| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-48086 🧪 | OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN | open-reception | appointment-booking-software | Critical | 9.9 | 2026-08-06 21:30:32 | Deep Dive |
| CVE-2026-48085 🧪 | OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap | open-reception | appointment-booking-software | Critical | 9.8 | 2026-08-06 21:29:00 | Deep Dive |
| CVE-2026-47765 🧪 | Frappe: Lack of Permissions in restore/bulk_restore | frappe | frappe | High | 7.1 | 2026-08-06 21:25:32 | Deep Dive |
| CVE-2026-47194 🧪 | Frappe: Host header poisoning can redirect magic login links to an attacker-controlled domain | frappe | frappe | High | 8.6 | 2026-08-06 21:19:19 | Deep Dive |
| CVE-2026-48084 🧪 | OpenReception doesn't rate limit passphrase login attempts | open-reception | appointment-booking-software | High | 7.4 | 2026-08-06 21:18:13 | Deep Dive |
| CVE-2026-48081 🧪 | OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer | open-reception | appointment-booking-software | High | 8.1 | 2026-08-06 21:10:28 | Deep Dive |
| CVE-2026-62857 🧪 | Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Internal Network Resources | fedify-dev | fedify | High | 8.8 | 2026-08-06 21:04:23 | Deep Dive |
| CVE-2026-48079 🧪 | OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry | open-reception | appointment-booking-software | High | 7.4 | 2026-08-06 21:00:45 | Deep Dive |
| CVE-2026-71488 🧪 | league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | thephpleague | commonmark | High | 7.5 | 2026-08-06 20:37:17 | Deep Dive |
| CVE-2026-67422 🧪 | pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors | facelessuser | pymdown-extensions | High | 7.5 | 2026-08-06 20:26:32 | Deep Dive |
| CVE-2026-63637 🧪 | Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter | dgraph-io | dgraph | High | 8.6 | 2026-08-06 20:20:32 | Deep Dive |
| CVE-2026-15733 📌 💣 | WGDashboard Remote Code Execution vulnerability EPSS 0.10 | WGDashboard | WGDashboard | 高危 | - | 2026-08-06 20:00:26 | Deep Dive |
| CVE-2026-70559 🧪 | Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll | DataLinkDC | Dinky | High | 7.5 | 2026-08-06 19:36:36 | Deep Dive |
| CVE-2026-70558 🧪 | Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token | DataLinkDC | Dinky | Critical | 9.8 | 2026-08-06 19:30:55 | Deep Dive |
| CVE-2026-64665 🧪 | Statamic: Account takeover via OAuth email matching without email-verification check | statamic | cms | High | 8.1 | 2026-08-06 19:25:02 | Deep Dive |
| CVE-2026-5857 🧪 | Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP Segments | Contiki-NG | Contiki-NG | High | 8.1 | 2026-08-06 18:52:40 | Deep Dive |
| CVE-2026-5856 🧪 | Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID Validation | Contiki-NG | Contiki-NG | High | 7.1 | 2026-08-06 18:47:39 | Deep Dive |
| CVE-2026-5855 🧪 | Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_read | Contiki-NG | Contiki-NG | High | 7.5 | 2026-08-06 18:39:07 | Deep Dive |
| CVE-2026-48080 🧪 | OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment | open-reception | appointment-booking-software | High | 8.0 | 2026-08-06 18:26:52 | Deep Dive |
| CVE-2026-19111 🧪 | Insecure direct object reference in Strands Agents Tools memory tool namespace isolation | AWS | strands-agents-tools | High | 8.1 | 2026-08-06 18:03:22 | Deep Dive |