| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-75106 🧪 | OpnForm Editable Submission Secret Derivation via Empty Hashids Salt | OpnForm | OpnForm | Critical | 9.1 | 2026-08-17 20:36:02 | Deep Dive |
| CVE-2026-75105 🧪 | phpIPAM Temporary Subnet Share Information Disclosure via Address Parameter | phpipam | phpipam | High | 7.5 | 2026-08-17 20:36:01 | Deep Dive |
| CVE-2026-75103 🧪 | Crawlab Missing Authorization on Password Change Endpoint Allows Account Takeover | crawlab-team | crawlab | High | 8.8 | 2026-08-17 20:36:00 | Deep Dive |
| CVE-2026-54356 🧪 | Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` | Budibase | budibase | High | 7.1 | 2026-08-17 20:32:06 | Deep Dive |
| CVE-2026-35219 🧪 | Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist | Budibase | budibase | High | 7.1 | 2026-08-17 20:28:41 | Deep Dive |
| CVE-2026-73410 🧪 | Budibase: SSRF via DNS rebinding in the REST datasource integration | Budibase | budibase | High | 8.5 | 2026-08-17 20:27:24 | Deep Dive |
| CVE-2026-64657 🧪 | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL | Budibase | budibase | High | 8.4 | 2026-08-17 20:25:00 | Deep Dive |
| CVE-2026-57233 🧪 | Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction | notepad-plus-plus | notepad-plus-plus | High | 8.1 | 2026-08-17 20:10:38 | Deep Dive |
| CVE-2026-54758 🧪 | Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs | notepad-plus-plus | notepad-plus-plus | High | 7.8 | 2026-08-17 20:05:52 | Deep Dive |
| CVE-2026-19478 📌 💣 | Improper Control of Generation of Code ('Code Injection') in GitLab | GitLab | GitLab | Critical | 9.4 | 2026-08-17 20:04:46 | Deep Dive |
| CVE-2026-71553 🧪 | ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS | apostrophecms | apostrophe | High | 7.1 | 2026-08-17 20:03:38 | Deep Dive |
| CVE-2026-75014 🧪 | SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection | SourceCodester | Pet Grooming Management Software | High | 7.3 | 2026-08-17 19:45:09 | Deep Dive |
| CVE-2026-57485 🧪 | Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoint | Stirling-Tools | Stirling-PDF | High | 8.5 | 2026-08-17 19:31:31 | Deep Dive |
| CVE-2026-45698 🧪 | Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir() | Netatalk | netatalk | High | 7.5 | 2026-08-17 18:21:20 | Deep Dive |
| CVE-2026-74238 🧪 | TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder | tier4 | nebula | High | 7.5 | 2026-08-17 18:12:38 | Deep Dive |
| CVE-2026-73523 🧪 | COVESA Open1722 0.9.2 Stack Memory Disclosure via acf-can-listener.c Integer Truncation | COVESA | Open1722 | High | 7.5 | 2026-08-17 18:00:02 | Deep Dive |
| CVE-2026-33437 🧪 | Stirling PDF: Stored XSS in Info Summary | Stirling-Tools | Stirling-PDF | High | 8.1 | 2026-08-17 17:58:23 | Deep Dive |
| CVE-2026-46345 🧪 | compliance-trestle - jinja has an Arbitrary File Write via Path Traversal | oscal-compass | compliance-trestle | High | 8.4 | 2026-08-17 17:54:17 | Deep Dive |
| CVE-2026-73522 🧪 | COVESA Open1722 0.9.2 Stack Buffer Overflow via avtp_to_can() in acf-can-listener | COVESA | Open1722 | High | 7.5 | 2026-08-17 17:53:21 | Deep Dive |
| CVE-2026-71980 🧪 | Belledonne Communications bcg729 1.1.2 Out-of-Bounds Read via decodeSIDframe() | BelledonneCommunications | bcg729 | High | 7.5 | 2026-08-17 17:50:41 | Deep Dive |