| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-82222 🧪 💣 | WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability | Liquid Web / StellarWP | GiveWP | Critical | 10.0 | 2026-08-28 10:46:14 | Deep Dive |
| CVE-2026-42007 | Open-Xchange Dovecot Pro 资源管理错误漏洞 | Open-Xchange GmbH | OX Dovecot Pro | Critical | 9.1 | 2026-08-28 10:12:25 | Deep Dive |
| CVE-2026-18918 | OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default | Eclipse Foundation | Eclipse Lyo | Critical | 9.1 | 2026-08-28 08:54:08 | Deep Dive |
| CVE-2026-40541 | Synology Chat Server 跨站脚本漏洞 | Synology | Synology Chat Server | Critical | 9.0 | 2026-08-28 07:07:24 | Deep Dive |
| CVE-2026-80714 | ipvs: do not propagate one-packet flag to synced conns | Linux | Linux | Critical | 9.8 | 2026-08-28 06:53:13 | Deep Dive |
| CVE-2026-80694 | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller | Linux | Linux | Critical | 9.8 | 2026-08-28 06:53:00 | Deep Dive |
| CVE-2026-80693 | idpf: bound interrupt-vector register fill to the allocated array | Linux | Linux | Critical | 9.3 | 2026-08-28 06:52:56 | Deep Dive |
| CVE-2026-80684 | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure | Linux | Linux | Critical | 9.3 | 2026-08-28 06:52:51 | Deep Dive |
| CVE-2026-80681 | vxlan: re-fetch eth header after route_shortcircuit() | Linux | Linux | Critical | 9.8 | 2026-08-28 06:52:49 | Deep Dive |
| CVE-2026-80674 | ntfs: validate resident attribute lists and harden the validator | Linux | Linux | Critical | 9.8 | 2026-08-28 06:49:14 | Deep Dive |
| CVE-2026-80673 | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() | Linux | Linux | Critical | 9.8 | 2026-08-28 06:49:13 | Deep Dive |
| CVE-2026-80671 | perf sched: Fix register_pid() overflow, strcpy, and BUG_ON | Linux | Linux | Critical | 9.3 | 2026-08-28 06:49:12 | Deep Dive |
| CVE-2026-80670 | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() | Linux | Linux | Critical | 9.1 | 2026-08-28 06:49:11 | Deep Dive |
| CVE-2026-80668 | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations | Linux | Linux | Critical | 9.8 | 2026-08-28 06:49:10 | Deep Dive |
| CVE-2026-80634 | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag | Linux | Linux | Critical | 9.8 | 2026-08-28 06:48:49 | Deep Dive |
| CVE-2026-80630 | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen | Linux | Linux | Critical | 9.8 | 2026-08-28 06:48:47 | Deep Dive |
| CVE-2026-80617 | net: airoha: fix foe_check_time allocation size | Linux | Linux | Critical | 9.8 | 2026-08-28 06:48:38 | Deep Dive |
| CVE-2026-80612 | net: lwtunnel: Drop skb metadata before LWT encapsulation | Linux | Linux | Critical | 9.8 | 2026-08-28 06:48:35 | Deep Dive |
| CVE-2026-80609 | qede: fix out-of-bounds check for cqe->len_list[] | Linux | Linux | Critical | 9.8 | 2026-08-28 06:48:33 | Deep Dive |
| CVE-2026-80603 | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read | Linux | Linux | Critical | 9.1 | 2026-08-28 06:48:29 | Deep Dive |