| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67243 🧪 | refirio freo2 任意文件上传漏洞 | refirio | freo2 | High | 8.6 | 2026-08-04 06:38:25 | Deep Dive |
| CVE-2026-64561 🧪 | KVM: x86: Check for invalid/obsolete root *after* making MMU pages available | Linux | Linux | High | 8.8 | 2026-08-04 06:23:21 | Deep Dive |
| CVE-2026-18686 🧪 | GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection | GL.iNet | GL-MT3000 | Critical | 9.8 | 2026-08-04 00:00:12 | Deep Dive |
| CVE-2026-67857 🧪 | Open62541 安全漏洞 | - | - | High | 7.5 | 2026-08-04 00:00:00 | Deep Dive |
| CVE-2026-67861 🧪 | Open62541 安全漏洞 | - | - | High | 7.5 | 2026-08-04 00:00:00 | Deep Dive |
| CVE-2026-67858 🧪 | Open62541 安全漏洞 | - | - | High | 7.5 | 2026-08-04 00:00:00 | Deep Dive |
| CVE-2026-67859 🧪 | Open62541 安全漏洞 | - | - | High | 7.5 | 2026-08-04 00:00:00 | Deep Dive |
| CVE-2026-18685 🧪 | GL.iNet GL-MT3000 modem.so glc set_upgrade command injection | GL.iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 23:15:09 | Deep Dive |
| CVE-2026-18684 🧪 | GL.iNet GL-MT3000 modem.so glc remove_profile command injection | GL.iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 22:45:10 | Deep Dive |
| CVE-2026-47746 🧪 | Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks | misskey-dev | misskey | High | 8.9 | 2026-08-03 21:56:40 | Deep Dive |
| CVE-2026-46713 🧪 | Misskey: JSON-LD signature validation + compaction may lead to improper activity handling | misskey-dev | misskey | Critical | 9.2 | 2026-08-03 21:37:46 | Deep Dive |
| CVE-2026-69249 🧪 | python-cryptography: Duplicate self-signed intermediates can cause exponential path-building | pyca | cryptography | High | 8.7 | 2026-08-03 21:26:46 | Deep Dive |
| CVE-2026-69247 🧪 | cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing | pyca | cryptography | High | 8.2 | 2026-08-03 21:16:32 | Deep Dive |
| CVE-2026-69246 🧪 | Guzzle: Noncanonical host can bypass host-based checks | guzzle | guzzle | High | 7.2 | 2026-08-03 21:07:04 | Deep Dive |
| CVE-2026-48113 🧪 | Chisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection | jpillora | chisel | High | 8.5 | 2026-08-03 21:05:14 | Deep Dive |
| CVE-2026-48063 🧪 | Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload | WhiskeySockets | Baileys | Critical | 9.3 | 2026-08-03 20:55:08 | Deep Dive |
| CVE-2026-69244 🧪 | AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) | aio-libs | aiohttp | High | 7.1 | 2026-08-03 20:51:00 | Deep Dive |
| CVE-2026-18647 🧪 | jina-ai reader Crawler/Puppeteer crawler.ts isValidTLD server-side request forgery | jina-ai | reader | High | 7.3 | 2026-08-03 20:45:09 | Deep Dive |
| CVE-2026-18733 🧪 | Prompt injection bypasses shell tool consent gate in Strands Agents Tools | AWS | strands-agents-tools | High | 8.8 | 2026-08-03 20:33:25 | Deep Dive |
| CVE-2026-69240 🧪 | Sequelize: SQL Injection (Oracle DB) | sequelize | sequelize | Critical | 9.8 | 2026-08-03 20:28:29 | Deep Dive |