| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-66003 🧪 | Frappe: Access control bypass via REST API dot-notation fields on linked doctypes | frappe | frappe | High | 7.1 | 2026-08-26 19:30:29 | Deep Dive |
| CVE-2026-32258 🧪 | Winter: Stored XSS through Editor Settings custom styles | wintercms | winter | High | 8.1 | 2026-08-26 16:49:07 | Deep Dive |
| CVE-2026-35445 🧪 | Winter: Authenticated backend users can bypass Users controller permission checks | wintercms | winter | High | 7.1 | 2026-08-26 16:40:52 | Deep Dive |
| CVE-2026-81036 🧪 | Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri | stalwartlabs | stalwart | High | 8.1 | 2026-08-26 15:45:03 | Deep Dive |
| CVE-2026-81035 🧪 | Midday Missing Owner Check on Team Deletion | midday-ai | midday | High | 8.1 | 2026-08-26 15:45:02 | Deep Dive |
| CVE-2026-81032 🧪 | NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration | vesoft-inc | nebula | Critical | 9.8 | 2026-08-26 15:45:00 | Deep Dive |
| CVE-2026-81027 🧪 | one-api through 0.6.10 Missing Authorization on URL-Parameter Channel Pinning | songquanpeng | one-api | High | 8.5 | 2026-08-26 15:44:57 | Deep Dive |
| CVE-2026-80427 🧪 | bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option Delimiter | nfriedly | bestzip | High | 8.4 | 2026-08-26 15:44:55 | Deep Dive |
| CVE-2026-54511 🧪 | @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys | dahlia | logtape | High | 8.6 | 2026-08-26 14:27:28 | Deep Dive |
| CVE-2026-54550 🧪 | IzPack: Path Traversal in UnpackerBase allows writing files outside the installation directory via malicious pack entries | izpack | izpack | High | 7.4 | 2026-08-26 14:24:07 | Deep Dive |
| CVE-2026-54523 🧪 | Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system | kyverno | kyverno | Critical | 9.6 | 2026-08-26 14:20:37 | Deep Dive |
| CVE-2026-54556 🧪 | Http4s: HTTP/2 Denial of Service with Ember Backend | http4s | http4s | High | 8.2 | 2026-08-26 14:10:22 | Deep Dive |
| CVE-2026-73108 🧪 | RustDesk < 1.4.7 Uncontrolled Memory Allocation DoS via BytesCodec | rustdesk | rustdesk | High | 7.5 | 2026-08-26 13:00:29 | Deep Dive |
| CVE-2026-79619 🧪 | OpenZFS: user-namespace capability check allows unprivileged local authorization bypass | OpenZFS | OpenZFS | High | 7.3 | 2026-08-26 12:50:11 | Deep Dive |
| CVE-2026-76148 🧪 | SASAKI Nobuyuki CorvusSKK 代码注入漏洞 | SASAKI Nobuyuki | CorvusSKK | High | 8.4 | 2026-08-26 04:55:07 | Deep Dive |
| CVE-2026-19632 📌 💣 | TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure | cozmoslabs | TranslatePress – Translate Multilingual sites with AI Translation | Critical | 9.8 | 2026-08-26 03:39:23 | Deep Dive |
| CVE-2026-57171 🧪 | Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345) | oscal-compass | compliance-trestle | High | 7.7 | 2026-08-25 23:39:16 | Deep Dive |
| CVE-2026-80202 🧪 | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter | kimai | kimai | High | 8.8 | 2026-08-25 23:19:07 | Deep Dive |
| CVE-2026-80198 🧪 | Kimai before 2.56.0 Information Disclosure via config() Twig Function | kimai | kimai | High | 7.5 | 2026-08-25 23:19:04 | Deep Dive |
| CVE-2026-80196 🧪 | Kimai before 2.58.0 Authentication Bypass via Password Reset Link | kimai | kimai | High | 7.5 | 2026-08-25 23:19:03 | Deep Dive |