| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19757 🧪 | Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal | Dromara | lamp-cloud | High | 7.3 | 2026-08-13 23:15:10 | Deep Dive |
| CVE-2026-19753 🧪 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery | Model Context Protocol | mcp-rdf-explorer | High | 7.3 | 2026-08-13 22:15:12 | Deep Dive |
| CVE-2026-73305 🧪 | Budibase: Privilege escalation via public role assignment API missing app-level authorization | Budibase | budibase | High | 8.8 | 2026-08-13 22:05:03 | Deep Dive |
| CVE-2026-73408 🧪 | Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector | Budibase | budibase | High | 7.6 | 2026-08-13 22:04:54 | Deep Dive |
| CVE-2026-73302 🧪 | Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified | Budibase | budibase | Critical | 9.0 | 2026-08-13 22:04:50 | Deep Dive |
| CVE-2026-73421 🧪 | NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) | nextauthjs | next-auth | Critical | 9.1 | 2026-08-13 22:04:37 | Deep Dive |
| CVE-2026-73417 🧪 | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) | jupyterlab | jupyterlab | High | 8.6 | 2026-08-13 22:04:32 | Deep Dive |
| CVE-2026-73420 🧪 | NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass | nextauthjs | next-auth | Critical | 9.1 | 2026-08-13 22:04:15 | Deep Dive |
| CVE-2026-73843 🧪 | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs | openchoreo | openchoreo | Critical | 9.6 | 2026-08-13 22:02:41 | Deep Dive |
| CVE-2026-73842 🧪 | OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation | openchoreo | openchoreo | Critical | 9.0 | 2026-08-13 21:59:24 | Deep Dive |
| CVE-2026-73841 🧪 | OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints | openchoreo | openchoreo | High | 8.8 | 2026-08-13 21:56:13 | Deep Dive |
| CVE-2026-72857 🧪 | Budibase before 3.40.0 Credential Exposure via STRING Fields | Budibase | budibase | High | 7.7 | 2026-08-13 21:54:46 | Deep Dive |
| CVE-2026-72856 🧪 | Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email | Budibase | budibase | High | 8.1 | 2026-08-13 21:54:45 | Deep Dive |
| CVE-2026-72855 🧪 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST | budibase | server | High | 8.5 | 2026-08-13 21:54:45 | Deep Dive |
| CVE-2026-72853 🧪 | Budibase before 3.40.0 SQL Injection via Oracle connector | Budibase | budibase | High | 7.6 | 2026-08-13 21:54:44 | Deep Dive |
| CVE-2026-72851 🧪 | Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook | budibase | server | Critical | 10.0 | 2026-08-13 21:54:43 | Deep Dive |
| CVE-2026-72850 🧪 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | budibase | server | Critical | 9.1 | 2026-08-13 21:54:43 | Deep Dive |
| CVE-2026-72849 🧪 | Budibase before 3.40.0 Identity Confusion via Chat-Link Handoff CSRF | budibase | server | High | 7.7 | 2026-08-13 21:54:42 | Deep Dive |
| CVE-2026-72842 🧪 | OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass | openwrt | luci | Critical | 9.9 | 2026-08-13 21:54:41 | Deep Dive |
| CVE-2026-72841 🧪 | luci-app-openvpn Path Traversal RCE via instance_name2 | openwrt | luci | Critical | 9.9 | 2026-08-13 21:54:41 | Deep Dive |