| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-80600 | batman-adv: dat: acquire ARP hw source only after skb realloc | Linux | Linux | Critical | 9.8 | 2026-08-28 06:48:27 | Deep Dive |
| CVE-2026-76581 | WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion | wpmudev | WPMU DEV Dashboard | Critical | 9.8 | 2026-08-28 06:39:50 | Deep Dive |
| CVE-2026-78032 | SOY CMS 反序列化注入漏洞 | Tsuyoshi Saito | SOY CMS | Critical | 9.3 | 2026-08-28 06:11:12 | Deep Dive |
| CVE-2026-82090 | getpocket Pocket 跨站脚本漏洞 | getpocket | Critical | 9.2 | 2026-08-28 03:36:24 | Deep Dive | |
| CVE-2026-82082 | Green-Computing|NUMail - OS Command Injection | Green-Computing | NUMail | Critical | 9.8 | 2026-08-28 03:12:10 | Deep Dive |
| CVE-2026-78174 | WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs | WatchGuard | Dimension | Critical | 9.3 | 2026-08-27 23:26:31 | Deep Dive |
| CVE-2026-61800 | Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893) | wazuh | wazuh | Critical | 9.1 | 2026-08-27 23:26:28 | Deep Dive |
| CVE-2026-19315 | Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution | WatchGuard | Fireware OS | Critical | 9.3 | 2026-08-27 23:24:34 | Deep Dive |
| CVE-2026-13086 | Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint | WatchGuard | Fireware OS | Critical | 9.3 | 2026-08-27 23:24:33 | Deep Dive |
| CVE-2026-19313 | Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution | WatchGuard | Fireware OS | Critical | 9.3 | 2026-08-27 23:24:33 | Deep Dive |
| CVE-2026-19318 | Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution | WatchGuard | Fireware OS | Critical | 9.3 | 2026-08-27 23:24:33 | Deep Dive |
| CVE-2026-76943 | Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel | Xiiaozet | Xiiaozet LK100W | Critical | 9.8 | 2026-08-27 21:50:49 | Deep Dive |
| CVE-2026-78239 | Xiiaozet LK100W Missing Authentication for Critical Function | Xiiaozet | Xiiaozet LK100W | Critical | 9.8 | 2026-08-27 21:48:31 | Deep Dive |
| CVE-2026-69658 | Ebyte NA111-M Cleartext Transmission of Sensitive Information | Ebyte | Ebyte NA111-M Firmware | Critical | 9.8 | 2026-08-27 21:37:27 | Deep Dive |
| CVE-2026-76179 | Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings | Ebyte | Ebyte NA111-M Firmware | Critical | 9.8 | 2026-08-27 21:22:54 | Deep Dive |
| CVE-2026-71187 | Ebyte NA111-M Use of Client-Side Authentication | Ebyte | Ebyte NA111-M Firmware | Critical | 9.8 | 2026-08-27 21:20:04 | Deep Dive |
| CVE-2026-73125 | Ebyte NA111-M Missing Authentication for Critical Function | Ebyte | Ebyte NA111-M Firmware | Critical | 9.8 | 2026-08-27 21:13:11 | Deep Dive |
| CVE-2026-50152 | Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users | ceph | ceph | Critical | 9.1 | 2026-08-27 20:53:42 | Deep Dive |
| CVE-2026-68929 | FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization | labring | FastGPT | Critical | 9.3 | 2026-08-27 20:21:31 | Deep Dive |
| CVE-2026-53579 | Trilium: Note Import to RCE via Book Note | TriliumNext | Trilium | Critical | 9.3 | 2026-08-27 19:33:24 | Deep Dive |