| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-70604 🧪 | Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads | electron | electron | High | 7.4 | 2026-08-05 15:59:24 | Deep Dive |
| CVE-2026-70601 🧪 | Electron: Context isolation bypass via Function.prototype.bind hijack | electron | electron | High | 7.5 | 2026-08-05 15:45:31 | Deep Dive |
| CVE-2026-39923 🧪 | Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset | Flarum | Flarum Framework | High | 8.1 | 2026-08-05 14:38:36 | Deep Dive |
| CVE-2026-67623 🧪 | Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook | mistralai | mistral-vibe | High | 8.8 | 2026-08-05 13:27:27 | Deep Dive |
| CVE-2026-71294 🧪 | Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions | Cotonti | Cotonti | High | 7.6 | 2026-08-05 12:38:48 | Deep Dive |
| CVE-2026-71292 🧪 | Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter | intelliants | subrion | High | 7.2 | 2026-08-05 12:38:43 | Deep Dive |
| CVE-2026-71291 🧪 | Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering | bolt | core | High | 8.8 | 2026-08-05 12:38:41 | Deep Dive |
| CVE-2026-71289 🧪 | NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API | NASA-AMMOS | anms | Critical | 9.8 | 2026-08-05 12:26:35 | Deep Dive |
| CVE-2026-71288 🧪 | Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl | Koha Community | Koha | High | 8.8 | 2026-08-05 12:26:34 | Deep Dive |
| CVE-2026-71287 🧪 | Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection | Cacti | cacti | High | 8.8 | 2026-08-05 12:26:33 | Deep Dive |
| CVE-2026-71285 🧪 | Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages | louislam | uptime-kuma | High | 8.1 | 2026-08-05 12:26:31 | Deep Dive |
| CVE-2026-71284 🧪 | Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename | fledge-iot | fledge | High | 7.2 | 2026-08-05 12:26:30 | Deep Dive |
| CVE-2026-71281 🧪 | peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and CorDA Modules | huggingface | peft | High | 8.8 | 2026-08-05 12:26:27 | Deep Dive |
| CVE-2026-71279 🧪 | Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execution | Koenkk | zigbee2mqtt | High | 8.0 | 2026-08-05 12:26:26 | Deep Dive |
| CVE-2026-71280 🧪 | go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch | go-shiori | shiori | High | 8.5 | 2026-08-05 12:26:26 | Deep Dive |
| CVE-2026-71278 🧪 | rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation | iot-ecology | rust-iot-platform | Critical | 9.8 | 2026-08-05 12:26:25 | Deep Dive |
| CVE-2026-71277 🧪 | rust-iot-platform Authentication Bypass via Non-Validated Authorization Header | iot-ecology | rust-iot-platform | Critical | 9.1 | 2026-08-05 12:26:24 | Deep Dive |
| CVE-2026-71276 🧪 | Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter | absmach | magistrala | High | 7.1 | 2026-08-05 12:26:23 | Deep Dive |
| CVE-2026-71274 🧪 | OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels | openshwprojects | OpenBK7231T_App | High | 8.5 | 2026-08-05 12:26:21 | Deep Dive |
| CVE-2026-71272 🧪 | Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext() | usememos | memos | High | 8.5 | 2026-08-05 12:26:19 | Deep Dive |