| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-80191 🧪 | GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthenticated Requests | GROWI, Inc. | GROWI | High | 7.5 | 2026-08-25 23:19:00 | Deep Dive |
| CVE-2026-57170 🧪 | Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) | oscal-compass | compliance-trestle | High | 7.8 | 2026-08-25 23:18:29 | Deep Dive |
| CVE-2026-52776 🧪 | Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 | oscal-compass | compliance-trestle | High | 8.6 | 2026-08-25 23:12:25 | Deep Dive |
| CVE-2026-54757 🧪 | Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data | oscal-compass | compliance-trestle | High | 7.8 | 2026-08-25 23:02:12 | Deep Dive |
| CVE-2026-79912 🧪 | TOTOLINK N600R cstecgi.cgi getCurrentTime command injection | TOTOLINK | N600R | High | 8.3 | 2026-08-25 22:30:12 | Deep Dive |
| CVE-2026-79911 🧪 | TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow | TOTOLINK | N600R | Critical | 10.0 | 2026-08-25 22:15:13 | Deep Dive |
| CVE-2026-80138 🧪 | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | MacWarrior | clipbucket-v5 | Critical | 9.8 | 2026-08-25 22:12:24 | Deep Dive |
| CVE-2026-63403 🧪 | Faktory: Unrecovered panic in command handlers allows full-server denial of service | contribsys | faktory | High | 8.7 | 2026-08-25 22:04:48 | Deep Dive |
| CVE-2026-63404 🧪 | Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hijack (network exposure / root RCE primitive) | contribsys | faktory | High | 7.3 | 2026-08-25 22:01:19 | Deep Dive |
| CVE-2026-80186 🧪 | Bluez: stack overflow in name2utf8 causes dos and potential code execution | Red Hat | Red Hat Enterprise Linux 10 | High | 7.6 | 2026-08-25 21:58:17 | Deep Dive |
| CVE-2026-79804 🧪 | SililaWijesinghe Food Ordering System search.php sql injection | SililaWijesinghe | Food Ordering System | High | 7.3 | 2026-08-25 21:30:10 | Deep Dive |
| CVE-2026-77357 🧪 | Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the server | mesop-dev | mesop | High | 8.7 | 2026-08-25 20:40:40 | Deep Dive |
| CVE-2026-65105 🧪 | NVIDIA NemoClaw 授权问题漏洞 | NVIDIA | NemoClaw | High | 8.1 | 2026-08-25 20:15:34 | Deep Dive |
| CVE-2026-65084 🧪 | NVIDIA NemoClaw 加密问题漏洞 | NVIDIA | NemoClaw | High | 8.1 | 2026-08-25 20:15:29 | Deep Dive |
| CVE-2026-65083 🧪 | NVIDIA OpenShell 输入验证错误漏洞 | NVIDIA | OpenShell | Critical | 9.9 | 2026-08-25 20:15:28 | Deep Dive |
| CVE-2026-65082 🧪 | NVIDIA NemoClaw 代码注入漏洞 | NVIDIA | NemoClaw | High | 7.0 | 2026-08-25 20:15:27 | Deep Dive |
| CVE-2026-65081 🧪 | NVIDIA NemoClaw 软件供应链问题漏洞 | NVIDIA | NemoClaw | High | 8.1 | 2026-08-25 20:15:26 | Deep Dive |
| CVE-2026-65089 🧪 | NVIDIA NemoClaw 命令注入漏洞 | NVIDIA | NemoClaw | High | 7.8 | 2026-08-25 20:15:25 | Deep Dive |
| CVE-2026-65090 🧪 | NVIDIA NemoClaw 命令注入漏洞 | NVIDIA | NemoClaw | High | 7.8 | 2026-08-25 20:15:24 | Deep Dive |
| CVE-2026-65099 🧪 | NVIDIA NemoClaw 命令注入漏洞 | NVIDIA | NemoClaw | High | 7.8 | 2026-08-25 20:15:23 | Deep Dive |