| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63725 🧪 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path | nuxsmin | sysPass | High | 7.2 | 2026-08-06 17:34:40 | Deep Dive |
| CVE-2026-70635 🧪 | TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index | timescale | timescaledb | High | 7.1 | 2026-08-06 16:54:38 | Deep Dive |
| CVE-2026-70634 🧪 | TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator | timescale | timescaledb | High | 8.1 | 2026-08-06 16:53:58 | Deep Dive |
| CVE-2026-71445 🧪 | Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-framework | ail-project | ail-framework | High | 8.2 | 2026-08-06 16:48:51 | Deep Dive |
| CVE-2026-71327 🧪 | Traefik: Gateway API route identity collision allows cross-namespace backend hijacking | traefik | traefik | High | 7.6 | 2026-08-06 16:38:12 | Deep Dive |
| CVE-2026-71324 🧪 | Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool | traefik | traefik | High | 7.0 | 2026-08-06 15:56:33 | Deep Dive |
| CVE-2026-43632 🧪 | llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints | ggml-org | llama.cpp | High | 8.1 | 2026-08-06 15:53:19 | Deep Dive |
| CVE-2026-43631 🧪 | llama.cpp b7492–b9060 Use-After-Free RCE via llama-server | ggml-org | llama.cpp | High | 8.1 | 2026-08-06 15:52:10 | Deep Dive |
| CVE-2026-43629 🧪 | llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore | ggml-org | llama.cpp | High | 8.1 | 2026-08-06 15:48:41 | Deep Dive |
| CVE-2026-43628 🧪 | llama.cpp b3978–b9058 Integer Underflow via DRY Sampler | ggml-org | llama.cpp | High | 7.8 | 2026-08-06 15:45:52 | Deep Dive |
| CVE-2026-43627 🧪 | llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function | ggml-org | llama.cpp | High | 7.8 | 2026-08-06 15:40:20 | Deep Dive |
| CVE-2026-70640 🧪 | llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp | ggml-org | llama.cpp | High | 7.0 | 2026-08-06 15:38:23 | Deep Dive |
| CVE-2026-53983 🧪 | Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Request Forgery via Orbital Data Source URL | Efstratios Goudelis | Ground Station | High | 8.6 | 2026-08-06 15:38:02 | Deep Dive |
| CVE-2026-7867 🧪 | Udisks2: udisks2: local privilege escalation via as-user option spoofing | - | - | High | 7.8 | 2026-08-06 15:36:03 | Deep Dive |
| CVE-2026-70638 🧪 | llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp | ggml-org | llama.cpp | High | 7.8 | 2026-08-06 15:35:08 | Deep Dive |
| CVE-2026-53984 🧪 | Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Data Injection via Socket.IO database_backup full_restore Action | Efstratios Goudelis | Ground Station | Critical | 9.1 | 2026-08-06 15:33:50 | Deep Dive |
| CVE-2026-43622 🧪 | llama.cpp b1886–b7445 Double Free via llama-android.cpp | ggml-org | llama.cpp | High | 7.8 | 2026-08-06 15:27:08 | Deep Dive |
| CVE-2026-53985 🧪 | Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO | Efstratios Goudelis | Ground Station | High | 7.5 | 2026-08-06 15:19:44 | Deep Dive |
| CVE-2026-5423 🧪 | Subscription Authentication Bypass via Unverified connectionParams.jwt | neo4j | graphql | High | 8.2 | 2026-08-06 15:15:29 | Deep Dive |
| CVE-2026-68750 🧪 | Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service | rrrene | html_sanitize_ex | High | 8.2 | 2026-08-06 14:50:20 | Deep Dive |