| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-52876 🧪 | Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback | truelockmc | streambert | High | 8.8 | 2026-08-18 21:29:08 | Deep Dive |
| CVE-2026-52872 🧪 | Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol | truelockmc | streambert | High | 8.8 | 2026-08-18 21:26:26 | Deep Dive |
| CVE-2026-62292 🧪 | libheif: Out-of-bounds read in uncompressed unci tile range slicing | strukturag | libheif | High | 8.7 | 2026-08-18 21:20:25 | Deep Dive |
| CVE-2026-50142 🧪 | libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check) | strukturag | libheif | High | 7.5 | 2026-08-18 21:18:04 | Deep Dive |
| CVE-2026-53455 🧪 | Blueprint Studio Git credential helper command injection | ha-china | blueprint-studio | High | 8.6 | 2026-08-18 20:49:36 | Deep Dive |
| CVE-2026-53453 🧪 | Blueprint Studio API authorization bypass for non-admin Home Assistant users | ha-china | blueprint-studio | High | 8.7 | 2026-08-18 20:48:21 | Deep Dive |
| CVE-2026-54347 🧪 | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover | froxlor | froxlor | High | 8.7 | 2026-08-18 20:16:37 | Deep Dive |
| CVE-2026-54348 🧪 | Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration | froxlor | froxlor | High | 7.2 | 2026-08-18 20:15:32 | Deep Dive |
| CVE-2026-62988 🧪 | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints | froxlor | froxlor | Critical | 9.0 | 2026-08-18 20:10:38 | Deep Dive |
| CVE-2026-52793 🧪 | Froxlor: API Authentication bypasses 2FA Authentication | froxlor | froxlor | High | 8.1 | 2026-08-18 20:09:33 | Deep Dive |
| CVE-2026-65984 🧪 | FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions | frangoteam | FUXA | High | 7.5 | 2026-08-18 20:07:25 | Deep Dive |
| CVE-2026-67443 🧪 | FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) | frangoteam | FUXA | Critical | 9.2 | 2026-08-18 20:06:16 | Deep Dive |
| CVE-2026-47719 🧪 | FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading | frangoteam | FUXA | High | 8.2 | 2026-08-18 19:59:29 | Deep Dive |
| CVE-2026-75877 🧪 | TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow | TRENDnet | TV-IP751WIC | Critical | 9.9 | 2026-08-18 19:45:08 | Deep Dive |
| CVE-2026-75936 🧪 | Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java | Amazon Ion | Amazon Ion Java | High | 7.5 | 2026-08-18 19:34:19 | Deep Dive |
| CVE-2026-75935 🧪 | Memory-amplification denial of service via declared-length preallocation in Amazon ion-java | Amazon Ion | Amazon Ion Java | High | 7.5 | 2026-08-18 19:33:47 | Deep Dive |
| CVE-2026-52829 🧪 | ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book | ZcashFoundation | zebra | High | 7.5 | 2026-08-18 19:27:57 | Deep Dive |
| CVE-2026-52736 🧪 | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache | ZcashFoundation | zebra | High | 8.7 | 2026-08-18 19:26:41 | Deep Dive |
| CVE-2026-52735 🧪 | ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser | ZcashFoundation | zebra | Critical | 9.3 | 2026-08-18 19:23:11 | Deep Dive |
| CVE-2026-71417 🧪 | Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it | Netflix | lemur | High | 7.3 | 2026-08-18 19:12:16 | Deep Dive |