| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73507 🧪 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion | netty | netty | High | 7.5 | 2026-08-13 14:25:34 | Deep Dive |
| CVE-2026-73505 🧪 | Oh My Posh: Arbitrary command execution via template injection in the path segment | JanDeDobbeleer | oh-my-posh | High | 7.8 | 2026-08-13 14:21:57 | Deep Dive |
| CVE-2026-19734 🧪 | IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking | Roskus | Prospero Flow CRM | High | 8.6 | 2026-08-13 14:04:56 | Deep Dive |
| CVE-2026-48702 🧪 | Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic | sigstore | rekor | High | 7.5 | 2026-08-13 13:14:19 | Deep Dive |
| CVE-2026-49478 🧪 | Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage | sigstore | fulcio | High | 8.7 | 2026-08-13 13:08:21 | Deep Dive |
| CVE-2026-16239 🧪 | PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code | - | PostgreSQL | High | 8.8 | 2026-08-13 13:00:13 | Deep Dive |
| CVE-2026-49827 🧪 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) | SMEWebify | WebErpMesv2 | Critical | 9.8 | 2026-08-13 12:51:55 | Deep Dive |
| CVE-2026-73629 🧪 | Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses | s9y | Serendipity | High | 8.5 | 2026-08-13 11:28:28 | Deep Dive |
| CVE-2026-73625 🧪 | GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling | gitpython-developers | GitPython | High | 8.8 | 2026-08-13 11:28:25 | Deep Dive |
| CVE-2026-73624 🧪 | GitPython before 3.1.54 Arbitrary File Overwrite via diff | gitpython-developers | GitPython | High | 8.1 | 2026-08-13 11:28:24 | Deep Dive |
| CVE-2026-73623 🧪 | GitPython before 3.1.54 Remote Code Execution via --template | gitpython-developers | GitPython | High | 7.5 | 2026-08-13 11:28:23 | Deep Dive |
| CVE-2026-73622 🧪 | GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() | gitpython-developers | GitPython | High | 7.5 | 2026-08-13 11:28:23 | Deep Dive |
| CVE-2026-73620 🧪 | GitPython before 3.1.57 Arbitrary File Overwrite and Read | gitpython-developers | GitPython | High | 8.1 | 2026-08-13 11:28:21 | Deep Dive |
| CVE-2026-73618 🧪 | Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter | budibase | server | High | 8.3 | 2026-08-13 11:28:20 | Deep Dive |
| CVE-2026-73617 🧪 | Budibase before 3.40.0 NoSQL Injection via MongoDB datasource | budibase | server | High | 7.1 | 2026-08-13 11:28:19 | Deep Dive |
| CVE-2026-73615 🧪 | Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch | Jovancoding | Network-AI | High | 8.8 | 2026-08-13 11:28:18 | Deep Dive |
| CVE-2026-73613 🧪 | filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink | filebrowser | filebrowser | High | 8.2 | 2026-08-13 11:28:17 | Deep Dive |
| CVE-2026-73614 🧪 | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation | Jovancoding | Network-AI | High | 8.8 | 2026-08-13 11:28:17 | Deep Dive |
| CVE-2026-73612 🧪 | File Browser before v2.63.22 Authorization Bypass via Recursive Operations | filebrowser | filebrowser | High | 8.1 | 2026-08-13 11:28:16 | Deep Dive |
| CVE-2026-73602 🧪 | Flowise before 3.1.3 Sandbox Escape to RCE | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:09 | Deep Dive |