| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-72538 🧪 | PrefectHQ Prefect - Argument Injection | PrefectHQ | Prefect | High | 8.8 | 2026-08-11 11:07:35 | Deep Dive |
| CVE-2026-72537 🧪 | Authentik Security authentik - Privilege Escalation | Authentik Security | authentik | High | 8.8 | 2026-08-11 11:07:23 | Deep Dive |
| CVE-2026-72536 🧪 | Chaskiq Chaskiq - Missing Authentication | Chaskiq | Chaskiq | High | 8.6 | 2026-08-11 11:07:07 | Deep Dive |
| CVE-2026-72535 🧪 | Chaskiq Chaskiq - Missing Authentication | Chaskiq | Chaskiq | High | 8.6 | 2026-08-11 11:06:55 | Deep Dive |
| CVE-2026-72534 🧪 | Authentik Security authentik - Privilege Escalation | Authentik Security | authentik | High | 8.8 | 2026-08-11 11:06:45 | Deep Dive |
| CVE-2026-72533 🧪 | Portainer Portainer CE - Authentication Bypass | Portainer | Portainer CE | High | 8.8 | 2026-08-11 11:06:34 | Deep Dive |
| CVE-2026-73160 🧪 | cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Addresses | MISP | cti-transmute | High | 8.7 | 2026-08-11 09:01:24 | Deep Dive |
| CVE-2026-71217 🧪 | Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion | Red Hat | Red Hat Enterprise Linux 10 | High | 7.5 | 2026-08-11 08:50:10 | Deep Dive |
| CVE-2026-48161 🧪 | react18-use was vulnerable to malicious code execution via compromised commits | dai-shi | react18-use | Critical | 9.3 | 2026-08-10 22:27:35 | Deep Dive |
| CVE-2026-48160 🧪 | react-tracked was vulnerable to malicious code execution via compromised commits | dai-shi | react-tracked | Critical | 9.3 | 2026-08-10 21:08:55 | Deep Dive |
| CVE-2026-72913 🧪 | Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences | kovidgoyal | kitty | High | 7.3 | 2026-08-10 21:07:30 | Deep Dive |
| CVE-2026-72911 🧪 | ERPNext: Possibility of server-side template injection due to missing validation | frappe | erpnext | Critical | 9.9 | 2026-08-10 21:00:47 | Deep Dive |
| CVE-2026-72910 🧪 | ERPNext: Unauthorised modification of master data due to missing validation | frappe | erpnext | High | 7.1 | 2026-08-10 20:57:41 | Deep Dive |
| CVE-2026-72909 🧪 | ERPNext: Broken Access Control on certain endpoints | frappe | erpnext | High | 7.1 | 2026-08-10 20:55:06 | Deep Dive |
| CVE-2026-72904 🧪 | Firecrawl: Arbitrary file read via JSON Schema $ref expansion | firecrawl | firecrawl | Critical | 9.3 | 2026-08-10 20:42:45 | Deep Dive |
| CVE-2026-72903 🧪 | Tabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directory | Eugeny | tabby | High | 8.1 | 2026-08-10 20:39:57 | Deep Dive |
| CVE-2026-73030 🧪 | unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape | frostming | unearth | High | 8.1 | 2026-08-10 20:09:45 | Deep Dive |
| CVE-2026-69118 🧪 | Cachet 2.4.1 Authenticated Server-Side Template Injection RCE | cachethq | cachet | High | 8.8 | 2026-08-10 19:42:33 | Deep Dive |
| CVE-2026-72902 🧪 | Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById | Dokploy | dokploy | Critical | 9.9 | 2026-08-10 19:41:41 | Deep Dive |
| CVE-2026-72901 🧪 | Dokploy: Remote Code Execution via volume-backup | Dokploy | dokploy | Critical | 9.9 | 2026-08-10 19:40:16 | Deep Dive |