| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19003 🧪 | MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings | MongoDB | BI Connector ODBC Driver | High | 7.8 | 2026-08-12 21:04:19 | Deep Dive |
| CVE-2026-19654 🧪 | Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd | Red Hat | Red Hat Enterprise Linux 10 | High | 7.5 | 2026-08-12 20:46:32 | Deep Dive |
| CVE-2026-19004 🧪 | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters | MongoDB | BI Connector ODBC Driver | High | 8.1 | 2026-08-12 20:33:14 | Deep Dive |
| CVE-2026-19001 🧪 | MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names | MongoDB | BI Connector ODBC Driver | Critical | 9.8 | 2026-08-12 20:27:03 | Deep Dive |
| CVE-2026-19002 🧪 | Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver | MongoDB | BI Connector ODBC Driver | High | 8.1 | 2026-08-12 20:24:35 | Deep Dive |
| CVE-2026-73418 🧪 | NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers | nextauthjs | next-auth | High | 7.5 | 2026-08-12 20:21:11 | Deep Dive |
| CVE-2026-16033 🧪 | Arbitrary file read+write on host via templates/ symlink in malicious image | Canonical | LXD | High | 8.5 | 2026-08-12 20:11:09 | Deep Dive |
| CVE-2026-66898 🧪 | Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE | Canonical | LXD | Critical | 9.9 | 2026-08-12 20:07:33 | Deep Dive |
| CVE-2026-67579 🧪 | Filter expression injection via forged keyset pagination cursor in Ash | ash-project | ash | High | 7.5 | 2026-08-12 20:04:42 | Deep Dive |
| CVE-2026-63293 🧪 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | Canonical | LXD | Critical | 9.9 | 2026-08-12 20:00:09 | Deep Dive |
| CVE-2026-63294 🧪 | Root RCE via image backup.yaml symlink | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:57:08 | Deep Dive |
| CVE-2026-73415 🧪 | jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab | jupyterlab | jupyterlab | High | 7.5 | 2026-08-12 19:54:01 | Deep Dive |
| CVE-2026-73414 🧪 | Shescape: Shell injection via unescaped parentheses on Windows with CMD | ericcornelissen | shescape | Critical | 9.2 | 2026-08-12 19:42:56 | Deep Dive |
| CVE-2026-73413 🧪 | Shescape: Quadratic-time denial of service in flag-protection | ericcornelissen | shescape | High | 8.7 | 2026-08-12 19:40:46 | Deep Dive |
| CVE-2026-63296 🧪 | Project restriction bypass via instance migration config override | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:27:46 | Deep Dive |
| CVE-2026-63297 🧪 | Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:25:24 | Deep Dive |
| CVE-2026-63298 🧪 | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:22:07 | Deep Dive |
| CVE-2026-63299 🧪 | Storage volume cross-project move and snapshot restore bypass project disk limits | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:17:07 | Deep Dive |
| CVE-2026-73326 🧪 | CamaleonCMS Missing Authorization via Plugin Administration Endpoints | owen2345 | CamaleonCMS | High | 7.6 | 2026-08-12 19:13:29 | Deep Dive |
| CVE-2026-62420 🧪 | Cross-project cluster migration bypasses project restrictions via cluster notification flag | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:12:28 | Deep Dive |