| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73601 🧪 | Flowise before 3.1.3 Remote Code Execution via Custom MCP | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:08 | Deep Dive |
| CVE-2026-73487 🧪 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:07 | Deep Dive |
| CVE-2026-73486 🧪 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:06 | Deep Dive |
| CVE-2026-73485 🧪 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:05 | Deep Dive |
| CVE-2026-73484 🧪 | Flowise before 3.1.3 Sandbox Escape via Pandas Methods | FlowiseAI | Flowise | High | 8.6 | 2026-08-13 11:28:05 | Deep Dive |
| CVE-2026-73483 🧪 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | FlowiseAI | Flowise | Critical | 9.4 | 2026-08-13 11:28:04 | Deep Dive |
| CVE-2026-19484 🧪 | @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary | @fastify/busboy | @fastify/busboy | High | 7.5 | 2026-08-13 08:50:47 | Deep Dive |
| CVE-2026-19481 🧪 | @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header | @fastify/busboy | @fastify/busboy | High | 7.5 | 2026-08-13 08:31:25 | Deep Dive |
| CVE-2026-46382 🧪 | Meeting Room Booking System has server-side request forgery in import functionality | meeting-room-booking-system | mrbs-code | High | 8.7 | 2026-08-12 23:39:51 | Deep Dive |
| CVE-2026-49473 🧪 | @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation | cedar-policy | authorization-for-expressjs | High | 8.8 | 2026-08-12 23:22:39 | Deep Dive |
| CVE-2026-49819 🧪 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | seriousm4x | UpSnap | Critical | 9.8 | 2026-08-12 23:13:46 | Deep Dive |
| CVE-2026-49481 🧪 | UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd | seriousm4x | UpSnap | Critical | 9.6 | 2026-08-12 23:08:45 | Deep Dive |
| CVE-2026-47717 🧪 💣 | FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations | frangoteam | FUXA | High | 7.5 | 2026-08-12 22:18:04 | Deep Dive |
| CVE-2026-73501 🧪 | kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default | getkin | kin-openapi | Critical | 9.1 | 2026-08-12 21:23:41 | Deep Dive |
| CVE-2026-73500 🧪 | etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline | etcd-io | etcd | High | 8.7 | 2026-08-12 21:22:25 | Deep Dive |
| CVE-2026-73499 🧪 | etcd: Watch API authorization bypass via open-ended range requests | etcd-io | etcd | High | 7.1 | 2026-08-12 21:20:32 | Deep Dive |
| CVE-2026-73498 🧪 | MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment | sooperset | mcp-atlassian | High | 7.7 | 2026-08-12 21:17:25 | Deep Dive |
| CVE-2026-73519 🧪 | WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret | wolfsoftwaresystemsltd | WolfStack | Critical | 9.8 | 2026-08-12 21:15:33 | Deep Dive |
| CVE-2026-73495 🧪 | blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) | http4s | blaze | High | 7.4 | 2026-08-12 21:11:55 | Deep Dive |
| CVE-2026-73493 🧪 | http4s-blaze-server: Unbounded WebSocket message aggregation | http4s | blaze | High | 7.5 | 2026-08-12 21:08:35 | Deep Dive |