| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19295 💣 | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement | IBM | Langflow OSS | Critical | 9.9 | 2026-08-28 20:53:00 | Deep Dive |
| CVE-2026-19286 | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement | IBM | Langflow OSS | Critical | 9.8 | 2026-08-28 20:52:24 | Deep Dive |
| CVE-2026-18527 | IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. | IBM | Administration Runtime Expert for i | Critical | 9.9 | 2026-08-28 20:48:34 | Deep Dive |
| CVE-2026-55634 | Pimcore: Remote Code Execution via DataObject Class-Definition Field Name | pimcore | pimcore | Critical | 9.9 | 2026-08-28 19:16:20 | Deep Dive |
| CVE-2026-55220 | Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column | pimcore | pimcore | Critical | 9.3 | 2026-08-28 19:12:44 | Deep Dive |
| CVE-2026-55247 | plone.app.event: Denial of service via iCalendar import | plone | plone.app.event | Critical | 9.1 | 2026-08-28 18:59:01 | Deep Dive |
| CVE-2026-55248 | plone.app.portlets: Denial of service via RSS feed portlet | plone | plone.app.portlets | Critical | 9.1 | 2026-08-28 18:40:51 | Deep Dive |
| CVE-2026-82329 KEV 📌 💣 | Potential authentication bypass leading to administrative access in Artifactory | jfrog | artifactory | Critical | 9.8 | 2026-08-28 18:27:44 | Deep Dive |
| CVE-2026-55378 | JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context values | shriyanss | js-recon | Critical | 9.3 | 2026-08-28 18:15:41 | Deep Dive |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) | yamcs | yamcs | Critical | 9.9 | 2026-08-28 17:29:57 | Deep Dive |
| CVE-2026-55559 | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) | yamcs | yamcs | Critical | 9.8 | 2026-08-28 17:22:08 | Deep Dive |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` | yamcs | yamcs | Critical | 9.1 | 2026-08-28 17:05:02 | Deep Dive |
| CVE-2026-55068 | free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints | free5gc | free5gc | Critical | 9.3 | 2026-08-28 16:57:12 | Deep Dive |
| CVE-2026-54755 | Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) | klever-io | klever-go | Critical | 9.6 | 2026-08-28 16:23:44 | Deep Dive |
| CVE-2026-54754 | Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) | klever-io | klever-go | Critical | 9.6 | 2026-08-28 16:20:07 | Deep Dive |
| CVE-2026-82277 | Argo Rollouts Dashboard Unauthenticated Mutating Operations | argoproj | argo-rollouts | Critical | 9.8 | 2026-08-28 16:18:58 | Deep Dive |
| CVE-2026-82266 | Redpanda Admin API Unauthenticated Superuser Access via Default Configuration | redpanda-data | redpanda | Critical | 9.8 | 2026-08-28 16:18:51 | Deep Dive |
| CVE-2026-54745 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true | kubeflow | pipelines | Critical | 10.0 | 2026-08-28 15:59:01 | Deep Dive |
| CVE-2026-82078 KEV 💣 | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector | PaperCut | PaperCut MF/NG | Critical | 9.4 | 2026-08-28 11:45:25 | Deep Dive |
| CVE-2026-82244 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() | budibase | server | Critical | 9.1 | 2026-08-28 10:49:31 | Deep Dive |