| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-78637 🧪 | Fdawgs node-poppler Argument Injection index.js pdfUnite argument injection | Fdawgs | node-poppler | High | 7.3 | 2026-08-25 04:45:11 | Deep Dive |
| CVE-2026-78683 🧪 | NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization | nltk | nltk | Critical | 9.6 | 2026-08-25 01:30:39 | Deep Dive |
| CVE-2026-78681 🧪 | NLTK before 3.10.3 Entity Expansion DoS via ElementTree | nltk | nltk | High | 7.5 | 2026-08-25 01:30:38 | Deep Dive |
| CVE-2026-78682 🧪 | NLTK before 3.10.3 SSRF Protection Bypass via Proxy | nltk | nltk | High | 7.5 | 2026-08-25 01:30:38 | Deep Dive |
| CVE-2026-78680 🧪 | NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary | nltk | nltk | High | 7.8 | 2026-08-25 01:30:37 | Deep Dive |
| CVE-2026-78677 🧪 | GitPython before 3.1.59 Path Traversal via separate-git-dir | gitpython-developers | GitPython | High | 7.5 | 2026-08-25 01:30:35 | Deep Dive |
| CVE-2026-78676 🧪 | GitPython before 3.1.59 Remote Code Execution via Config Injection | gitpython-developers | GitPython | Critical | 9.8 | 2026-08-25 01:30:34 | Deep Dive |
| CVE-2026-78675 🧪 | GitPython before 3.1.59 Local File Content Disclosure via .gitmodules | gitpython-developers | GitPython | High | 8.4 | 2026-08-25 01:30:33 | Deep Dive |
| CVE-2026-76846 🧪 | Grav before 2.0.16 Information Disclosure via Twig Sandbox | getgrav | grav | High | 7.5 | 2026-08-25 01:30:32 | Deep Dive |
| CVE-2026-75574 🧪 | Grav before 4.2.2 Remote Code Execution via Email Twig | getgrav | grav | High | 8.8 | 2026-08-25 01:30:27 | Deep Dive |
| CVE-2026-72700 🧪 | Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison | getgrav | grav | High | 7.5 | 2026-08-25 01:30:23 | Deep Dive |
| CVE-2026-72696 🧪 | Grav CMS before 2.0.16 Symlink Following via createLockFile | getgrav | grav | High | 8.4 | 2026-08-25 01:30:15 | Deep Dive |
| CVE-2026-72695 🧪 | Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile | getgrav | grav | High | 8.1 | 2026-08-25 01:30:12 | Deep Dive |
| CVE-2026-56709 🧪 | Grav before 3.9.2 Host Header Injection via sendInvitationEmail | getgrav | grav | High | 7.5 | 2026-08-25 01:30:10 | Deep Dive |
| CVE-2026-56707 🧪 | Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode | getgrav | grav | High | 7.7 | 2026-08-25 01:30:07 | Deep Dive |
| CVE-2026-56705 🧪 | Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection | vrana | adminer | Critical | 9.8 | 2026-08-25 01:30:04 | Deep Dive |
| CVE-2026-56703 🧪 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | vrana | adminer | High | 7.2 | 2026-08-25 01:30:01 | Deep Dive |
| CVE-2026-34968 🧪 | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop | vrana | adminer | High | 8.1 | 2026-08-25 01:30:00 | Deep Dive |
| CVE-2026-56702 🧪 | Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload | vrana | adminer | High | 8.8 | 2026-08-25 01:30:00 | Deep Dive |
| CVE-2026-53532 🧪 | OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS) | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-24 22:24:03 | Deep Dive |