| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73653 🧪 | Vitest: Browser Mode provider commands bypass the file-access permission gate | vitest-dev | vitest | Critical | 9.4 | 2026-08-13 18:19:00 | Deep Dive |
| CVE-2026-73652 🧪 | vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review | vantage6 | vantage6 | High | 7.1 | 2026-08-13 18:15:55 | Deep Dive |
| CVE-2026-73650 🧪 | SVGO: removeScripts plugin leaves some executable scripts intact | svg | svgo | High | 8.2 | 2026-08-13 18:08:36 | Deep Dive |
| CVE-2026-73649 🧪 | Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) | shepherdwind | velocity.js | Critical | 9.8 | 2026-08-13 18:05:32 | Deep Dive |
| CVE-2026-72741 🧪 | Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access | goodrain | rainbond | High | 8.1 | 2026-08-13 17:59:26 | Deep Dive |
| CVE-2026-73644 🧪 | OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant | OpenIdentityPlatform | OpenDJ | Critical | 9.6 | 2026-08-13 17:52:49 | Deep Dive |
| CVE-2026-73643 🧪 | js-yaml: Exponential parsing time in the flow collections leads to denial of service | nodeca | js-yaml | High | 7.5 | 2026-08-13 17:47:30 | Deep Dive |
| CVE-2026-73569 🧪 | fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits | NaturalIntelligence | fast-xml-parser | High | 8.7 | 2026-08-13 17:45:25 | Deep Dive |
| CVE-2026-73568 🧪 | py-libp2p: yamux connection DoS via oversized data frame | libp2p | py-libp2p | High | 7.5 | 2026-08-13 17:43:26 | Deep Dive |
| CVE-2026-73567 🧪 | sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock | JuneAndGreen | sm-crypto | Critical | 9.1 | 2026-08-13 17:40:54 | Deep Dive |
| CVE-2026-73566 🧪 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection | isaacs | node-tar | High | 7.5 | 2026-08-13 17:39:06 | Deep Dive |
| CVE-2026-73564 🧪 | frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow | fatedier | frp | High | 8.7 | 2026-08-13 17:35:47 | Deep Dive |
| CVE-2026-18428 🧪 | SQL Query Validation Bypass in OpenSearch Direct Query | AWS | Opensearch | High | 8.8 | 2026-08-13 17:32:48 | Deep Dive |
| CVE-2026-73561 🧪 | Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion | anephenix | hub | High | 7.5 | 2026-08-13 17:24:35 | Deep Dive |
| CVE-2026-67614 🧪 | CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal | usmannasir | cyberpanel | Critical | 9.8 | 2026-08-13 17:08:40 | Deep Dive |
| CVE-2026-73514 🧪 | PostGIS address_standardizer Out-of-Bounds Write via standardize_address() | PostGIS | address_standardizer | High | 8.8 | 2026-08-13 15:36:15 | Deep Dive |
| CVE-2026-73670 🧪 | CMS Admin SQL Injection via db_data.php table_name Parameter | Saurus | Saurus CMS Community Edition | High | 7.2 | 2026-08-13 15:35:32 | Deep Dive |
| CVE-2026-73570 KEV 🧪 | Zimbra Collaboration 命令注入漏洞 EPSS 0.32 | Zimbra | Collaboration | High | 8.9 | 2026-08-13 15:19:42 | Deep Dive |
| CVE-2026-19710 🧪 | SourceCodester Simple Student Information System view_department.php sql injection | SourceCodester | Simple Student Information System | High | 7.3 | 2026-08-13 15:15:09 | Deep Dive |
| CVE-2026-49857 🧪 | auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback | ymw0407 | auth-fetch-mcp | High | 7.4 | 2026-08-13 14:50:25 | Deep Dive |