| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73407 🧪 | Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak (bypass of CVE-2026-48152)) | Budibase | budibase | Critical | 9.0 | 2026-08-12 19:09:56 | Deep Dive |
| CVE-2026-73332 🧪 | CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field | owen2345 | CamaleonCMS | High | 8.7 | 2026-08-12 19:09:48 | Deep Dive |
| CVE-2026-63300 🧪 | Cross-project instance move bypasses all project restrictions allowing host command execution | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:09:04 | Deep Dive |
| CVE-2026-73331 🧪 | CamaleonCMS 2.9.1 Authenticated SQL Injection via Post Slug Field | owen2345 | CamaleonCMS | High | 7.1 | 2026-08-12 19:06:32 | Deep Dive |
| CVE-2026-73406 🧪 | Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint | Budibase | budibase | High | 7.5 | 2026-08-12 19:03:52 | Deep Dive |
| CVE-2026-73329 🧪 | CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint | owen2345 | CamaleonCMS | High | 8.7 | 2026-08-12 18:54:07 | Deep Dive |
| CVE-2026-73303 🧪 | Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session) | Budibase | budibase | High | 8.2 | 2026-08-12 18:51:39 | Deep Dive |
| CVE-2026-18952 🧪 | Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin | AWS | Opensearch | High | 8.1 | 2026-08-12 18:42:39 | Deep Dive |
| CVE-2026-19311 🧪 | Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin | AWS | OpenSearch | High | 8.1 | 2026-08-12 18:34:03 | Deep Dive |
| CVE-2026-73300 🧪 | Budibase: SQL Injection via `multipleStatements: true` | Budibase | budibase | Critical | 9.6 | 2026-08-12 18:05:51 | Deep Dive |
| CVE-2026-42018 KEV 📌 💣 | Anonymous user token generation exposure in JFrog Artifactory EPSS 0.11 | jfrog | artifactory | High | 7.5 | 2026-08-12 17:43:21 | Deep Dive |
| CVE-2026-73299 🧪 | Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer | microsoft | prompty | Critical | 10.0 | 2026-08-12 17:31:39 | Deep Dive |
| CVE-2026-73298 🧪 | Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/write/delete processes | microsoft | Container-Migration-Solution-Accelerator | High | 8.7 | 2026-08-12 17:24:57 | Deep Dive |
| CVE-2026-44741 🧪 | Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter | pimcore | pimcore | High | 8.8 | 2026-08-12 17:06:19 | Deep Dive |
| CVE-2026-48554 🧪 | Nagios Core / XI Authenticated RCE via Unfiltered NOTIFICATION-Family Macro Substitution | Nagios Enterprises, LLC. | Nagios Core | High | 7.5 | 2026-08-12 16:48:28 | Deep Dive |
| CVE-2026-48553 🧪 | Nagios Core / XI Authenticated RCE via Custom-Variable Macro Injection | Nagios Enterprises, LLC. | Nagios Core | High | 7.5 | 2026-08-12 16:46:36 | Deep Dive |
| CVE-2026-48551 🧪 | Nagios Core / XI CSRF Protection Bypass via Double-Submit Cookie | Nagios Enterprises, LLC. | Nagios Core | High | 7.4 | 2026-08-12 16:32:17 | Deep Dive |
| CVE-2026-73296 🧪 | Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure | microsoft | UFO | Critical | 9.4 | 2026-08-12 16:29:03 | Deep Dive |
| CVE-2026-73294 🧪 | Semaphore U: OS Command Injection | semaphoreui | semaphore | Critical | 9.9 | 2026-08-12 15:55:01 | Deep Dive |
| CVE-2026-73293 🧪 | Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision | semaphoreui | semaphore | High | 8.8 | 2026-08-12 15:45:22 | Deep Dive |