| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71271 🧪 | Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass | usememos | memos | High | 8.5 | 2026-08-05 12:26:19 | Deep Dive |
| CVE-2026-71270 🧪 | Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPrint Subprocess | Stirling-Tools | Stirling-PDF | High | 8.6 | 2026-08-05 12:26:18 | Deep Dive |
| CVE-2026-71268 🧪 | OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write | thiagoralves | OpenPLC_v3 | Critical | 9.9 | 2026-08-05 12:26:16 | Deep Dive |
| CVE-2026-71267 🧪 | microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header() | rxi | microtar | Critical | 9.8 | 2026-08-05 12:26:15 | Deep Dive |
| CVE-2026-71266 🧪 | tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing | syoyo | tinyobjloader-c | High | 7.8 | 2026-08-05 12:26:14 | Deep Dive |
| CVE-2026-71265 🧪 | Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy() | domoticz | domoticz | High | 7.5 | 2026-08-05 12:26:13 | Deep Dive |
| CVE-2026-71264 🧪 | WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settings-PIN Lock State | Aircoookie | WLED | High | 8.2 | 2026-08-05 12:26:12 | Deep Dive |
| CVE-2026-71263 🧪 | FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool() | cwalter-at | FreeModbus | Critical | 9.1 | 2026-08-05 12:26:11 | Deep Dive |
| CVE-2026-71262 🧪 | IoTSharp BlobStorageController Missing Authentication and Path Traversal | IoTSharp | IoTSharp | Critical | 9.8 | 2026-08-05 12:26:11 | Deep Dive |
| CVE-2026-71261 🧪 | dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buffer Overflow on 32-bit Builds | mackron | dr_libs | High | 7.8 | 2026-08-05 12:26:10 | Deep Dive |
| CVE-2026-71259 🧪 | ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution | esphome | esphome | High | 8.6 | 2026-08-05 12:26:08 | Deep Dive |
| CVE-2026-16022 🧪 | Command Injection in @oblique/cli | Swiss Federal Office of Information Technology, Systems and Telecommunication | @oblique/cli | High | 7.8 | 2026-08-05 12:06:20 | Deep Dive |
| CVE-2026-71256 🧪 | nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id | debevv | nanoMODBUS | Critical | 9.8 | 2026-08-05 11:44:22 | Deep Dive |
| CVE-2026-71255 🧪 | nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res() | debevv | nanoMODBUS | High | 8.6 | 2026-08-05 11:44:21 | Deep Dive |
| CVE-2026-71254 🧪 | nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record() | debevv | nanoMODBUS | Critical | 9.8 | 2026-08-05 11:44:20 | Deep Dive |
| CVE-2026-61891 🧪 | Eclipse Theia 信息泄露漏洞 | Eclipse Foundation | Eclipse Theia | High | 7.5 | 2026-08-05 11:03:02 | Deep Dive |
| CVE-2026-60009 🧪 | Eclipse Theia 路径遍历漏洞 | Eclipse Foundation | Eclipse Theia | High | 8.8 | 2026-08-05 10:59:24 | Deep Dive |
| CVE-2026-71252 🧪 | toner-management - Unauthenticated State-Changing Admin Actions | raghav993 | toner-management | High | 8.2 | 2026-08-05 10:57:14 | Deep Dive |
| CVE-2026-71248 🧪 | Inventory-Management-System-PHP - Unauthenticated SQL Injection in Login and Product Deletion | Harsh21Patel | Inventory-Management-System-PHP | Critical | 9.8 | 2026-08-05 10:57:03 | Deep Dive |
| CVE-2026-71244 🧪 | Paperless-ngx - Mail Account Test Connection Leaks Stored IMAP/OAuth Credentials to Attacker-Controlled Host | paperless-ngx | paperless-ngx | Medium | 6.5 | 2026-08-05 10:56:51 | Deep Dive |