| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-75498 🧪 | Webkul QloApps SQL injection | Webkul | QloApps | High | 7.2 | 2026-08-25 16:37:44 | Deep Dive |
| CVE-2026-59184 🧪 | OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 16:28:48 | Deep Dive |
| CVE-2026-55557 🧪 | browse-mcp: Arbitrary file write via unconfined download and state paths | That1Drifter | browse-mcp | High | 8.6 | 2026-08-25 16:28:07 | Deep Dive |
| CVE-2026-55553 🧪 | urllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage | node-modules | urllib | High | 7.5 | 2026-08-25 16:18:22 | Deep Dive |
| CVE-2026-24169 🧪 | NVIDIA Unified Fabric Manager Enterprise 命令注入漏洞 | NVIDIA | Unified Fabric Manager Enterprise - GA | High | 8.0 | 2026-08-25 16:17:43 | Deep Dive |
| CVE-2026-24170 🧪 | NVIDIA Unified Fabric Manager Enterprise 授权问题漏洞 | NVIDIA | Unified Fabric Manager Enterprise - GA | High | 8.8 | 2026-08-25 16:17:42 | Deep Dive |
| CVE-2026-24263 🧪 | NVIDIA DGX Spark 异常处理不当漏洞 | NVIDIA | DGX Spark | High | 8.2 | 2026-08-25 16:11:07 | Deep Dive |
| CVE-2026-55640 🧪 | Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) | cbcoutinho | nextcloud-mcp-server | Critical | 9.1 | 2026-08-25 16:03:28 | Deep Dive |
| CVE-2026-55580 🧪 | mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist | sonirico | mcp-shell | High | 8.6 | 2026-08-25 15:42:36 | Deep Dive |
| CVE-2026-55581 🧪 | mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable | sonirico | mcp-shell | High | 8.4 | 2026-08-25 15:40:11 | Deep Dive |
| CVE-2026-55582 🧪 | mcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias | sonirico | mcp-shell | High | 8.4 | 2026-08-25 15:37:43 | Deep Dive |
| CVE-2026-55546 🧪 | QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input | QWED-AI | qwed-mcp | Critical | 9.8 | 2026-08-25 15:25:35 | Deep Dive |
| CVE-2026-55536 🧪 | Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) | MervinPraison | PraisonAI | Critical | 9.1 | 2026-08-25 15:21:53 | Deep Dive |
| CVE-2026-55532 🧪 | PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server | MervinPraison | PraisonAI | High | 7.6 | 2026-08-25 15:17:53 | Deep Dive |
| CVE-2026-79784 🧪 | Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration | gemelo-ai | vocos | High | 8.8 | 2026-08-25 15:16:12 | Deep Dive |
| CVE-2026-79774 🧪 | Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy | wintercms | winter | High | 8.4 | 2026-08-25 15:16:06 | Deep Dive |
| CVE-2026-79770 🧪 | Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer | sparklemotion | nokogiri | High | 7.5 | 2026-08-25 15:16:03 | Deep Dive |
| CVE-2026-79675 🧪 | NLTK before 3.10.3 JVM Argument Injection via Per-Call Options | nltk | nltk | Critical | 9.8 | 2026-08-25 15:16:01 | Deep Dive |
| CVE-2026-79674 🧪 | NLTK 3.10.2 Path Traversal via corpus-reader constructors | nltk | nltk | High | 8.2 | 2026-08-25 15:16:00 | Deep Dive |
| CVE-2026-55527 🧪 | PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location | MervinPraison | PraisonAI | High | 7.1 | 2026-08-25 15:09:08 | Deep Dive |