| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-65986 🧪 | CVAT has stored XSS via annotation guide assets | cvat-ai | cvat | High | 8.5 | 2026-08-04 20:13:48 | Deep Dive |
| CVE-2026-70554 🧪 | MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie | MaxSite | MaxSite CMS | Critical | 9.8 | 2026-08-04 20:11:56 | Deep Dive |
| CVE-2026-70486 🧪 | Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin | open-webui | open-webui | High | 8.2 | 2026-08-04 20:01:55 | Deep Dive |
| CVE-2026-47682 🧪 | CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes | cvat-ai | cvat | High | 7.1 | 2026-08-04 20:00:50 | Deep Dive |
| CVE-2026-18810 🧪 | H3C NX15 networkSetup missing authentication | H3C | NX15 | High | 7.3 | 2026-08-04 20:00:09 | Deep Dive |
| CVE-2026-70485 🧪 | Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs | open-webui | open-webui | High | 7.1 | 2026-08-04 19:59:22 | Deep Dive |
| CVE-2026-70482 🧪 | Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client | open-webui | open-webui | High | 8.1 | 2026-08-04 19:51:58 | Deep Dive |
| CVE-2026-70479 🧪 | Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader | open-webui | open-webui | High | 7.7 | 2026-08-04 19:40:12 | Deep Dive |
| CVE-2026-70553 🧪 | MaxSite CMS Unauthenticated RCE via Install Endpoint | MaxSite | MaxSite CMS | Critical | 9.8 | 2026-08-04 19:37:43 | Deep Dive |
| CVE-2026-70478 🧪 | Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service | FlowiseAI | Flowise | Critical | 9.2 | 2026-08-04 19:37:22 | Deep Dive |
| CVE-2026-70477 🧪 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | FlowiseAI | Flowise | Critical | 9.5 | 2026-08-04 19:29:15 | Deep Dive |
| CVE-2026-70552 🧪 | MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php | MaxSite | MaxSite CMS | Critical | 9.8 | 2026-08-04 19:28:28 | Deep Dive |
| CVE-2026-70476 🧪 | Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation | FlowiseAI | Flowise | High | 8.3 | 2026-08-04 19:23:57 | Deep Dive |
| CVE-2026-70475 🧪 | Flowise: Missing Authorization on Execution Update Endpoint | FlowiseAI | Flowise | High | 7.1 | 2026-08-04 19:18:44 | Deep Dive |
| CVE-2026-47781 🧪 | pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing | pdm-project | pdm | High | 8.4 | 2026-08-04 18:42:23 | Deep Dive |
| CVE-2026-69703 🧪 | Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit | maximeAmini | Atals-Livre | Critical | 9.8 | 2026-08-04 18:41:27 | Deep Dive |
| CVE-2026-0163 🧪 | Google Android 安全漏洞 | Android | 超危 | - | 2026-08-04 18:31:11 | Deep Dive | |
| CVE-2026-70474 🧪 | Flowise: Cross-Workspace OAuth2 Credential Metadata Leak | FlowiseAI | Flowise | High | 7.6 | 2026-08-04 18:01:02 | Deep Dive |
| CVE-2026-47764 🧪 | pdm: Path traversal in wheel installation via overridden write_to_fs | pdm-project | pdm | High | 8.4 | 2026-08-04 17:57:16 | Deep Dive |
| CVE-2026-70473 🧪 | Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history | FlowiseAI | Flowise | High | 8.3 | 2026-08-04 17:56:50 | Deep Dive |