| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-74792 🧪 | Scriban before 7.0.0 Stack Overflow via nested array initializers | scriban | scriban | High | 7.5 | 2026-08-16 13:14:16 | Deep Dive |
| CVE-2026-74791 🧪 | Scriban before 7.0.0 Authorization Bypass via Stale Include Cache | scriban | scriban | High | 8.6 | 2026-08-16 13:14:15 | Deep Dive |
| CVE-2026-74790 🧪 | Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache | scriban | scriban | Critical | 9.1 | 2026-08-16 13:14:14 | Deep Dive |
| CVE-2026-74789 🧪 | Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations | scriban | scriban | High | 7.5 | 2026-08-16 13:14:14 | Deep Dive |
| CVE-2026-74788 🧪 | Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right | scriban | scriban | High | 7.5 | 2026-08-16 13:14:13 | Deep Dive |
| CVE-2026-74787 🧪 | Scriban before 7.0.0 Uncontrolled Recursion via object.to_json | scriban | scriban | High | 7.5 | 2026-08-16 13:14:12 | Deep Dive |
| CVE-2026-74784 🧪 | Scriban before 7.2.0 Denial of Service via array.insert_at | scriban | scriban | High | 8.7 | 2026-08-16 13:14:11 | Deep Dive |
| CVE-2026-74783 🧪 | Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service | scriban | scriban | High | 7.5 | 2026-08-16 13:14:09 | Deep Dive |
| CVE-2026-73062 🧪 | Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication | scriban | scriban | High | 7.5 | 2026-08-16 13:14:09 | Deep Dive |
| CVE-2026-73061 🧪 | Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor | scriban | scriban | Critical | 9.8 | 2026-08-16 13:14:08 | Deep Dive |
| CVE-2026-73060 🧪 | Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply | scriban | scriban | High | 7.5 | 2026-08-16 13:14:07 | Deep Dive |
| CVE-2026-73057 🧪 | stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service | stoatchat | stoatchat | High | 7.5 | 2026-08-16 13:14:05 | Deep Dive |
| CVE-2024-58375 🧪 | OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation | opentofu | opentofu | High | 7.5 | 2026-08-16 13:14:04 | Deep Dive |
| CVE-2026-19924 🧪 | Tenda AC10 httpd R7WebsSecurityHandler improper authentication | Tenda | AC10 | Critical | 9.8 | 2026-08-16 01:00:13 | Deep Dive |
| CVE-2026-19919 🧪 | code-projects Online Shopping System Login login.php sql injection | code-projects | Online Shopping System | High | 7.3 | 2026-08-15 23:30:11 | Deep Dive |
| CVE-2026-74767 🧪 | Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompression Bomb | pandora-analysis | pandora | High | 8.7 | 2026-08-15 21:56:45 | Deep Dive |
| CVE-2026-74764 🧪 | Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora | pandora-analysis | pandora | Critical | 10.0 | 2026-08-15 21:39:10 | Deep Dive |
| CVE-2026-19905 🧪 | Jinher OA attendance_out_approve.aspx sql injection | Jinher | OA | High | 7.3 | 2026-08-15 18:45:08 | Deep Dive |
| CVE-2026-19598 📌 💣 | Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router | sc0ttkclark | Pods – Custom Content Types and Fields | Critical | 9.8 | 2026-08-15 17:25:27 | Deep Dive |
| CVE-2026-19901 🧪 | LB-LINK X-PRO easycwmp hard-coded credentials | LB-LINK | X-PRO | High | 8.1 | 2026-08-15 17:15:08 | Deep Dive |