| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-82856 | @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass | hulumi | policies | Critical | 9.8 | 2026-08-31 08:46:30 | Deep Dive |
| CVE-2026-82855 | @hulumi/policies before 1.3.2 Evidence Validation Bypass | hulumi | policies | Critical | 9.8 | 2026-08-31 08:46:29 | Deep Dive |
| CVE-2026-82854 | Nodemailer before 8.0.3 SMTP Command Injection via envelope.size | nodemailer | nodemailer | Critical | 9.8 | 2026-08-31 08:46:28 | Deep Dive |
| CVE-2026-19410 | Google Cloud Build Comment Control Bypass via Webhook Suppression | Google Cloud | Google Cloud Build | Critical | 9.4 | 2026-08-31 08:14:52 | Deep Dive |
| CVE-2026-58574 | Dell powerstore 500t 授权问题漏洞 | Dell | PowerStore 500T | Critical | 9.8 | 2026-08-31 06:28:46 | Deep Dive |
| CVE-2026-82616 | TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow | TOTOLINK | NR1800X | Critical | 9.9 | 2026-08-31 04:45:12 | Deep Dive |
| CVE-2026-82593 | D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow | D-Link | DIR-825M | Critical | 9.9 | 2026-08-30 23:15:11 | Deep Dive |
| CVE-2026-82592 | D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow | D-Link | DIR-825M | Critical | 9.9 | 2026-08-30 23:00:14 | Deep Dive |
| CVE-2026-82542 | Tenda HG10 Boa Web Server formIPv6Routing buffer overflow | Tenda | HG10 | Critical | 10.0 | 2026-08-30 12:30:10 | Deep Dive |
| CVE-2026-82539 | TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption | TOTOLINK | A720R | Critical | 9.1 | 2026-08-30 10:15:10 | Deep Dive |
| CVE-2026-15980 | MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token | TangibleWP | MyHome Core | Critical | 9.8 | 2026-08-30 04:25:48 | Deep Dive |
| CVE-2026-15369 | Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout | Addify | Custom User Registration Fields for WooCommerce | Critical | 9.8 | 2026-08-29 19:26:34 | Deep Dive |
| CVE-2026-82460 | Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown | coderaiser | cloudcmd | Critical | 9.8 | 2026-08-29 16:35:25 | Deep Dive |
| CVE-2026-82456 📌 💣 | argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP | argoproj-labs | argocd-mcp | Critical | 10.0 | 2026-08-29 13:47:57 | Deep Dive |
| CVE-2026-82454 | Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in | omnivore-app | omnivore | Critical | 9.1 | 2026-08-29 13:47:56 | Deep Dive |
| CVE-2026-82452 | rust-iot-platform Authentication Bypass via Missing Request Guards | iot-ecology | rust-iot-platform | Critical | 9.8 | 2026-08-29 13:47:55 | Deep Dive |
| CVE-2026-82448 | Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key | Shinobi Systems | Shinobi | Critical | 9.8 | 2026-08-29 12:05:35 | Deep Dive |
| CVE-2026-14494 | Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field | bdthemes | SigmaForms Pro – AI Generated Forms | Critical | 9.8 | 2026-08-29 11:30:17 | Deep Dive |
| CVE-2026-80725 | net: gro: properly validate BIG TCP aggregation criteria | Linux | Linux | Critical | 9.8 | 2026-08-29 06:39:35 | Deep Dive |
| CVE-2026-3627 | Multiple Vulnerabilities in IBM Concert Software | IBM | Concert | Critical | 9.1 | 2026-08-28 20:53:38 | Deep Dive |