| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-58375 🧪 | Frappe has potential SQL Injection due to missing validation | frappe | frappe | High | 8.1 | 2026-08-07 18:21:10 | Deep Dive |
| CVE-2026-64638 🧪 💣 | WordPress 跨站脚本漏洞 | WordPress | WordPress | High | 8.9 | 2026-08-07 18:02:07 | Deep Dive |
| CVE-2026-67585 🧪 | Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation | DivvyPayHQ | absinthe_federation | High | 8.7 | 2026-08-07 16:42:23 | Deep Dive |
| CVE-2026-71556 🧪 | go-git: Worktree operations may follow symlinks | go-git | go-git | High | 7.1 | 2026-08-07 16:37:40 | Deep Dive |
| CVE-2026-68772 🧪 | ZenML 0.94.6 Remote Code Execution via CloudpickleMaterializer | ZenML | ZenML | High | 8.0 | 2026-08-07 16:27:42 | Deep Dive |
| CVE-2026-19211 🧪 | SourceCodester Photo Share Website ajax.php signup sql injection | SourceCodester | Photo Share Website | High | 7.3 | 2026-08-07 16:15:10 | Deep Dive |
| CVE-2026-17594 📌 💣 | Nexus Repository 3 - Authorization Bypass in Repository Creation | Sonatype | Nexus Repository 3 | High | 8.2 | 2026-08-07 16:07:43 | Deep Dive |
| CVE-2022-4995 🧪 | Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp | Weaver Network Co., Ltd. | E-cology 9.0 | Critical | 9.8 | 2026-08-07 14:39:51 | Deep Dive |
| CVE-2026-19264 🧪 | Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover | gitroomhq | postiz-app | Critical | 9.8 | 2026-08-07 14:15:15 | Deep Dive |
| CVE-2026-15816 🧪 | Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() | Red Hat | Red Hat Enterprise Linux 10 | High | 7.5 | 2026-08-07 10:33:34 | Deep Dive |
| CVE-2026-19196 🧪 | SourceCodester Photo Share Website ajax.php login sql injection | SourceCodester | Photo Share Website | High | 7.3 | 2026-08-07 05:00:13 | Deep Dive |
| CVE-2026-19195 🧪 | V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control | V-Secure | Jingyun Antivirus | High | 7.8 | 2026-08-07 04:45:09 | Deep Dive |
| CVE-2026-19193 🧪 | Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control | Jiangmin | Antivirus | High | 7.8 | 2026-08-07 04:15:10 | Deep Dive |
| CVE-2026-48054 🧪 | OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri | OpenZeppelin | contracts-wizard | High | 8.8 | 2026-08-06 21:37:55 | Deep Dive |
| CVE-2026-48088 🧪 | OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory | open-reception | appointment-booking-software | Critical | 9.4 | 2026-08-06 21:34:32 | Deep Dive |
| CVE-2026-48087 🧪 | OpenReception: WebAuthn passkey injection allows account takeover | open-reception | appointment-booking-software | Critical | 9.8 | 2026-08-06 21:32:31 | Deep Dive |
| CVE-2026-70636 🧪 | Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint | FlowiseAI | Flowise | High | 7.5 | 2026-08-06 21:31:56 | Deep Dive |
| CVE-2026-67622 🧪 | Flowise 3.1.4 IDOR in OpenAI Assistants Integration | FlowiseAI | Flowise | Critical | 9.9 | 2026-08-06 21:31:34 | Deep Dive |
| CVE-2026-67434 🧪 | PHP_CodeSniffer gitblame report command injection via crafted filename | PHPCSStandards | PHP_CodeSniffer | High | 7.3 | 2026-08-06 21:31:33 | Deep Dive |
| CVE-2026-67621 🧪 | Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints | FlowiseAI | Flowise | High | 7.6 | 2026-08-06 21:31:13 | Deep Dive |