| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73244 🧪 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing | kekingcn | kkFileView | Medium | 5.3 | 2026-08-11 20:08:25 | Deep Dive |
| CVE-2026-73243 🧪 | kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass | kekingcn | kkFileView | Medium | 5.8 | 2026-08-11 20:04:39 | Deep Dive |
| CVE-2026-73242 🧪 | FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage` | FreeRDP | FreeRDP | High | 8.3 | 2026-08-11 19:49:47 | Deep Dive |
| CVE-2026-73241 🧪 | FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`) | FreeRDP | FreeRDP | High | 8.3 | 2026-08-11 19:47:28 | Deep Dive |
| CVE-2026-19091 🧪 | GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | High | 8.1 | 2026-08-11 19:37:28 | Deep Dive |
| CVE-2026-73232 🧪 | ffuf denial of service (OOM) via HTTP response decompression bomb | ffuf | ffuf | High | 7.5 | 2026-08-11 19:32:49 | Deep Dive |
| CVE-2026-73034 📌 💣 | DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header | eosphoros-ai | DB-GPT | Critical | 9.8 | 2026-08-11 19:31:49 | Deep Dive |
| CVE-2026-73231 🧪 | Faker: helpers.fake exploitable into arbritary code execution | faker-js | faker | High | 7.8 | 2026-08-11 19:28:45 | Deep Dive |
| CVE-2026-45618 🧪 | LiquidJS is Vulnerable to Remote Code Execution | harttle | liquidjs | Critical | 10.0 | 2026-08-11 19:27:10 | Deep Dive |
| CVE-2026-48813 🧪 | Flawfinder output manipulation via untrusted filenames and source text | david-a-wheeler | flawfinder | High | 8.7 | 2026-08-11 19:24:54 | Deep Dive |
| CVE-2026-73032 🧪 | PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() | papersgpt | papersgpt-for-zotero | Critical | 9.6 | 2026-08-11 19:19:02 | Deep Dive |
| CVE-2026-48804 🧪 | python-socketio: Binary attachment accumulation can cause denial of service | miguelgrinberg | python-socketio | High | 7.5 | 2026-08-11 19:17:54 | Deep Dive |
| CVE-2026-73031 🧪 | telegram-search Stored XSS via v-html in MessageList.vue | GramSearch | telegram-search | High | 8.7 | 2026-08-11 19:02:51 | Deep Dive |
| CVE-2026-72742 🧪 | DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing | Stanford NLP | DSPy | High | 8.6 | 2026-08-11 18:50:48 | Deep Dive |
| CVE-2026-73227 🧪 | electerm's RDP clipboard file download may parse unsafe file name | electerm | electerm | High | 8.1 | 2026-08-11 18:45:22 | Deep Dive |
| CVE-2026-73226 🧪 | Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist | electerm | electerm | High | 8.8 | 2026-08-11 18:44:02 | Deep Dive |
| CVE-2026-73225 🧪 | electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename | electerm | electerm | High | 8.1 | 2026-08-11 18:42:16 | Deep Dive |
| CVE-2026-73224 🧪 | Electerm check folder size function may get attacked by unsafe folder name | electerm | electerm | High | 8.8 | 2026-08-11 18:39:21 | Deep Dive |
| CVE-2026-73223 🧪 | electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename | electerm | electerm | High | 8.1 | 2026-08-11 18:37:41 | Deep Dive |
| CVE-2026-69119 🧪 | Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id} | Taubyte | tau | High | 8.3 | 2026-08-11 18:36:12 | Deep Dive |