| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71566 🧪 | KubeVirt backend is not authenticated | openshift-metal3 | fakefish | Critical | 9.3 | 2026-08-17 14:22:17 | Deep Dive |
| CVE-2026-19693 🧪 | extract-zip arbitrary file write outside the destination directory via a symlink at the final path component | max-mapper | extract-zip | High | 8.1 | 2026-08-17 13:30:22 | Deep Dive |
| CVE-2026-75002 🧪 | Roundcube Webmail 命令注入漏洞 | Roundcube | Webmail | High | 7.1 | 2026-08-17 12:48:41 | Deep Dive |
| CVE-2026-74998 🧪 | Roundcube Webmail 跨站脚本漏洞 | Roundcube | Webmail | High | 7.2 | 2026-08-17 12:40:30 | Deep Dive |
| CVE-2026-74997 🧪 | Roundcube Webmail 命令注入漏洞 | Roundcube | Webmail | High | 8.8 | 2026-08-17 12:37:45 | Deep Dive |
| CVE-2026-18674 🧪 | Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unvalidated in-band zone identifier | Kong Inc. | Kong Mesh | High | 7.0 | 2026-08-17 12:08:11 | Deep Dive |
| CVE-2026-74843 🧪 | Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow | Wavlink | WN531P3 | Critical | 10.0 | 2026-08-17 11:15:08 | Deep Dive |
| CVE-2026-74901 🧪 | openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:05:00 | Deep Dive |
| CVE-2026-74899 🧪 | openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:59 | Deep Dive |
| CVE-2026-74900 🧪 | openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:59 | Deep Dive |
| CVE-2026-74896 🧪 | openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:58 | Deep Dive |
| CVE-2026-74895 🧪 | openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:57 | Deep Dive |
| CVE-2026-74894 🧪 | openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:57 | Deep Dive |
| CVE-2026-74893 🧪 | openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets | jahlives | openssl_encrypt | High | 8.8 | 2026-08-17 11:04:56 | Deep Dive |
| CVE-2026-74891 🧪 | openssl_encrypt before 1.4.0 Hardcoded Database Credentials | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:55 | Deep Dive |
| CVE-2026-74892 🧪 | openssl_encrypt before 1.4.0 Hardcoded Secret Key | jahlives | openssl_encrypt | High | 7.5 | 2026-08-17 11:04:55 | Deep Dive |
| CVE-2026-74889 🧪 | openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:53 | Deep Dive |
| CVE-2026-74888 🧪 | openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation | jahlives | openssl_encrypt | High | 7.5 | 2026-08-17 11:04:52 | Deep Dive |
| CVE-2026-74886 🧪 | openssl_encrypt before 1.4.0 Plugin Import Guard Bypass | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:51 | Deep Dive |
| CVE-2026-74884 🧪 | openssl_encrypt before 1.4.0 Path Traversal via plugin_id | jahlives | openssl_encrypt | High | 7.5 | 2026-08-17 11:04:50 | Deep Dive |