| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19900 🧪 💣 | LB-LINK X-PRO shadow hard-coded credentials | LB-LINK | X-PRO | High | 8.1 | 2026-08-15 16:45:07 | Deep Dive |
| CVE-2026-19899 🧪 | SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection | SourceCodester | Class and Exam Timetabling System | High | 7.3 | 2026-08-15 16:30:09 | Deep Dive |
| CVE-2026-19474 🧪 | @fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted upload | @fastify/multipart | @fastify/multipart | High | 7.5 | 2026-08-15 13:36:13 | Deep Dive |
| CVE-2026-18549 🧪 | @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit | @fastify/multipart | @fastify/multipart | High | 7.5 | 2026-08-15 13:26:54 | Deep Dive |
| CVE-2026-18500 🧪 | @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key | @fastify/jwt | @fastify/jwt | High | 8.1 | 2026-08-15 13:16:12 | Deep Dive |
| CVE-2026-15826 📌 💣 | User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Critical | 9.8 | 2026-08-15 06:38:10 | Deep Dive |
| CVE-2026-73683 🧪 | Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay | Laravel | Socialite | High | 8.1 | 2026-08-14 21:32:18 | Deep Dive |
| CVE-2026-73680 🧪 | Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename | Cockpit HQ | Cockpit CMS | High | 8.8 | 2026-08-14 19:56:32 | Deep Dive |
| CVE-2026-45699 🧪 | Netatalk has Integer Underflow → Stack Buffer Overflow in copydir() | Netatalk | netatalk | High | 7.5 | 2026-08-14 19:05:47 | Deep Dive |
| CVE-2026-73679 🧪 | ImpressCMS Authenticated RCE via PHP Custom Tag eval() | ImpressCMS | ImpressCMS | High | 7.2 | 2026-08-14 19:03:25 | Deep Dive |
| CVE-2026-73678 🧪 | MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec() | MindsDB | Minds Platform | Critical | 10.0 | 2026-08-14 18:49:36 | Deep Dive |
| CVE-2026-49457 🧪 | QUIC has Broken TLS verification | benoitc | erlang_quic | Critical | 9.1 | 2026-08-14 18:27:21 | Deep Dive |
| CVE-2026-48528 🧪 | Metacat has an unauthenticated SQL injection vulnerability | NCEAS | metacat | Critical | 9.8 | 2026-08-14 17:56:35 | Deep Dive |
| CVE-2026-73850 🧪 | Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function | emlog | emlog | High | 8.6 | 2026-08-14 17:46:26 | Deep Dive |
| CVE-2026-73849 🧪 | emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. | emlog | emlog | Critical | 9.8 | 2026-08-14 17:37:20 | Deep Dive |
| CVE-2026-19846 🧪 | TOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 17:15:09 | Deep Dive |
| CVE-2026-19845 🧪 | TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 17:00:10 | Deep Dive |
| CVE-2026-19844 🧪 | TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 16:45:11 | Deep Dive |
| CVE-2026-49989 🧪 | CrateDB's Blob HTTP handler bypasses authorization | crate | crate | High | 7.1 | 2026-08-14 16:29:17 | Deep Dive |
| CVE-2026-49986 🧪 | Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` | cdeust | Cortex | High | 7.1 | 2026-08-14 16:21:39 | Deep Dive |