| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-10196 | Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | Critical | 9.8 | 2026-09-05 11:28:48 | Deep Dive |
| CVE-2026-86124 | AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server | HKUDS | AutoAgent | Critical | 9.8 | 2026-09-05 09:59:12 | Deep Dive |
| CVE-2026-86121 | Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control | trycua | cua-computer-server | Critical | 9.8 | 2026-09-05 09:59:10 | Deep Dive |
| CVE-2024-11080 | Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection | pickplugins | Post Grid | Critical | 9.8 | 2026-09-05 08:27:21 | Deep Dive |
| CVE-2026-83627 | Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log | wpmudev | Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN | Critical | 9.8 | 2026-09-05 05:30:55 | Deep Dive |
| CVE-2026-13447 | MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery | inspireui | MStore API – Create Native Android & iOS Apps On The Cloud | Critical | 9.8 | 2026-09-05 05:30:54 | Deep Dive |
| CVE-2026-52777 | YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize | YesWiki | yeswiki | Critical | 9.4 | 2026-09-04 23:51:47 | Deep Dive |
| CVE-2026-52766 | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action | YesWiki | yeswiki | Critical | 9.1 | 2026-09-04 23:40:12 | Deep Dive |
| CVE-2026-75925 | IXON VPN Client CRLF Injection | IXON | IXON VPN Client | Critical | 9.6 | 2026-09-04 21:19:02 | Deep Dive |
| CVE-2026-18658 | IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed | IBM | Operational Decision Manager | Critical | 9.8 | 2026-09-04 16:10:19 | Deep Dive |
| CVE-2026-19274 | IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image | IBM | Observability with Instana (Agent) | Critical | 9.6 | 2026-09-04 15:49:34 | Deep Dive |
| CVE-2026-44402 🧪 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | Voltronic Power | SNMP Web Pro | Critical | 9.8 | 2026-09-04 15:31:12 | Deep Dive |
| CVE-2026-85696 | SadTalker OS Command Injection via Audio Filename | OpenTalker | SadTalker | Critical | 9.8 | 2026-09-04 14:32:39 | Deep Dive |
| CVE-2026-85695 | FastChat Unauthenticated Worker Registration SSRF and Model Spoofing | lm-sys | FastChat | Critical | 9.4 | 2026-09-04 14:32:38 | Deep Dive |
| CVE-2026-85688 📌 💣 | TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer | TEN-framework | ten-framework | Critical | 9.8 | 2026-09-04 14:32:33 | Deep Dive |
| CVE-2026-85684 | marker through 2.0.0 Path Traversal via upload filename | datalab-to | marker | Critical | 9.1 | 2026-09-04 14:32:30 | Deep Dive |
| CVE-2026-85672 | zerox 1.1.20 OS Command Injection via Document URL File Extension | getomni-ai | zerox | Critical | 9.8 | 2026-09-04 14:32:27 | Deep Dive |
| CVE-2026-85667 | xiaobei through 5.5.2 Unauthenticated Webhook Message Injection | TeamWiseFlow | xiaobei | Critical | 9.1 | 2026-09-04 14:32:23 | Deep Dive |
| CVE-2026-85663 | Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch | aimhubio | aim | Critical | 9.8 | 2026-09-04 14:32:20 | Deep Dive |
| CVE-2026-85661 | excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode | haris-musa | excel-mcp-server | Critical | 9.8 | 2026-09-04 14:32:19 | Deep Dive |