| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-69258 🧪 | Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API | FlowiseAI | Flowise | High | 8.8 | 2026-08-04 15:56:07 | Deep Dive |
| CVE-2026-69257 🧪 | Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses | FlowiseAI | Flowise | High | 7.6 | 2026-08-04 15:51:48 | Deep Dive |
| CVE-2026-15307 🧪 | Server-side file-write and request forgery via spatial lookups | djangoproject | Django | High | 8.8 | 2026-08-04 15:48:19 | Deep Dive |
| CVE-2026-69256 🧪 | Flowise: Remote Code Execution Vulnerability in CSVAgent | FlowiseAI | Flowise | Critical | 9.4 | 2026-08-04 15:45:55 | Deep Dive |
| CVE-2026-69255 🧪 | Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified | FlowiseAI | Flowise | Critical | 9.2 | 2026-08-04 15:39:39 | Deep Dive |
| CVE-2026-69110 🧪 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music | Microck | opencode-studio | Critical | 9.1 | 2026-08-04 15:30:21 | Deep Dive |
| CVE-2026-69254 🧪 | Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override | FlowiseAI | Flowise | Critical | 9.4 | 2026-08-04 15:28:50 | Deep Dive |
| CVE-2026-69100 🧪 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution | dromara | lamp-cloud | High | 8.8 | 2026-08-04 15:20:03 | Deep Dive |
| CVE-2026-69098 🧪 | kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization | Cinnamon | kotaemon | Critical | 9.8 | 2026-08-04 15:15:06 | Deep Dive |
| CVE-2026-69253 🧪 | Flowise Sandbox Escape to RCE | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-04 15:13:39 | Deep Dive |
| CVE-2026-69252 🧪 | Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization | FlowiseAI | Flowise | High | 7.2 | 2026-08-04 14:54:00 | Deep Dive |
| CVE-2026-18801 🧪 | Stored Clickhouse SQL Injection Through Customer Usage Attribution | openmeter | openmeter | Critical | 9.3 | 2026-08-04 14:53:02 | Deep Dive |
| CVE-2026-68494 🧪 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for CVE-2026-18401 / GHSA-72hv-8253-57qq) | FasterXML | jackson-core | High | 8.7 | 2026-08-04 14:39:14 | Deep Dive |
| CVE-2026-69251 🧪 💣 | Flowise RCE via TypeORM DataSource | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-04 14:27:55 | Deep Dive |
| CVE-2026-69250 🧪 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | FlowiseAI | Flowise | High | 8.5 | 2026-08-04 14:20:35 | Deep Dive |
| CVE-2026-58080 🧪 | Eclipse Milo 授权问题漏洞 | Eclipse Foundation | Eclipse Milo | High | 8.8 | 2026-08-04 12:05:11 | Deep Dive |
| CVE-2026-63252 🧪 | Eclipse Milo 资源管理错误漏洞 | Eclipse Foundation | Eclipse Milo | High | 8.7 | 2026-08-04 12:03:19 | Deep Dive |
| CVE-2026-62927 🧪 | Eclipse Milo 授权问题漏洞 | Eclipse Foundation | Eclipse Milo | High | 8.7 | 2026-08-04 11:58:00 | Deep Dive |
| CVE-2026-60007 🧪 | Eclipse Milo 信息泄露漏洞 | Eclipse Foundation | Eclipse Milo | Critical | 9.1 | 2026-08-04 11:55:42 | Deep Dive |
| CVE-2026-10050 🧪 | Digest authentication lossy encoding | Eclipse Foundation | Eclipse Jetty - EE8 | High | 8.7 | 2026-08-04 11:02:41 | Deep Dive |