| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71213 🧪 | typemill - No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force | typemill | typemill | Critical | 9.1 | 2026-08-05 06:59:30 | Deep Dive |
| CVE-2026-71209 🧪 💣 | audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal | advplyr | audiobookshelf | High | 7.5 | 2026-08-05 06:59:17 | Deep Dive |
| CVE-2026-71207 🧪 | Stock-Inventory-Management-System - Unauthenticated SQL Injection and Hardcoded Credentials in login.php Enable Full Authentication Bypass | mrswapnilsahu | Stock-Inventory-Management-System | Critical | 9.8 | 2026-08-05 06:59:10 | Deep Dive |
| CVE-2026-71206 🧪 | shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion | go-shiori | shiori | High | 8.3 | 2026-08-05 06:59:07 | Deep Dive |
| CVE-2026-71202 🧪 | raster - Integer Underflow in crop() Offset Handling Causes Capacity-Overflow Panic | kosinix | raster | High | 7.5 | 2026-08-05 06:58:54 | Deep Dive |
| CVE-2026-70378 🧪 | imagecli - Negative carve Ratio Bypasses Bounds Check and Crashes Process via Reachable Panic | theotherphil | imagecli | High | 7.5 | 2026-08-05 06:58:51 | Deep Dive |
| CVE-2026-70377 🧪 | imagecli - Uncontrolled Memory Allocation via Unbounded scale Ratio Causes Denial of Service | theotherphil | imagecli | High | 7.5 | 2026-08-05 06:58:48 | Deep Dive |
| CVE-2026-70376 🧪 | Pluck CMS - CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and RCE | pluck-cms | Pluck CMS | Critical | 9.6 | 2026-08-05 06:58:44 | Deep Dive |
| CVE-2026-55747 🧪 | PocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File Tools | The-Pocket | PocketFlow (pocketflow-coding-agent cookbook example) | Medium | 6.8 | 2026-08-05 06:58:41 | Deep Dive |
| CVE-2026-55739 🧪 | Crater - Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Company Customer Data Theft and Deletion | crater-invoice | Crater | High | 8.3 | 2026-08-05 06:58:38 | Deep Dive |
| CVE-2026-54418 🧪 | Leantime - Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account 2FA Secret Disclosure and Bypass | Leantime | Leantime | High | 8.1 | 2026-08-05 06:58:35 | Deep Dive |
| CVE-2026-54416 🧪 | Pluck CMS - Unrestricted File Upload via Missing .php8 Extension in Upload Blacklist | pluck-cms | Pluck CMS | High | 7.2 | 2026-08-05 06:58:24 | Deep Dive |
| CVE-2026-17505 📌 💣 | TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting | cozmoslabs | TranslatePress – Translate Multilingual sites with AI Translation | Medium | 6.1 | 2026-08-05 06:37:57 | Deep Dive |
| CVE-2026-17532 📌 💣 | Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting | seraphinitesoft | Seraphinite Accelerator | Medium | 6.1 | 2026-08-05 06:37:56 | Deep Dive |
| CVE-2026-6639 📌 💣 | AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenticated Sensitive Information Exposure | wupsales | AI Copilot – Content Generator | High | 7.5 | 2026-08-05 06:37:54 | Deep Dive |
| CVE-2026-70375 🧪 | HashBrown CMS - OS Command Injection via Git Deployer Branch Field | HashBrownCMS | hashbrown-cms | High | 8.8 | 2026-08-05 05:46:26 | Deep Dive |
| CVE-2026-70374 🧪 | HashBrown CMS - OS Command Injection in Media Upload Thumbnail Generation | HashBrownCMS | hashbrown-cms | High | 8.8 | 2026-08-05 05:46:19 | Deep Dive |
| CVE-2026-18902 🧪 | H3C NX15 esps repeaterproc command injection | H3C | NX15 | High | 7.2 | 2026-08-05 04:30:09 | Deep Dive |
| CVE-2026-18901 🧪 | H3C NX15 Web API esps service.add routine | H3C | NX15 | High | 7.2 | 2026-08-05 04:00:11 | Deep Dive |
| CVE-2026-18900 🧪 | H3C NX15 Backend RPC esps file.exec os command injection | H3C | NX15 | High | 7.2 | 2026-08-05 03:45:10 | Deep Dive |