| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-48024 🧪 | Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager | wazuh | wazuh | Critical | 9.1 | 2026-08-19 16:14:21 | Deep Dive |
| CVE-2026-48162 🧪 | Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file path injection in Wazuh manager | wazuh | wazuh | Critical | 9.1 | 2026-08-19 16:13:16 | Deep Dive |
| CVE-2026-44901 🧪 | Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability | wazuh | wazuh | High | 8.4 | 2026-08-19 16:12:12 | Deep Dive |
| CVE-2026-46343 🧪 | Wazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file() | wazuh | wazuh | High | 7.5 | 2026-08-19 16:07:58 | Deep Dive |
| CVE-2026-44252 🧪 | Wazuh Manager dapi RBAC Bypass Allows Privilege Escalation | wazuh | wazuh | High | 7.7 | 2026-08-19 16:04:01 | Deep Dive |
| CVE-2026-64852 🧪 | Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account | getgrav | grav-plugin-api | High | 8.7 | 2026-08-19 16:00:06 | Deep Dive |
| CVE-2026-64850 🧪 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | getgrav | grav | High | 8.7 | 2026-08-19 15:58:03 | Deep Dive |
| CVE-2026-64851 🧪 | Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers | getgrav | grav-plugin-shortcode-core | High | 8.5 | 2026-08-19 15:56:44 | Deep Dive |
| CVE-2026-63408 🧪 | Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter | getgrav | grav-plugin-api | High | 7.5 | 2026-08-19 15:53:09 | Deep Dive |
| CVE-2026-63407 🧪 | Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses | getgrav | grav-plugin-api | High | 8.2 | 2026-08-19 15:51:37 | Deep Dive |
| CVE-2026-62673 🧪 | Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems | getgrav | grav | High | 8.2 | 2026-08-19 15:46:59 | Deep Dive |
| CVE-2026-62667 🧪 | Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL | getgrav | grav-plugin-api | High | 8.1 | 2026-08-19 15:43:19 | Deep Dive |
| CVE-2026-62669 🧪 | Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge | getgrav | grav | High | 7.4 | 2026-08-19 15:40:03 | Deep Dive |
| CVE-2026-62666 🧪 | Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super | getgrav | grav-plugin-api | High | 8.8 | 2026-08-19 15:36:37 | Deep Dive |
| CVE-2026-62668 🧪 | Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols | getgrav | grav | Critical | 9.4 | 2026-08-19 15:29:24 | Deep Dive |
| CVE-2026-52889 🧪 | Formie: Server-Side Template Injection in Formie Hidden field defaults | verbb | formie | Critical | 9.8 | 2026-08-19 14:57:13 | Deep Dive |
| CVE-2026-52834 🧪 | jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms | tirr-c | jxl-oxide | High | 7.3 | 2026-08-19 14:55:32 | Deep Dive |
| CVE-2026-52792 🧪 | Algernon: Server-side script source disclosure on Windows via NTFS filename | xyproto | algernon | High | 8.7 | 2026-08-19 14:49:45 | Deep Dive |
| CVE-2026-49289 🧪 | SimpleSAMLphp SAML2: Possible DoS via XPath Transform | simplesamlphp | saml2 | High | 7.5 | 2026-08-19 14:48:53 | Deep Dive |
| CVE-2026-49283 🧪 | SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass | simplesamlphp | saml2 | High | 8.7 | 2026-08-19 14:47:06 | Deep Dive |