| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-48802 🧪 | python-engineio has unbound thread allocation that can cause denial of service | miguelgrinberg | python-engineio | High | 7.5 | 2026-08-11 18:27:51 | Deep Dive |
| CVE-2026-73222 🧪 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) | davila7 | claude-code-templates | High | 8.8 | 2026-08-11 18:27:09 | Deep Dive |
| CVE-2026-48809 🧪 | python-engineio has possible denial of service due to maximum payload size sometimes not being enforced | miguelgrinberg | python-engineio | High | 7.5 | 2026-08-11 18:18:37 | Deep Dive |
| CVE-2026-69102 🧪 | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust | dromara | MaxKey | Critical | 9.8 | 2026-08-11 18:04:26 | Deep Dive |
| CVE-2026-72713 🧪 | XAgent Path Traversal Arbitrary File Read via /workspace/file | OpenBMB | XAgent | High | 7.5 | 2026-08-11 17:53:53 | Deep Dive |
| CVE-2026-71362 📌 💣 | Adobe Commerce | Incorrect Authorization (CWE-863) | Adobe | Adobe Commerce | Critical | 9.1 | 2026-08-11 17:52:48 | Deep Dive |
| CVE-2026-73218 🧪 | Cursor: Sandbox escape via launching privileged containers | cursor | cursor | High | 7.7 | 2026-08-11 17:47:29 | Deep Dive |
| CVE-2026-73217 🧪 | Cursor: Sandbox escape via tampered Python virtual environments | cursor | cursor | High | 7.7 | 2026-08-11 17:46:16 | Deep Dive |
| CVE-2026-73215 🧪 | The coturn server can end in a state where it does not accept more requests with "even-port" enabled. | coturn | coturn | High | 7.1 | 2026-08-11 17:38:08 | Deep Dive |
| CVE-2026-73214 🧪 | coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS | coturn | coturn | High | 8.2 | 2026-08-11 17:34:52 | Deep Dive |
| CVE-2026-73211 🧪 | PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() | Chocobozzz | PeerTube | Critical | 9.8 | 2026-08-11 17:22:00 | Deep Dive |
| CVE-2026-48771 🧪 | ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration | Ishankjha740 | ishankportfolio | High | 8.2 | 2026-08-11 17:20:55 | Deep Dive |
| CVE-2026-73090 🧪 | PeerTube: Cross-origin remote video takeover via Update activity | Chocobozzz | PeerTube | Critical | 9.3 | 2026-08-11 17:19:30 | Deep Dive |
| CVE-2026-73089 🧪 | Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM | browserslist | browserslist | High | 7.5 | 2026-08-11 17:05:39 | Deep Dive |
| CVE-2026-62735 🧪 | Windows HTTP.sys Elevation of Privilege Vulnerability | Microsoft | Windows 10 Version 1607 | High | 7.8 | 2026-08-11 17:04:15 | Deep Dive |
| CVE-2026-73088 🧪 | Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) | browserslist | browserslist | High | 7.5 | 2026-08-11 17:00:06 | Deep Dive |
| CVE-2026-73086 🧪 | nanoid: Integer Overflow or Wraparound | ai | nanoid | High | 7.4 | 2026-08-11 16:46:23 | Deep Dive |
| CVE-2026-73080 🧪 | SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle | seaweedfs | seaweedfs | Critical | 9.3 | 2026-08-11 15:57:11 | Deep Dive |
| CVE-2026-67180 🧪 | Google Turbinia arbitrary command execution | Turbinia | High | 8.4 | 2026-08-11 15:56:32 | Deep Dive | |
| CVE-2026-67179 🧪 | Genkit improper host header validation | genkit-ai | genkit | High | 7.8 | 2026-08-11 15:56:09 | Deep Dive |