| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-66065 🧪 | Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211) | Q00 | ouroboros | High | 8.4 | 2026-08-03 20:20:28 | Deep Dive |
| CVE-2026-47211 🧪 | Ouroboros: Remote Code Execution via Untrusted Project-Directory .env | Q00 | ouroboros | High | 8.4 | 2026-08-03 20:01:03 | Deep Dive |
| CVE-2026-69192 🧪 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass | beaugunderson | ip-address | High | 7.7 | 2026-08-03 19:56:14 | Deep Dive |
| CVE-2026-18641 🧪 | Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection | Sangfor | Operation and Maintenance Security Management System | High | 7.3 | 2026-08-03 19:45:10 | Deep Dive |
| CVE-2026-69185 🧪 | Socket.IO: Zero-attachment Memory Exhaustion | socketio | socket.io | High | 7.5 | 2026-08-03 19:09:10 | Deep Dive |
| CVE-2026-48031 🧪 | Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery | dhax | go-base | Critical | 9.1 | 2026-08-03 19:05:51 | Deep Dive |
| CVE-2026-67598 🧪 | Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php | emlog | emlog | High | 7.4 | 2026-08-03 19:02:06 | Deep Dive |
| CVE-2026-18616 🧪 | GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection | GL-iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 18:30:11 | Deep Dive |
| CVE-2026-18615 🧪 | GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection | GL-iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 18:15:08 | Deep Dive |
| CVE-2026-18614 🧪 | GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection | GL-iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 18:00:10 | Deep Dive |
| CVE-2026-18613 🧪 | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection | GL-iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 17:45:10 | Deep Dive |
| CVE-2026-18612 🧪 | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection | GL-iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 17:30:10 | Deep Dive |
| CVE-2026-18607 🧪 | Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow | Wavlink | WN572 | High | 8.8 | 2026-08-03 16:45:09 | Deep Dive |
| CVE-2026-69152 🧪 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation | juliangruber | brace-expansion | High | 7.5 | 2026-08-03 16:33:36 | Deep Dive |
| CVE-2026-69149 🧪 | Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) | angular | angular | High | 8.6 | 2026-08-03 16:14:40 | Deep Dive |
| CVE-2026-41453 🧪 | Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter | krayin | laravel-crm | High | 8.8 | 2026-08-03 15:47:11 | Deep Dive |
| CVE-2026-41452 📌 💣 | Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup | krayin | laravel-crm | Critical | 9.8 | 2026-08-03 15:43:05 | Deep Dive |
| CVE-2026-18602 🧪 | GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection | GL.iNet | GL-MT3000 | Critical | 9.8 | 2026-08-03 15:30:09 | Deep Dive |
| CVE-2026-18248 🧪 | @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header | @fastify/aws-lambda | @fastify/aws-lambda | Critical | 9.1 | 2026-08-03 15:20:05 | Deep Dive |
| CVE-2026-69097 🧪 | GitPython before 3.1.53 Config Injection via Submodule Names | gitpython-developers | GitPython | High | 7.0 | 2026-08-03 13:20:49 | Deep Dive |