| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71243 🧪 | backmeup (npm) - OS Command Injection via Backup Option Values | adaltas | backmeup | High | 8.8 | 2026-08-05 10:56:48 | Deep Dive |
| CVE-2026-71242 🧪 | Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in NotePolicy | crater-invoice | crater | High | 8.3 | 2026-08-05 10:56:45 | Deep Dive |
| CVE-2026-71241 🧪 | Book-Management-System - Unauthenticated Disclosure of Student PII and Borrowing History | lyric777 | Book-Management-System | High | 7.5 | 2026-08-05 10:56:43 | Deep Dive |
| CVE-2026-71239 🧪 | DjangoCRM - Server-Side Template Injection in Mass Mail Message Rendering | DjangoCRM | django-crm | High | 8.1 | 2026-08-05 10:56:37 | Deep Dive |
| CVE-2026-71238 🧪 | DjangoCRM - Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery | DjangoCRM | django-crm | Critical | 9.1 | 2026-08-05 10:56:34 | Deep Dive |
| CVE-2026-71237 🧪 | Miantang IoT-PHP - Unauthenticated SQL Injection in /userlogin | Miantang | IoT-PHP | Critical | 9.8 | 2026-08-05 10:56:31 | Deep Dive |
| CVE-2026-71236 🧪 | Grocy - Stored XSS via HTMLPurifier Output Double-Decode | grocy | grocy | High | 8.7 | 2026-08-05 10:56:28 | Deep Dive |
| CVE-2026-71235 🧪 | Magistrala IoT Platform - Unrestricted Go/Lua Script Execution in Rules Engine | absmach | magistrala | High | 8.8 | 2026-08-05 10:56:25 | Deep Dive |
| CVE-2026-71234 🧪 | Documize Community - Attachment Download Authorization Bypass via Non-Validated secure Token | documize | community | High | 7.5 | 2026-08-05 10:56:22 | Deep Dive |
| CVE-2026-71233 🧪 | InvoiceNinja - Stored XSS via Invoice/Quote Terms Field | invoiceninja | invoiceninja | High | 8.7 | 2026-08-05 10:56:19 | Deep Dive |
| CVE-2026-71232 🧪 | MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCE | magicblack | maccms10 | High | 7.2 | 2026-08-05 10:56:16 | Deep Dive |
| CVE-2026-71231 🧪 | IOTSmartHome - Unauthenticated SQL Injection via lastLogin Cookie | thebradleysanders | IOTSmartHome | Critical | 9.8 | 2026-08-05 10:56:07 | Deep Dive |
| CVE-2026-12609 🧪 | Eclipse Theia 路径遍历漏洞 | Eclipse Foundation | Eclipse Theia | High | 7.5 | 2026-08-05 10:55:43 | Deep Dive |
| CVE-2026-66747 🧪 | ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant | Zbtlink | CPE2801 Firmware | Critical | 9.8 | 2026-08-05 10:50:46 | Deep Dive |
| CVE-2026-44945 🧪 | Cross-Cluster Impersonation Confused-Deputy Privilege Escalation | SUSE | Rancher | Critical | 9.1 | 2026-08-05 10:00:04 | Deep Dive |
| CVE-2026-25703 🧪 | Potential information leakage from manager /network/graph API in NeuVector | SUSE | NeuVector | High | 7.3 | 2026-08-05 09:48:19 | Deep Dive |
| CVE-2026-55997 🧪 | Long-lived Rancher registration token exposed in plaintext | rancher | rancher | High | 8.8 | 2026-08-05 07:53:00 | Deep Dive |
| CVE-2026-59675 🧪 | Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service | SUSE | Rancher | High | 7.5 | 2026-08-05 07:49:12 | Deep Dive |
| CVE-2026-71215 🧪 | art-template - Path Traversal in Sub-Template Resolution via include()/extend() | art-template | art-template | High | 7.5 | 2026-08-05 06:59:36 | Deep Dive |
| CVE-2026-71214 🧪 | NASA-AMMOS plandev - Client-Supplied session_variables Bypass Hasura-Origin Authorization in sequencing-server | NASA-AMMOS | plandev (sequencing-server) | Critical | 9.8 | 2026-08-05 06:59:33 | Deep Dive |