| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-18577 KEV 📌 💣 | Incomplete patch leads to administrative account takeover EPSS 0.15 | N-able | N-central | High | 8.2 | 2026-08-02 22:06:18 | Deep Dive |
| CVE-2026-65321 🧪 | PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS | laughingman7743 | PyAthena | Critical | 9.8 | 2026-08-02 14:56:29 | Deep Dive |
| CVE-2026-68581 🧪 | Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision | go-vikunja | vikunja | High | 8.1 | 2026-08-02 12:15:28 | Deep Dive |
| CVE-2026-68580 🧪 | FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel | FreeRDP | FreeRDP | High | 7.5 | 2026-08-02 12:15:27 | Deep Dive |
| CVE-2026-68579 🧪 | FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read | FreeRDP | FreeRDP | Critical | 9.6 | 2026-08-02 12:15:26 | Deep Dive |
| CVE-2026-68578 🧪 | ArcadeDB before 26.7.3 Authentication Bypass via MCP Transport | ArcadeData | arcadedb | High | 7.5 | 2026-08-02 12:15:26 | Deep Dive |
| CVE-2026-67357 🧪 | ArcadeDB before 26.7.3 Information Disclosure via get_server_settings | ArcadeData | arcadedb | High | 7.5 | 2026-08-02 12:15:25 | Deep Dive |
| CVE-2026-67356 🧪 | ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger | ArcadeData | arcadedb | High | 8.8 | 2026-08-02 12:15:24 | Deep Dive |
| CVE-2025-71400 🧪 | better-auth passkey before 1.4.0 IDOR via delete-passkey | better-auth | passkey | High | 7.1 | 2026-08-02 12:15:23 | Deep Dive |
| CVE-2025-71399 🧪 | Better Auth before 1.4.5 Path Normalization Bypass via rou3 | better-auth | better-auth | High | 8.6 | 2026-08-02 12:15:22 | Deep Dive |
| CVE-2026-55735 🧪 | Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation | ueberauth | guardian | High | 8.2 | 2026-08-01 18:46:05 | Deep Dive |
| CVE-2026-67298 🧪 | FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67320 🧪 | axios before 0.33.0 Prototype Pollution via Node HTTP adapter | axios | axios | High | 8.3 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67341 🧪 | ArcadeDB before 26.7.2 Authorization Bypass via SQL DEFINE FUNCTION | ArcadeData | arcadedb | Critical | 9.8 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67327 🧪 | better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP | better-auth | better-auth | High | 8.3 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67323 🧪 | GitPython before 3.1.51 Command Injection via unguarded Git options | gitpython-developers | GitPython | High | 8.4 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67288 🧪 | FreeRDP before 3.29.0 Denial of Service via smartcard cache | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67309 🧪 | Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | traefik | traefik | High | 7.8 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67336 🧪 | better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider | better-auth | better-auth | High | 8.7 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67324 🧪 | GitPython 3.1.50 Authentication Bypass via Joined Short Options | gitpython-developers | GitPython | Critical | 9.8 | 2026-08-01 12:22:18 | Deep Dive |