| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-81578 KEV 📌 💣 | PaperCut MF/NG: Authentication Bypass | PaperCut | PaperCut MF/NG | High | 8.8 | 2026-08-28 11:39:45 | Deep Dive |
| CVE-2026-82222 🧪 💣 | WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability | Liquid Web / StellarWP | GiveWP | Critical | 10.0 | 2026-08-28 10:46:14 | Deep Dive |
| CVE-2026-37736 🧪 | OWASP json-sanitizer 资源管理错误漏洞 | - | - | 高危 | - | 2026-08-28 00:00:00 | Deep Dive |
| CVE-2026-81730 🧪 | Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename | Dolibarr | dolibarr | High | 8.2 | 2026-08-27 20:07:35 | Deep Dive |
| CVE-2026-19092 📌 💣 | Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing | Unknown | Tutor LMS | Critical | 9.8 | 2026-08-27 17:05:38 | Deep Dive |
| CVE-2026-75005 🧪 | Apache APISIX: Unauthenticated CPU-exhaustion DoS | Apache Software Foundation | Apache APISIX | High | 8.7 | 2026-08-27 09:15:32 | Deep Dive |
| CVE-2026-81491 🧪 | boxpositron with-context-mcp index.ts project_folder path traversal | boxpositron | with-context-mcp | High | 7.3 | 2026-08-27 02:15:10 | Deep Dive |
| CVE-2026-81421 🧪 | ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery | ddfourtwo | sentry-selfhosted-mcp | High | 7.3 | 2026-08-26 23:45:10 | Deep Dive |
| CVE-2026-47862 🧪 | ZipTransformer uses file_name header to build workDirectory path without sanitization | Spring | Spring Integration | Medium | 5.4 | 2026-08-26 23:28:48 | Deep Dive |
| CVE-2026-47860 🧪 | Unbounded decompression of attacker-supplied compressed message bodies | Spring | Spring AMQP | Medium | 6.5 | 2026-08-26 23:28:47 | Deep Dive |
| CVE-2026-47665 🧪 | Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML | penpot | penpot | High | 8.7 | 2026-08-26 22:50:34 | Deep Dive |
| CVE-2026-65956 🧪 | KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF | 1Panel-dev | KubePi | Critical | 10.0 | 2026-08-26 22:40:56 | Deep Dive |
| CVE-2026-81203 🧪 | SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection | SourceCodester | Simple Online Food Ordering System | High | 7.3 | 2026-08-26 22:30:12 | Deep Dive |
| CVE-2026-81202 🧪 | itsourcecode Payroll System CRUD Operation ajax.php delete missing authentication | itsourcecode | Payroll System | High | 7.3 | 2026-08-26 21:30:12 | Deep Dive |
| CVE-2026-77298 🧪 | SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy | seaweedfs | seaweedfs | High | 8.7 | 2026-08-26 21:16:51 | Deep Dive |
| CVE-2026-61792 🧪 | Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242) | WeblateOrg | weblate | High | 7.7 | 2026-08-26 20:26:28 | Deep Dive |
| CVE-2026-79921 🧪 | amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload | rabbitmq | amqp091-go | High | 8.9 | 2026-08-26 20:24:58 | Deep Dive |
| CVE-2026-55228 🧪 | Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project | WeblateOrg | weblate | High | 8.1 | 2026-08-26 20:14:03 | Deep Dive |
| CVE-2026-60004 KEV 🧪 💣 | Gitea 代码注入漏洞 EPSS 0.87 | Gitea | Gitea | Critical | 9.8 | 2026-08-26 19:45:00 | Deep Dive |
| CVE-2026-46369 🧪 | Nimiq: Validity store off by one error | nimiq | core-rs-albatross | High | 7.5 | 2026-08-26 19:32:46 | Deep Dive |