| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-14600 🧪 | Admin Account Takeover via Path Traversal in vsDesk | vsDesk | vsDesk | Critical | 9.3 | 2026-08-19 17:39:43 | Deep Dive |
| CVE-2026-72717 🧪 | Orval: Import-time RCE via schema default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:39:23 | Deep Dive |
| CVE-2026-71867 🧪 | Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:38:36 | Deep Dive |
| CVE-2026-71868 🧪 | Orval: Import-time RCE via enum-typed default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:37:34 | Deep Dive |
| CVE-2026-71865 🧪 | Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:36:48 | Deep Dive |
| CVE-2026-71869 🧪 | Orval: Import-time RCE via array-items default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:36:07 | Deep Dive |
| CVE-2026-71864 🧪 | Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:34:55 | Deep Dive |
| CVE-2026-71871 🧪 | Orval: Import-time RCE via header-parameter default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:33:56 | Deep Dive |
| CVE-2026-72716 🧪 | Orval: Import-time RCE via query-parameter default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:33:02 | Deep Dive |
| CVE-2026-62681 🧪 | Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:31:03 | Deep Dive |
| CVE-2026-71866 🧪 | Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:27:28 | Deep Dive |
| CVE-2026-32475 📌 💣 | WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability | Elementor | Elementor Pro | Critical | 9.0 | 2026-08-19 17:24:56 | Deep Dive |
| CVE-2026-67581 🧪 | On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay | ZenHive | mpp | High | 8.7 | 2026-08-19 17:20:10 | Deep Dive |
| CVE-2026-73541 🧪 | Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain | ZenHive | mpp | High | 8.3 | 2026-08-19 17:20:00 | Deep Dive |
| CVE-2026-73136 🧪 | Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay | ZenHive | mpp | High | 8.2 | 2026-08-19 17:19:52 | Deep Dive |
| CVE-2025-14603 🧪 | Use of user input in raw SQL queries in vsDesk leading to blind SQL injection | vsDesk | vsDesk | High | 8.8 | 2026-08-19 17:16:08 | Deep Dive |
| CVE-2024-13942 🧪 | Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnerability leading to arbitrary code execution with highest privileges | Rockchip | RK3588s | High | 7.6 | 2026-08-19 16:40:18 | Deep Dive |
| CVE-2026-45798 🧪 | Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field | wazuh | wazuh | High | 7.5 | 2026-08-19 16:20:55 | Deep Dive |
| CVE-2026-49441 🧪 | Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager | wazuh | wazuh | Critical | 9.1 | 2026-08-19 16:19:37 | Deep Dive |
| CVE-2026-41424 🧪 | Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint | wazuh | wazuh | High | 8.2 | 2026-08-19 16:18:25 | Deep Dive |