| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-75852 🧪 | ArcadeDB MongoDB wire protocol authentication bypass cross-database | ArcadeData | arcadedb | Critical | 9.8 | 2026-08-18 11:19:56 | Deep Dive |
| CVE-2026-75851 🧪 | ArcadeDB before 26.8.1 Authentication Bypass via Async Command | ArcadeData | arcadedb | Critical | 9.9 | 2026-08-18 11:19:55 | Deep Dive |
| CVE-2026-75846 🧪 | ArcadeDB before 26.8.1 Unauthorized Function Deletion via DELETE FUNCTION | ArcadeData | arcadedb | High | 7.1 | 2026-08-18 11:19:53 | Deep Dive |
| CVE-2026-75844 🧪 | ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass | ArcadeData | arcadedb | High | 7.1 | 2026-08-18 11:19:52 | Deep Dive |
| CVE-2026-75842 🧪 | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV | ArcadeData | arcadedb | High | 7.7 | 2026-08-18 11:19:51 | Deep Dive |
| CVE-2026-75843 🧪 | ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction | ArcadeData | arcadedb | Critical | 9.9 | 2026-08-18 11:19:51 | Deep Dive |
| CVE-2026-75840 🧪 | ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex | ArcadeData | arcadedb | High | 7.5 | 2026-08-18 11:19:49 | Deep Dive |
| CVE-2026-75838 🧪 | DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook | cure53 | DOMPurify | Medium | 5.1 | 2026-08-18 11:19:48 | Deep Dive |
| CVE-2026-75837 🧪 | Grav before 2.0.14 Privilege Escalation via Group Access Field | getgrav | grav | Critical | 9.1 | 2026-08-18 11:19:47 | Deep Dive |
| CVE-2026-75836 🧪 | Grav API Plugin before 1.0.14 Missing Authorization | getgrav | grav | High | 8.8 | 2026-08-18 11:19:46 | Deep Dive |
| CVE-2026-75831 🧪 | Grav before 2.0.15 Stored XSS via audio/video source URL | getgrav | grav | High | 7.6 | 2026-08-18 11:19:43 | Deep Dive |
| CVE-2026-75830 🧪 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy | getgrav | grav | High | 7.1 | 2026-08-18 11:19:42 | Deep Dive |
| CVE-2026-75829 🧪 | grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint | getgrav | grav | High | 8.1 | 2026-08-18 11:19:42 | Deep Dive |
| CVE-2026-75828 🧪 | Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass | getgrav | grav | High | 8.7 | 2026-08-18 11:19:41 | Deep Dive |
| CVE-2026-75827 🧪 | Grav before 2.0.15 Arbitrary File Write via error_log | getgrav | grav | High | 8.8 | 2026-08-18 11:19:40 | Deep Dive |
| CVE-2026-75627 🧪 | Bastillion Authentication Bypass via Path-Prefix Routing Mismatch | bastillion-io | Bastillion | Critical | 9.8 | 2026-08-18 10:46:55 | Deep Dive |
| CVE-2026-75626 🧪 | SpiderFoot Stored Cross-Site Scripting via Correlation Titles | smicallef | spiderfoot | Critical | 9.3 | 2026-08-18 10:46:54 | Deep Dive |
| CVE-2026-11801 📌 💣 | WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via classifieds-types REST Endpoint | gwin | WPAdverts – Classifieds Plugin | High | 7.5 | 2026-08-18 02:27:04 | Deep Dive |
| CVE-2026-75094 🧪 | COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection | COMFAST | CF-N1-S | Critical | 9.1 | 2026-08-18 01:45:10 | Deep Dive |
| CVE-2026-75089 🧪 | PHPGurukul Complaint Management System check_availability.php sql injection | PHPGurukul | Complaint Management System | High | 7.3 | 2026-08-18 01:00:11 | Deep Dive |