| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-72840 🧪 | OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write | openwrt | luci | High | 8.8 | 2026-08-13 21:54:40 | Deep Dive |
| CVE-2026-72839 🧪 | filebrowser through 2.63.16 Privilege Escalation via Signup | filebrowser | filebrowser | Critical | 9.8 | 2026-08-13 21:54:39 | Deep Dive |
| CVE-2026-73667 🧪 | OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods | openchoreo | openchoreo | High | 8.8 | 2026-08-13 21:43:44 | Deep Dive |
| CVE-2026-73666 🧪 | OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete | openchoreo | backstage-plugins | High | 8.2 | 2026-08-13 21:40:14 | Deep Dive |
| CVE-2026-73665 🧪 | FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection | FreePBX | ucp | Critical | 9.3 | 2026-08-13 21:32:02 | Deep Dive |
| CVE-2026-73664 🧪 | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module | FreePBX | backup | High | 8.6 | 2026-08-13 21:30:38 | Deep Dive |
| CVE-2026-19750 🧪 | Tenda CH/CP/TX3 SSH hard-coded password | Tenda | CH | High | 8.1 | 2026-08-13 21:30:10 | Deep Dive |
| CVE-2026-73663 🧪 | FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover | FreePBX | missedcall | Critical | 9.3 | 2026-08-13 21:29:14 | Deep Dive |
| CVE-2026-73662 🧪 | Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files | FreePBX | music | High | 7.6 | 2026-08-13 21:27:14 | Deep Dive |
| CVE-2026-73661 🧪 | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup | FreePBX | framework | High | 8.6 | 2026-08-13 21:25:26 | Deep Dive |
| CVE-2026-73660 🧪 | FreePBX: Authenticated TTS AGI Command Injection Through TTS Name | FreePBX | tts | High | 7.5 | 2026-08-13 21:23:01 | Deep Dive |
| CVE-2026-72776 🧪 | AgenticSeek Unauthenticated RCE via /query API Endpoint | Fosowl | AgenticSeek | Critical | 9.8 | 2026-08-13 21:14:18 | Deep Dive |
| CVE-2026-19747 🧪 | Tenda CH7 ATE Module Kylin HandleCmd command injection | Tenda | CH7 | Critical | 9.8 | 2026-08-13 19:45:09 | Deep Dive |
| CVE-2026-45725 🧪 | compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal | oscal-compass | compliance-trestle | High | 7.1 | 2026-08-13 19:22:59 | Deep Dive |
| CVE-2026-48099 🧪 | WsgiDAV encoded dot segments can escape filesystem share roots | mar10 | wsgidav | High | 7.1 | 2026-08-13 19:15:02 | Deep Dive |
| CVE-2026-59714 🧪 | Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) | open-webui | open-webui | High | 7.1 | 2026-08-13 19:10:42 | Deep Dive |
| CVE-2026-49864 🧪 | wetty vulnerable to DOM XSS via file-download filename | butlerx | wetty | High | 8.6 | 2026-08-13 19:10:41 | Deep Dive |
| CVE-2026-73530 🧪 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() | flytohub | flyto-core | High | 7.7 | 2026-08-13 19:01:46 | Deep Dive |
| CVE-2026-73482 🧪 | phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php | phplist | phplist3 | High | 8.1 | 2026-08-13 18:49:02 | Deep Dive |
| CVE-2026-72777 🧪 | Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url | DayuanJiang | next-ai-draw-io | High | 8.6 | 2026-08-13 18:23:18 | Deep Dive |