| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-65098 🧪 | NVIDIA NemoClaw 授权问题漏洞 | NVIDIA | NemoClaw | High | 8.1 | 2026-08-25 20:15:22 | Deep Dive |
| CVE-2026-65096 🧪 | NVIDIA NemoClaw 命令注入漏洞 | NVIDIA | NemoClaw | High | 7.8 | 2026-08-25 20:15:20 | Deep Dive |
| CVE-2026-65093 🧪 | NVIDIA OpenShell 权限许可和访问控制问题漏洞 | NVIDIA | OpenShell | Critical | 9.9 | 2026-08-25 20:15:15 | Deep Dive |
| CVE-2026-65092 🧪 | NVIDIA OpenShell 路径遍历漏洞 | NVIDIA | OpenShell | High | 8.5 | 2026-08-25 20:15:14 | Deep Dive |
| CVE-2026-65091 🧪 | NVIDIA OpenShell 命令注入漏洞 | NVIDIA | OpenShell | High | 8.8 | 2026-08-25 20:15:13 | Deep Dive |
| CVE-2026-59981 🧪 | OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 19:58:37 | Deep Dive |
| CVE-2026-68515 🧪 | OpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel union | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 19:34:15 | Deep Dive |
| CVE-2026-55099 🧪 | icalendar: Algorithmic Complexity in Equality | collective | icalendar | High | 7.5 | 2026-08-25 19:27:02 | Deep Dive |
| CVE-2026-45019 🧪 | Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access | Chainlit | chainlit | High | 7.2 | 2026-08-25 19:20:59 | Deep Dive |
| CVE-2026-68513 🧪 | OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 19:06:12 | Deep Dive |
| CVE-2026-55620 🧪 | eml_parser: DoS via deeply nested parens in Received headers | GOVCERT-LU | eml_parser | High | 7.5 | 2026-08-25 18:26:55 | Deep Dive |
| CVE-2026-80049 🧪 | Airbyte Platform through 2.0.0 Cross-Workspace Authorization Bypass via Caller-Supplied workspaceId | airbytehq | airbyte-platform | High | 8.8 | 2026-08-25 18:23:17 | Deep Dive |
| CVE-2026-79788 🧪 | Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Address | dradis | dradis-ce | High | 7.1 | 2026-08-25 18:23:16 | Deep Dive |
| CVE-2026-79787 🧪 | Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature | Alluxio | alluxio | Critical | 9.8 | 2026-08-25 18:23:15 | Deep Dive |
| CVE-2026-79786 🧪 | Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration | coroot | coroot | High | 7.1 | 2026-08-25 18:23:14 | Deep Dive |
| CVE-2026-55637 🧪 | genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport | GeiserX | genieacs-mcp | High | 8.8 | 2026-08-25 18:03:35 | Deep Dive |
| CVE-2026-59982 🧪 | OpenEXR: DWAA InputFile AC buffer overflow on ILP32 platforms | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 17:59:25 | Deep Dive |
| CVE-2026-59189 🧪 | OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindow origin | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 16:51:31 | Deep Dive |
| CVE-2026-59187 🧪 | OpenEXR: exrmetrics deep pixelmode heap buffer overflow | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 16:38:51 | Deep Dive |
| CVE-2026-75498 🧪 | Webkul QloApps SQL injection | Webkul | QloApps | High | 7.2 | 2026-08-25 16:37:44 | Deep Dive |