| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-49289 🧪 | SimpleSAMLphp SAML2: Possible DoS via XPath Transform | simplesamlphp | saml2 | High | 7.5 | 2026-08-19 14:48:53 | Deep Dive |
| CVE-2026-49283 🧪 | SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass | simplesamlphp | saml2 | High | 8.7 | 2026-08-19 14:47:06 | Deep Dive |
| CVE-2026-53451 🧪 | Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution | sgoudelis | ground-station | Critical | 9.8 | 2026-08-19 14:45:24 | Deep Dive |
| CVE-2026-48711 🧪 | SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | libfuse | sshfs | High | 7.0 | 2026-08-19 14:42:50 | Deep Dive |
| CVE-2026-47187 🧪 | SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write | libfuse | sshfs | Critical | 9.3 | 2026-08-19 14:41:58 | Deep Dive |
| CVE-2026-75949 🧪 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 | cmsjunkie.com | J-BusinessDirectory extension for Joomla | Critical | 10.0 | 2026-08-19 14:40:42 | Deep Dive |
| CVE-2026-45272 🧪 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | PoxenStudio | talebook | Critical | 9.4 | 2026-08-19 14:39:50 | Deep Dive |
| CVE-2026-45273 🧪 | MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint | PoxenStudio | talebook | High | 8.7 | 2026-08-19 14:37:45 | Deep Dive |
| CVE-2026-44829 🧪 | Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename | gotenberg | gotenberg | High | 8.8 | 2026-08-19 14:35:07 | Deep Dive |
| CVE-2026-45742 🧪 | Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | gotenberg | gotenberg | High | 7.5 | 2026-08-19 14:34:15 | Deep Dive |
| CVE-2026-45741 🧪 | Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes | gotenberg | gotenberg | High | 7.5 | 2026-08-19 14:32:50 | Deep Dive |
| CVE-2026-49253 🧪 | electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling | electerm | electerm | High | 7.1 | 2026-08-19 14:31:56 | Deep Dive |
| CVE-2026-49255 🧪 | electerm: Command Injection in File System Operations (rmrf, mv, cp) | electerm | electerm | High | 8.8 | 2026-08-19 14:30:13 | Deep Dive |
| CVE-2026-43961 🧪 | Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() filter() expression allows arbitrary code execution | vim | vim | High | 7.8 | 2026-08-19 14:06:09 | Deep Dive |
| CVE-2026-76245 🧪 | stigmem Federation Peer Token Timestamp Validation Bypass | eidetic-labs | stigmem | High | 7.1 | 2026-08-19 14:02:22 | Deep Dive |
| CVE-2026-76244 🧪 | stigmem-node Insecure Federation Transport Configuration | eidetic-labs | stigmem | Critical | 9.1 | 2026-08-19 14:02:21 | Deep Dive |
| CVE-2026-76243 🧪 | stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth | eidetic-labs | stigmem | Critical | 9.2 | 2026-08-19 14:02:20 | Deep Dive |
| CVE-2026-76242 🧪 | stigmem Federation Peer Registration Authentication Bypass | eidetic-labs | stigmem | Critical | 9.1 | 2026-08-19 14:02:19 | Deep Dive |
| CVE-2026-76241 🧪 | stigmem Plugin Signature Enforcement Bypass via Configuration | eidetic-labs | stigmem | High | 7.3 | 2026-08-19 14:02:19 | Deep Dive |
| CVE-2026-76240 🧪 | stigmem Postgres SQL Injection via Schema Identifier | eidetic-labs | stigmem | High | 7.5 | 2026-08-19 14:02:18 | Deep Dive |