| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73220 🧪 | CVAT: Stored XSS via annotation guides in audio tasks | cvat-ai | cvat | High | 8.5 | 2026-08-20 14:32:53 | Deep Dive |
| CVE-2026-70383 🧪 | Arbitrary file overwrite vulnerability in DigiDoc4 client | Estonian Information System Authority (RIA) | DigiDoc4 | High | 8.4 | 2026-08-20 14:04:15 | Deep Dive |
| CVE-2026-76635 🧪 | baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php | baserproject | basercms | High | 7.2 | 2026-08-20 13:58:06 | Deep Dive |
| CVE-2026-76833 🧪 | @cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag | cgauge | @cgauge/yaml | High | 7.8 | 2026-08-20 13:33:15 | Deep Dive |
| CVE-2026-76987 🧪 | liftoff-sr CIPster Generic Attribute Logic ciptypes.h SetAttrData memory corruption | liftoff-sr | CIPster | High | 7.3 | 2026-08-20 12:15:10 | Deep Dive |
| CVE-2025-14601 🧪 | vsDesk Task Scheduler OS Command Injection | vsDesk | vsDesk | High | 8.6 | 2026-08-20 07:21:26 | Deep Dive |
| CVE-2026-76956 🧪 | libexpat 异常处理不当漏洞 | libexpat project | libexpat | Medium | 5.9 | 2026-08-20 04:22:51 | Deep Dive |
| CVE-2026-76795 🧪 | AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery | AeternaLabsHQ | PullMD | High | 7.3 | 2026-08-20 00:45:12 | Deep Dive |
| CVE-2026-76764 🧪 | code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection | code-projects | Employee Management System | High | 7.3 | 2026-08-20 00:00:13 | Deep Dive |
| CVE-2026-76762 🧪 | code-projects Assessment Management welcome.php sql injection | code-projects | Assessment Management | High | 7.3 | 2026-08-19 23:15:10 | Deep Dive |
| CVE-2026-76761 🧪 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection | chenhg5 | cc-connect | High | 7.3 | 2026-08-19 23:00:12 | Deep Dive |
| CVE-2026-76760 🧪 | chenhg5 cc-connect webhook.go authenticate code injection | chenhg5 | cc-connect | High | 7.3 | 2026-08-19 22:45:14 | Deep Dive |
| CVE-2026-76591 🧪 | TRENDnet TEW-755AP ssi email.cgi log_email_server command injection | TRENDnet | TEW-755AP | High | 7.4 | 2026-08-19 22:00:11 | Deep Dive |
| CVE-2026-76832 🧪 | Agno PythonTools Path Traversal via joinpath file_name argument | Agno AGI | Agno | High | 8.8 | 2026-08-19 21:58:51 | Deep Dive |
| CVE-2026-76590 🧪 | TRENDnet TEW-755AP ssi wan.cgi stack-based overflow | TRENDnet | TEW-755AP | Critical | 9.9 | 2026-08-19 21:45:08 | Deep Dive |
| CVE-2026-76850 🧪 | LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disaggregated Serving Peer Connector | InternLM | lmdeploy | Critical | 9.8 | 2026-08-19 21:41:28 | Deep Dive |
| CVE-2026-76589 🧪 | TRENDnet TEW-755AP mycli FUN_401000 stack-based overflow | TRENDnet | TEW-755AP | Critical | 9.9 | 2026-08-19 21:30:09 | Deep Dive |
| CVE-2026-75595 🧪 | Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext | netty | netty | Critical | 9.1 | 2026-08-19 21:00:28 | Deep Dive |
| CVE-2026-76584 🧪 | TRENDnet TV-IP751WIC alphapd set_time.cgi stack-based overflow | TRENDnet | TV-IP751WIC | Critical | 9.9 | 2026-08-19 21:00:10 | Deep Dive |
| CVE-2026-75596 🧪 | Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing | netty | netty | High | 8.7 | 2026-08-19 20:56:22 | Deep Dive |