| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73079 🧪 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials | Wei-Shaw | sub2api | High | 8.5 | 2026-08-11 15:54:00 | Deep Dive |
| CVE-2026-56721 🧪 | CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController | owen2345 | CamaleonCMS | High | 8.8 | 2026-08-11 15:48:59 | Deep Dive |
| CVE-2026-73078 🧪 | Vim: Arbitrary Code Execution via Netrw Menu Construction | vim | vim | High | 8.6 | 2026-08-11 15:41:08 | Deep Dive |
| CVE-2026-73077 🧪 | Vim: Arbitrary Code Execution via Shell Keyword Lookup | vim | vim | High | 8.4 | 2026-08-11 15:39:25 | Deep Dive |
| CVE-2026-73076 🧪 | Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` | vim | vim | High | 8.4 | 2026-08-11 15:38:00 | Deep Dive |
| CVE-2025-31114 🧪 | Fooocus webui vulnerable to Remote Code Execution | lllyasviel | Fooocus | Critical | 9.3 | 2026-08-11 15:37:34 | Deep Dive |
| CVE-2026-73074 🧪 | Vim: Heap Buffer Overflow in Text Property Handling | vim | vim | High | 7.1 | 2026-08-11 15:35:07 | Deep Dive |
| CVE-2026-73072 🧪 | Vim: Heap Buffer Overflow when Loading a Spell File | vim | vim | High | 8.5 | 2026-08-11 15:31:35 | Deep Dive |
| CVE-2026-18860 🧪 | Velociraptor incorrect Org deletion permissions check | Rapid7 | Velociraptor | High | 8.7 | 2026-08-11 14:52:56 | Deep Dive |
| CVE-2026-72922 🧪 | AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification | Significant-Gravitas | AutoGPT | High | 8.2 | 2026-08-11 14:32:12 | Deep Dive |
| CVE-2026-72921 🧪 | SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths | seaweedfs | seaweedfs | High | 8.1 | 2026-08-11 14:28:49 | Deep Dive |
| CVE-2026-72920 🧪 | SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control | seaweedfs | seaweedfs | Critical | 9.8 | 2026-08-11 14:23:22 | Deep Dive |
| CVE-2026-46670 🧪 💣 | YesWiki: Unauthenticated SQL Injection | YesWiki | yeswiki | Critical | 9.8 | 2026-08-11 13:58:33 | Deep Dive |
| CVE-2026-19539 🧪 | IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion | Roskus | Prospero Flow CRM | High | 8.6 | 2026-08-11 13:54:05 | Deep Dive |
| CVE-2026-48056 🧪 | Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler | truelockmc | streambert | Critical | 10.0 | 2026-08-11 13:52:45 | Deep Dive |
| CVE-2026-48046 🧪 | Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler | truelockmc | streambert | Critical | 9.3 | 2026-08-11 13:08:46 | Deep Dive |
| CVE-2026-72781 🧪 | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape | craftcms | cms | High | 8.8 | 2026-08-11 12:17:16 | Deep Dive |
| CVE-2026-72778 🧪 | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config | craftcms | cms | High | 8.8 | 2026-08-11 12:17:14 | Deep Dive |
| CVE-2026-72606 🧪 | Pinry Pinry - Server-Side Request Forgery | Pinry | Pinry | High | 7.5 | 2026-08-11 11:15:54 | Deep Dive |
| CVE-2026-72605 🧪 | Swing Music Swing Music - Missing Authentication | Swing Music | Swing Music | High | 7.5 | 2026-08-11 11:15:38 | Deep Dive |