| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-72689 🧪 | OpenSignLabs opensignserver - Broken Object Level Authorization | OpenSignLabs | opensignserver | High | 7.5 | 2026-08-10 11:59:06 | Deep Dive |
| CVE-2026-72688 🧪 | OpenSignLabs opensignserver - Missing Authentication for Critical Function | OpenSignLabs | opensignserver | High | 7.5 | 2026-08-10 11:59:03 | Deep Dive |
| CVE-2026-72594 🧪 | lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload | lobehub | lobe-chat | High | 7.6 | 2026-08-10 10:41:58 | Deep Dive |
| CVE-2026-72593 🧪 | dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access | dulldusk | phpfm | Critical | 9.8 | 2026-08-10 10:41:55 | Deep Dive |
| CVE-2026-72592 🧪 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | dulldusk | phpfm | Critical | 9.8 | 2026-08-10 10:41:52 | Deep Dive |
| CVE-2026-72591 🧪 | Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter | gabehf | Koito | High | 7.7 | 2026-08-10 10:41:48 | Deep Dive |
| CVE-2026-72590 🧪 | alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter | alseambusher | crontab-ui | Critical | 9.8 | 2026-08-10 10:41:45 | Deep Dive |
| CVE-2026-72589 🧪 | alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field | alseambusher | crontab-ui | Critical | 9.8 | 2026-08-10 10:41:42 | Deep Dive |
| CVE-2026-72586 🧪 | frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler | frangoteam | FUXA | High | 7.5 | 2026-08-10 10:41:33 | Deep Dive |
| CVE-2026-72584 🧪 | fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery | fastschema | fastschema | High | 7.4 | 2026-08-10 10:41:27 | Deep Dive |
| CVE-2026-72582 🧪 | fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint | fastschema | fastschema | High | 7.5 | 2026-08-10 10:41:22 | Deep Dive |
| CVE-2026-72579 🧪 | NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server | NASA | HyperCP | High | 7.5 | 2026-08-10 10:41:13 | Deep Dive |
| CVE-2026-72578 🧪 | FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher | FreePBX | FreePBX Framework | High | 8.8 | 2026-08-10 10:41:09 | Deep Dive |
| CVE-2026-72577 🧪 | NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection | NASA | fprime-gds | Critical | 9.8 | 2026-08-10 10:41:07 | Deep Dive |
| CVE-2026-72575 🧪 | daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects | daptin | daptin | Critical | 9.1 | 2026-08-10 10:41:01 | Deep Dive |
| CVE-2026-72573 🧪 | 4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter | 4xmen | pm2panel | High | 8.8 | 2026-08-10 10:40:55 | Deep Dive |
| CVE-2026-72572 🧪 | o1lab xmysql - Unauthenticated Path Traversal via name Query Parameter | o1lab | xmysql | High | 7.5 | 2026-08-10 10:40:52 | Deep Dive |
| CVE-2026-72571 🧪 | mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter | mustafaakin | cast-localvideo | High | 7.5 | 2026-08-10 10:40:49 | Deep Dive |
| CVE-2026-72569 🧪 | cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion | cube-root | directory-serve | Critical | 9.1 | 2026-08-10 10:40:43 | Deep Dive |
| CVE-2026-72567 🧪 | deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete | AsyncFuncAI | deepwiki-open | Critical | 9.8 | 2026-08-10 10:40:37 | Deep Dive |