| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-72566 🧪 | automatisch - Server-Side Request Forgery via HTTP Request Custom Action | automatisch | automatisch | High | 7.7 | 2026-08-10 10:40:35 | Deep Dive |
| CVE-2026-72565 🧪 | Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass | Tencent | APIJSON | Critical | 9.8 | 2026-08-10 10:40:32 | Deep Dive |
| CVE-2026-72564 🧪 | fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication | fosrl | Pangolin | Critical | 9.6 | 2026-08-10 10:40:29 | Deep Dive |
| CVE-2026-19384 🧪 | SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection | SourceCodester | Simple Doctors Appointment System | High | 7.3 | 2026-08-10 01:30:11 | Deep Dive |
| CVE-2026-19379 🧪 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | EFM | ipTIME AX8004M | High | 7.3 | 2026-08-10 00:00:13 | Deep Dive |
| CVE-2026-19376 🧪 | Uasoft Badaso File API api.php class permission | Uasoft | Badaso | High | 7.3 | 2026-08-09 23:30:09 | Deep Dive |
| CVE-2026-19374 🧪 | adafap api-mcp Proxy API Endpoint route.ts customAxios server-side request forgery | adafap | api-mcp | High | 7.3 | 2026-08-09 23:00:13 | Deep Dive |
| CVE-2026-19351 🧪 | dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection | dresende | node-sql-query | High | 7.3 | 2026-08-09 11:30:11 | Deep Dive |
| CVE-2026-19348 🧪 | Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection | Shenzhen Aitemi | M300 Wi-Fi Repeater | Critical | 9.8 | 2026-08-09 10:30:09 | Deep Dive |
| CVE-2026-19344 🧪 | code-projects Task Management System comment_count_user.php sql injection | code-projects | Task Management System | High | 7.3 | 2026-08-09 09:15:09 | Deep Dive |
| CVE-2026-19343 🧪 | code-projects Task Management System AdminLogin.php sql injection | code-projects | Task Management System | High | 7.3 | 2026-08-09 07:45:09 | Deep Dive |
| CVE-2026-19342 🧪 | code-projects Task Management System Login index.php improper authentication | code-projects | Task Management System | High | 7.3 | 2026-08-09 07:30:09 | Deep Dive |
| CVE-2026-19341 🧪 | UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow | UTT | HiPER 1200GW | High | 8.8 | 2026-08-09 07:00:10 | Deep Dive |
| CVE-2026-67620 🧪 | Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List | FlowiseAI | Flowise | High | 7.7 | 2026-08-08 16:03:40 | Deep Dive |
| CVE-2026-19263 🧪 | INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection | INQUIRELAB | mcp-bridge-api | High | 7.3 | 2026-08-08 06:45:09 | Deep Dive |
| CVE-2026-52880 🧪 | Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run | klever-io | klever-go | High | 7.5 | 2026-08-07 22:53:41 | Deep Dive |
| CVE-2026-52879 🧪 | Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS | klever-io | klever-go | High | 7.5 | 2026-08-07 22:36:54 | Deep Dive |
| CVE-2026-52878 🧪 | Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chain | klever-io | klever-go | High | 7.5 | 2026-08-07 22:32:27 | Deep Dive |
| CVE-2026-48026 🧪 | lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML | treeverse | lakeFS | High | 8.7 | 2026-08-07 22:29:36 | Deep Dive |
| CVE-2026-46409 🧪 | OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution | openyak | openyak | Critical | 9.6 | 2026-08-07 22:11:58 | Deep Dive |