (HPE) | Fabric Composer | Critical | 10.0 | 2026-09-01 19:47:53 | Deep Dive |
| CVE-2026-82971 🧪 | QVidium Opera11 CGI Script net_tr.cgi command injection | QVidium | Opera11 | Critical | 10.0 | 2026-08-31 22:15:40 | Deep Dive |
| CVE-2026-82921 🧪 | ShopEx ECShop pack.php check_img_type unrestricted upload | ShopEx | ECShop | High | 7.3 | 2026-08-31 21:15:35 | Deep Dive |
| CVE-2026-81779 🧪 | WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability | Silk Themes | Newspapers X | Critical | 10.0 | 2026-08-31 20:42:27 | Deep Dive |
| CVE-2026-82602 🧪 | SeaCMS ass.php authorization | - | SeaCMS | Medium | 5.3 | 2026-08-31 01:30:09 | Deep Dive |
| CVE-2026-82475 🧪 | iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check | iflytek | astron-agent | High | 8.1 | 2026-08-29 16:35:35 | Deep Dive |
| CVE-2026-82456 📌 💣 | argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP | argoproj-labs | argocd-mcp | Critical | 10.0 | 2026-08-29 13:47:57 | Deep Dive |
| CVE-2026-82329 KEV 📌 💣 | Potential authentication bypass leading to administrative access in Artifactory | jfrog | artifactory | Critical | 9.8 | 2026-08-28 18:27:44 | Deep Dive |
| CVE-2026-55549 📌 💣 | Yamcs: Reflected XSS in the URL of the Authorize Endpoint | yamcs | yamcs | Medium | 6.5 | 2026-08-28 17:15:53 | Deep Dive |
| CVE-2026-82275 🧪 | Qwen-Agent Arbitrary File Read via Caller-Supplied Document Path | QwenLM | Qwen-Agent | High | 7.5 | 2026-08-28 16:18:57 | Deep Dive |
| CVE-2026-15603 🧪 | morgan vulnerable to Log Forging via unescaped Unicode line separators | morgan | morgan | Medium | 5.3 | 2026-08-28 13:41:50 | Deep Dive |