| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-68749 🧪 | Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service | rrrene | html_sanitize_ex | High | 8.2 | 2026-08-06 14:50:13 | Deep Dive |
| CVE-2026-53977 🧪 | OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown | Bohdan Triapitsyn | OpenChamber | High | 7.5 | 2026-08-06 14:43:38 | Deep Dive |
| CVE-2026-70646 🧪 | aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler | vovchic17 | aiosend | High | 7.5 | 2026-08-06 14:38:53 | Deep Dive |
| CVE-2026-28141 📌 💣 | WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability | Syed Balkhi | NextGEN Gallery | High | 7.1 | 2026-08-06 14:27:11 | Deep Dive |
| CVE-2026-53976 🧪 💣 | OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter | Bohdan Triapitsyn | OpenChamber | Critical | 9.1 | 2026-08-06 14:24:32 | Deep Dive |
| CVE-2026-53975 🧪 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | Bohdan Triapitsyn | OpenChamber | Critical | 9.8 | 2026-08-06 14:06:13 | Deep Dive |
| CVE-2026-66733 🧪 | Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache | Eukaryot | sonic3air | High | 7.5 | 2026-08-06 12:58:05 | Deep Dive |
| CVE-2026-19021 🧪 | SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection | SourceCodester | Computer Repair Shop Management System | High | 7.3 | 2026-08-06 08:00:09 | Deep Dive |
| CVE-2026-19010 🧪 | TinyAGI Message API Endpoint index.ts processMessage authorization | - | TinyAGI | High | 7.3 | 2026-08-06 07:00:11 | Deep Dive |
| CVE-2026-19009 🧪 | TinyAGI Message API Endpoint response.ts collectFiles file inclusion | - | TinyAGI | High | 7.3 | 2026-08-06 06:45:09 | Deep Dive |
| CVE-2026-13153 📌 💣 | Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint | Unknown | Gutenberg Essential Blocks | 中危 | - | 2026-08-06 06:00:13 | Deep Dive |
| CVE-2026-16268 📌 💣 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler | Unknown | Newsletters | 高危 | - | 2026-08-06 06:00:10 | Deep Dive |
| CVE-2026-19000 🧪 | JeecgBoot Anonymous Chat Attachment send server-side request forgery | - | JeecgBoot | High | 7.3 | 2026-08-06 05:15:09 | Deep Dive |
| CVE-2026-16636 🧪 | FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs | wpmanageninja | FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP | High | 7.2 | 2026-08-06 03:26:08 | Deep Dive |
| CVE-2026-18991 🧪 | nanocoai NanoClaw send_file core.ts path traversal | nanocoai | NanoClaw | High | 7.3 | 2026-08-06 02:30:13 | Deep Dive |
| CVE-2026-67531 🧪 | FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool | agentfront | frontmcp | Critical | 9.3 | 2026-08-05 22:54:36 | Deep Dive |
| CVE-2026-19024 🧪 | HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message | The HDF Group | HDF5 | High | 8.2 | 2026-08-05 22:14:30 | Deep Dive |
| CVE-2026-71321 🧪 | Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation | nuxt | nuxt | High | 7.5 | 2026-08-05 21:42:48 | Deep Dive |
| CVE-2026-71320 🧪 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | nuxt | nuxt | High | 8.1 | 2026-08-05 21:29:51 | Deep Dive |
| CVE-2026-71319 🧪 | Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution | nuxt | devtools | Critical | 9.6 | 2026-08-05 21:26:59 | Deep Dive |