| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-59902 🧪 | Netty: Memory Exhaustion in SctpMessageCompletionHandler | netty | netty | High | 7.5 | 2026-08-17 17:48:56 | Deep Dive |
| CVE-2026-54284 🧪 | sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger | andialbrecht | sqlparse | High | 8.7 | 2026-08-17 17:43:48 | Deep Dive |
| CVE-2026-59893 🧪 | sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service) | andialbrecht | sqlparse | High | 7.5 | 2026-08-17 17:41:37 | Deep Dive |
| CVE-2026-71979 🧪 | INDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag Parsing | indilib | indi | High | 7.5 | 2026-08-17 17:40:38 | Deep Dive |
| CVE-2026-71491 🧪 | sqlparse: Quadratic O(n²) DoS in group_comments | andialbrecht | sqlparse | High | 8.7 | 2026-08-17 17:16:49 | Deep Dive |
| CVE-2026-74253 🧪 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 | regularlabs.com | Sourcerer extension for Joomla | Critical | 10.0 | 2026-08-17 17:12:55 | Deep Dive |
| CVE-2026-68519 🧪 | Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) | nicolargo | glances | High | 7.1 | 2026-08-17 17:10:26 | Deep Dive |
| CVE-2026-62982 🧪 | Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection | nicolargo | glances | High | 8.8 | 2026-08-17 17:07:49 | Deep Dive |
| CVE-2026-68518 🧪 | Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction | nicolargo | glances | High | 8.8 | 2026-08-17 16:18:29 | Deep Dive |
| CVE-2026-61666 🧪 | websocket-driver: Denial of service via malformed Host header | faye | websocket-driver-ruby | High | 8.9 | 2026-08-17 16:16:33 | Deep Dive |
| CVE-2026-71479 🧪 | New API: Integer overflow in quota billing yields negative charges (self-crediting) | QuantumNous | new-api | Critical | 9.1 | 2026-08-17 16:11:28 | Deep Dive |
| CVE-2026-64866 🧪 | New API: Admin can reset passkeys for same-level or higher-privileged users | QuantumNous | new-api | Medium | 5.1 | 2026-08-17 16:06:39 | Deep Dive |
| CVE-2025-27772 🧪 | Uptrain vulnerable to remote code execution via `/new_run` endpoint | uptrain-ai | uptrain | High | 7.4 | 2026-08-17 15:47:51 | Deep Dive |
| CVE-2025-27771 🧪 | Uptrain vulnerable to remote code execution via `/add_prompts` endpoint | uptrain-ai | uptrain | High | 7.4 | 2026-08-17 15:44:26 | Deep Dive |
| CVE-2026-64868 🧪 | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging | QuantumNous | new-api | High | 7.5 | 2026-08-17 15:44:14 | Deep Dive |
| CVE-2025-27770 🧪 | UpTrain vulnerable to Remote code execution at `/create_project` | uptrain-ai | uptrain | High | 7.4 | 2026-08-17 15:43:21 | Deep Dive |
| CVE-2025-27621 🧪 | UpTrain has a Constant Default API Key | uptrain-ai | uptrain | High | 7.7 | 2026-08-17 15:42:31 | Deep Dive |
| CVE-2026-64859 🧪 | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation | QuantumNous | new-api | Critical | 9.1 | 2026-08-17 15:42:19 | Deep Dive |
| CVE-2026-73646 🧪 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure | postcss | postcss | High | 7.5 | 2026-08-17 15:35:14 | Deep Dive |
| CVE-2026-71567 🧪 | User-controlled variables inserted unescaped into shell scripts and Kubernetes manifests | openshift-metal3 | fakefish | High | 7.7 | 2026-08-17 14:39:10 | Deep Dive |