| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71878 🧪 | Authentication bypass in Integrated Publishing Toolkit | GBIF | Integrated Publishing Toolkit | Critical | 9.2 | 2026-08-18 17:41:34 | Deep Dive |
| CVE-2026-54552 🧪 | sh _uid does not drop supplementary groups (incomplete privilege drop) | amoffat | sh | High | 7.9 | 2026-08-18 17:37:40 | Deep Dive |
| CVE-2026-74038 🧪 | Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment | Wazuh | wazuh-manager | High | 7.1 | 2026-08-18 17:25:08 | Deep Dive |
| CVE-2026-44472 🧪 | Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge | saleor | saleor | High | 8.1 | 2026-08-18 17:11:42 | Deep Dive |
| CVE-2026-18963 📌 💣 | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass | Red Hat | Red Hat build of Keycloak 26.4 | Critical | 9.1 | 2026-08-18 17:05:07 | Deep Dive |
| CVE-2026-57580 🧪 | authentik: Account Takeover via SAML NameID Comment Truncation | goauthentik | authentik | Critical | 9.4 | 2026-08-18 17:00:19 | Deep Dive |
| CVE-2026-61574 🧪 | authentik RAC: access any endpoint via an unrelated application | goauthentik | authentik | High | 8.8 | 2026-08-18 16:57:47 | Deep Dive |
| CVE-2026-54730 🧪 | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView | goauthentik | authentik | High | 8.6 | 2026-08-18 16:55:30 | Deep Dive |
| CVE-2026-50577 🧪 | ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter | fbeta-GmbH | ePA3-Service-OpenSource | High | 7.4 | 2026-08-18 16:52:38 | Deep Dive |
| CVE-2026-50578 🧪 | ePA 3.x Integration: TLS Certificate Verification Universally Disabled | fbeta-GmbH | ePA3-Service-OpenSource | High | 7.5 | 2026-08-18 16:51:45 | Deep Dive |
| CVE-2026-52723 🧪 | ePA 3.x Integration: VAU Server Authentication Bypass via Circular Certificate Trust | fbeta-GmbH | ePA3-Service-OpenSource | Critical | 9.1 | 2026-08-18 16:50:50 | Deep Dive |
| CVE-2026-19869 🧪 | Privilege Escalation via Dropped Field-Level @authentication | neo4j | graphql | High | 7.6 | 2026-08-18 16:35:20 | Deep Dive |
| CVE-2026-63337 🧪 | RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading | rabbitmq | rabbitmq-java-client | High | 7.5 | 2026-08-18 16:27:10 | Deep Dive |
| CVE-2026-69220 🧪 | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS | rabbitmq | rabbitmq-java-client | High | 8.7 | 2026-08-18 16:25:16 | Deep Dive |
| CVE-2026-69219 🧪 | RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation | rabbitmq | rabbitmq-java-client | High | 8.7 | 2026-08-18 16:23:32 | Deep Dive |
| CVE-2026-49223 🧪 | Vvveb product review authorization bypass allows Vendors to read, approve, edit, or delete reviews under other Vendors' products | givanz | Vvveb | High | 7.6 | 2026-08-18 16:18:10 | Deep Dive |
| CVE-2026-49224 🧪 | Vvveb post revision authorization bypass allows Authors to read, restore, or delete other Authors' post revisions | givanz | Vvveb | High | 8.3 | 2026-08-18 16:17:31 | Deep Dive |
| CVE-2026-49222 🧪 | Vvveb product question authorization bypass allows Vendors to read, approve, edit, or delete questions under other Vendors' products | givanz | Vvveb | High | 7.6 | 2026-08-18 16:17:01 | Deep Dive |
| CVE-2026-49225 🧪 | Vvveb product revision authorization bypass allows Vendors to read, restore, or delete other Vendors' product revisions | givanz | Vvveb | High | 8.3 | 2026-08-18 16:16:25 | Deep Dive |
| CVE-2026-49228 🧪 | Vvveb product authorization bypass allows Vendors to read, duplicate, or delete other Vendors' products | givanz | Vvveb | High | 8.8 | 2026-08-18 16:15:46 | Deep Dive |