| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-47249 🧪 | Klever-Go KVM: Hash-array amplification in P2P resolver request handling | klever-io | klever-go | High | 7.5 | 2026-08-07 22:09:04 | Deep Dive |
| CVE-2026-58262 🧪 | Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum | klever-io | klever-go | High | 7.1 | 2026-08-07 22:00:57 | Deep Dive |
| CVE-2026-47243 🧪 | Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs | kata-containers | kata-containers | Critical | 9.2 | 2026-08-07 21:36:50 | Deep Dive |
| CVE-2026-48170 🧪 | scimPatch vulnerable to prototype pollution via unfiltered keys in patch | thomaspoignant | scim-patch | Critical | 9.1 | 2026-08-07 21:26:55 | Deep Dive |
| CVE-2026-48169 🧪 | PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API | MervinPraison | praisonai-platform | High | 8.8 | 2026-08-07 21:22:04 | Deep Dive |
| CVE-2026-45808 🧪 | OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL | openbao | openbao | High | 7.1 | 2026-08-07 21:15:01 | Deep Dive |
| CVE-2026-50540 🧪 | Kata Containers: Config Path Annotation Arbitrary File Loading | kata-containers | kata-containers | Critical | 9.6 | 2026-08-07 20:56:26 | Deep Dive |
| CVE-2026-66061 🧪 | Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution | home-assistant | core | High | 7.1 | 2026-08-07 20:43:42 | Deep Dive |
| CVE-2026-61808 🧪 💣 | LightRAG: Missing Authentication for Critical API Functions in Default Configuration | HKUDS | LightRAG | Critical | 9.8 | 2026-08-07 20:09:49 | Deep Dive |
| CVE-2026-62296 🧪 | HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of service | hapifhir | org.hl7.fhir.core | High | 7.5 | 2026-08-07 20:03:17 | Deep Dive |
| CVE-2026-62295 🧪 | HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service | hapifhir | org.hl7.fhir.core | High | 7.5 | 2026-08-07 19:36:31 | Deep Dive |
| CVE-2026-48007 🧪 | Element Call reports full URLs of visited pages to analytics server | element-hq | element-call | High | 8.6 | 2026-08-07 19:32:00 | Deep Dive |
| CVE-2026-48039 🧪 | Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token | pipeboard-co | meta-ads-mcp | Critical | 9.1 | 2026-08-07 19:29:40 | Deep Dive |
| CVE-2026-65819 🧪 | gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enabling unauthenticated remote DoS via DecodingLayerParser | gopacket | gopacket | High | 7.5 | 2026-08-07 19:19:16 | Deep Dive |
| CVE-2026-48098 🧪 | NexTOR IP Changer Unsafely Uses sudo and shell=True | 0x5t4l1n | NexTOR_IP_CHANGER | High | 7.3 | 2026-08-07 19:09:29 | Deep Dive |
| CVE-2026-48097 🧪 | NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution | 0x5t4l1n | NexTOR_IP_CHANGER | High | 7.8 | 2026-08-07 19:06:23 | Deep Dive |
| CVE-2026-11430 🧪 | Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit | Trilby Media | grav-plugin-scheduler-webhook | High | 7.3 | 2026-08-07 19:02:10 | Deep Dive |
| CVE-2026-71851 🧪 | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain | brix | crypto-js | Critical | 9.0 | 2026-08-07 18:48:08 | Deep Dive |
| CVE-2026-71847 🧪 | Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams | ruby | json | High | 8.7 | 2026-08-07 18:31:29 | Deep Dive |
| CVE-2026-19231 🧪 | SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection | SourceCodester | Simple Doctors Appointment System | High | 7.3 | 2026-08-07 18:30:10 | Deep Dive |