| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-70666 🧪 | Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs | Netflix | lemur | High | 7.4 | 2026-08-18 19:05:27 | Deep Dive |
| CVE-2026-71303 🧪 | Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist | Netflix | lemur | High | 7.7 | 2026-08-18 19:03:56 | Deep Dive |
| CVE-2026-71307 🧪 | Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API | Netflix | lemur | High | 7.7 | 2026-08-18 19:02:14 | Deep Dive |
| CVE-2026-71308 🧪 | Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates | Netflix | lemur | High | 8.1 | 2026-08-18 19:00:41 | Deep Dive |
| CVE-2026-55166 🧪 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR | Netflix | lemur | Critical | 9.9 | 2026-08-18 18:51:41 | Deep Dive |
| CVE-2026-17106 🧪 | Tar extraction in moby/go-archive can write outside the destination directory via link following | moby | go-archive | High | 7.1 | 2026-08-18 18:35:13 | Deep Dive |
| CVE-2025-9210 🧪 | Missing JSON Web Token signature validation in Otalio Ship Property Management System | Otalio | Ship Property Management System | High | 8.1 | 2026-08-18 18:25:47 | Deep Dive |
| CVE-2026-47629 🧪 | NVIDIA Triton Inference Server 输入验证错误漏洞 | NVIDIA | Triton Inference Server | High | 7.5 | 2026-08-18 18:24:00 | Deep Dive |
| CVE-2026-47628 🧪 | NVIDIA Triton Inference Server 资源管理错误漏洞 | NVIDIA | Triton Inference Server | High | 7.5 | 2026-08-18 18:23:59 | Deep Dive |
| CVE-2026-47627 🧪 | NVIDIA Triton Inference Server 路径遍历漏洞 | NVIDIA | Triton Inference Server | Critical | 9.8 | 2026-08-18 18:23:58 | Deep Dive |
| CVE-2026-24185 🧪 | NVIDIA NVOS 授权问题漏洞 | NVIDIA | NVOS | High | 7.1 | 2026-08-18 18:16:23 | Deep Dive |
| CVE-2026-24184 🧪 | NVIDIA Cumulus Linux GA 缓冲区错误漏洞 | NVIDIA | Cumulus Linux GA | High | 7.5 | 2026-08-18 18:16:22 | Deep Dive |
| CVE-2026-24183 🧪 | NVIDIA Cumulus Linux GA 权限许可和访问控制问题漏洞 | NVIDIA | Cumulus Linux GA | High | 7.8 | 2026-08-18 18:16:21 | Deep Dive |
| CVE-2026-71551 🧪 | Super Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with Persistent Whitelist | super-productivity | super-productivity | High | 7.8 | 2026-08-18 18:06:19 | Deep Dive |
| CVE-2026-48508 🧪 | Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission | Netflix | lemur | High | 8.8 | 2026-08-18 18:03:09 | Deep Dive |
| CVE-2026-71880 🧪 | Server-side template injection in Integrated Publishing Toolkit | GBIF | Integrated Publishing Toolkit | High | 7.6 | 2026-08-18 17:56:55 | Deep Dive |
| CVE-2026-75625 🧪 | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass | uber | kraken | Critical | 9.0 | 2026-08-18 17:56:54 | Deep Dive |
| CVE-2026-50161 🧪 | libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow | baresip | re | Critical | 9.3 | 2026-08-18 17:53:02 | Deep Dive |
| CVE-2026-50143 🧪 | Actor MCP path authority injection leaks Apify token | apify | apify-mcp-server | High | 8.1 | 2026-08-18 17:51:19 | Deep Dive |
| CVE-2026-71879 🧪 | Authentication bypass in Integrated Publishing Toolkit | GBIF | Integrated Publishing Toolkit | Critical | 9.1 | 2026-08-18 17:41:48 | Deep Dive |