| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63383 🧪 | Libevent: decode_tag_internal() can lead to out-of-bounds read | libevent | libevent | High | 8.7 | 2026-08-20 17:48:25 | Deep Dive |
| CVE-2026-63388 🧪 | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept | libevent | libevent | High | 8.4 | 2026-08-20 17:44:18 | Deep Dive |
| CVE-2026-76641 🧪 | Expat Out-of-Bounds Read via dtdCopy | libexpat | libexpat | High | 7.5 | 2026-08-20 17:31:11 | Deep Dive |
| CVE-2026-77022 🧪 | Comfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow | Comfast | CF-N1-S | Critical | 9.9 | 2026-08-20 16:45:07 | Deep Dive |
| CVE-2026-65842 🧪 | Plate: SSRF with response disclosure in DOCX image embedding | udecode | plate | High | 8.2 | 2026-08-20 16:40:24 | Deep Dive |
| CVE-2026-55642 🧪 | dbx: Unauthenticated arbitrary SQL execution in dbx-web (authentication fails open when no password is configured) | t8y2 | dbx | Critical | 9.8 | 2026-08-20 16:38:30 | Deep Dive |
| CVE-2026-40345 🧪 | deepmerge-ts: Stack exhaustion when merging recursive object graphs | RebeccaStevens | deepmerge-ts | High | 8.2 | 2026-08-20 16:33:53 | Deep Dive |
| CVE-2026-77020 🧪 | CodeAstro Apartment Visitor Management System password-recovery.php sql injection | CodeAstro | Apartment Visitor Management System | High | 7.3 | 2026-08-20 16:30:11 | Deep Dive |
| CVE-2026-61704 🧪 | link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 | OP-Engineering | link-preview-js | High | 7.5 | 2026-08-20 16:21:10 | Deep Dive |
| CVE-2026-77176 🧪 | Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy | Red Hat | Red Hat OpenShift Container Platform 4 | High | 8.1 | 2026-08-20 16:20:18 | Deep Dive |
| CVE-2026-69183 🧪 | Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass) | monkeytypegame | monkeytype | High | 7.5 | 2026-08-20 16:16:43 | Deep Dive |
| CVE-2026-77019 🧪 | CodeAstro Apartment Visitor Management System forgotpw.php sql injection | CodeAstro | Apartment Visitor Management System | High | 7.3 | 2026-08-20 16:15:09 | Deep Dive |
| CVE-2026-54616 🧪 | NanaZip: Heap out-of-bounds read in NanaZip SquashFS LZ4 decompressor via unchecked negative return value | M2Team | NanaZip | High | 7.1 | 2026-08-20 16:11:54 | Deep Dive |
| CVE-2026-54449 🧪 | LangBot: Authenticated RCE Via MCP Configuration | langbot-app | LangBot | High | 8.8 | 2026-08-20 16:10:25 | Deep Dive |
| CVE-2026-77004 🧪 | Comfast CF-N1-S mbox-config sprintf command injection | Comfast | CF-N1-S | High | 7.4 | 2026-08-20 16:00:10 | Deep Dive |
| CVE-2026-75140 🧪 | jsoup Uncontrolled Resource Consumption in XmlTreeBuilder | jhy | soup | High | 7.5 | 2026-08-20 15:56:50 | Deep Dive |
| CVE-2026-76998 🧪 | SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection | SourceCodester | Simple Online Food Ordering System | High | 7.3 | 2026-08-20 15:30:10 | Deep Dive |
| CVE-2026-76996 🧪 | SourceCodester Simple Online Food Ordering System view_order.php sql injection | SourceCodester | Simple Online Food Ordering System | High | 7.3 | 2026-08-20 15:00:10 | Deep Dive |
| CVE-2026-63490 🧪 | Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass | jknack | handlebars.java | High | 7.5 | 2026-08-20 14:45:36 | Deep Dive |
| CVE-2026-49825 🧪 | lxml: javascript: URL bypass in Cleaner via xlink:href | lxml | lxml | High | 8.2 | 2026-08-20 14:42:31 | Deep Dive |