| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67329 🧪 | @better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription | better-auth | stripe | High | 7.1 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67300 🧪 | FreeRDP before 3.29.0 Use-After-Free via async message proxy | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67328 🧪 | @better-auth/sso before 1.6.21 Account Takeover via SSO | better-auth | sso | High | 8.1 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67333 🧪 | better-auth before 1.6.13 Stored XSS via javascript redirect_uri | better-auth | better-auth | High | 7.2 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67299 🧪 | FreeRDP before 3.29.0 Use-After-Free via WindowIcon async message | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67340 🧪 | ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts | ArcadeData | arcadedb | High | 7.2 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67326 🧪 | GitPython before 3.1.50 Newline Injection via config_writer section | gitpython-developers | GitPython | High | 7.0 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67331 🧪 | better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass | better-auth | scim | High | 8.3 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67343 🧪 | ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server | ArcadeData | arcadedb | High | 8.8 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67291 🧪 | FreeRDP before 3.29.0 Heap Out-of-Bounds Read via GLYPH_FRAGMENT_ADD | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67296 🧪 | FreeRDP before 3.29.0 Denial of Service via RDPEI PDU | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-67289 🧪 | FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection | FreeRDP | FreeRDP | Critical | 9.8 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2025-71403 🧪 | better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass | better-auth | better-auth | High | 7.1 | 2026-08-01 12:22:18 | Deep Dive |
| CVE-2026-66402 🧪 | FreeRDP before 3.29.0 TLS Certificate Identity Validation Bypass | FreeRDP | FreeRDP | Critical | 9.8 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67308 🧪 | Wazuh GitHub Actions Shell Injection via Fork Pull Request | wazuh | wazuh | Critical | 9.3 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67325 🧪 | GitPython before 3.1.51 Command Injection via option prefix abbreviation | gitpython-developers | GitPython | High | 8.8 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67290 🧪 | FreeRDP before 3.29.0 Heap Out-of-Bounds Read via TSMF | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67301 🧪 | FreeRDP before 3.29.0 Out-of-bounds Read via Polygon async message-proxy | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67330 🧪 | better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision | better-auth | scim | Critical | 9.9 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67322 🧪 | GitPython before 3.1.52 Environment Variable Exfiltration via clone_from | gitpython-developers | GitPython | High | 7.5 | 2026-08-01 12:22:17 | Deep Dive |