| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-45018 | Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | Chainlit | chainlit | Critical | 9.8 | 2026-08-25 19:18:46 | Deep Dive |
| CVE-2026-79787 🧪 | Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature | Alluxio | alluxio | Critical | 9.8 | 2026-08-25 18:23:15 | Deep Dive |
| CVE-2026-76195 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) | Adobe | Adobe Campaign Classic | Critical | 10.0 | 2026-08-25 17:27:12 | Deep Dive |
| CVE-2026-76197 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) | Adobe | Adobe Campaign Classic | Critical | 10.0 | 2026-08-25 17:27:11 | Deep Dive |
| CVE-2026-76193 | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) | Adobe | Adobe Campaign Classic | Critical | 10.0 | 2026-08-25 17:27:10 | Deep Dive |
| CVE-2026-55640 🧪 | Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) | cbcoutinho | nextcloud-mcp-server | Critical | 9.1 | 2026-08-25 16:03:28 | Deep Dive |
| CVE-2026-55546 🧪 | QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input | QWED-AI | qwed-mcp | Critical | 9.8 | 2026-08-25 15:25:35 | Deep Dive |
| CVE-2026-55536 🧪 | Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) | MervinPraison | PraisonAI | Critical | 9.1 | 2026-08-25 15:21:53 | Deep Dive |
| CVE-2026-79675 🧪 | NLTK before 3.10.3 JVM Argument Injection via Per-Call Options | nltk | nltk | Critical | 9.8 | 2026-08-25 15:16:01 | Deep Dive |
| CVE-2026-16286 | File Upload in TRTEK Software's Software Repository Management | TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company | Software Repository Management | Critical | 9.8 | 2026-08-25 14:26:20 | Deep Dive |
| CVE-2026-77998 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 | miniorange.com | SAML SSO Free for Joomla extension for Joomla | Critical | 10.0 | 2026-08-25 12:50:47 | Deep Dive |
| CVE-2026-57910 | WatchGuard Agent improper authentication allows unauthenticated remote code execution | WatchGuard | WatchGuard Agent | Critical | 9.3 | 2026-08-25 11:47:49 | Deep Dive |
| CVE-2026-57909 | WatchGuard Agent path traversal allows unauthenticated remote code execution | WatchGuard | WatchGuard Agent | Critical | 9.4 | 2026-08-25 11:47:03 | Deep Dive |
| CVE-2026-79657 🧪 | NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization | nltk | nltk | Critical | 9.8 | 2026-08-25 11:33:23 | Deep Dive |
| CVE-2026-77136 | Server-Side Template Injection in extension "powermail" (powermail) | TYPO3 | Extension "powermail" | Critical | 9.5 | 2026-08-25 09:00:40 | Deep Dive |
| CVE-2026-77138 | Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail) | TYPO3 | Extension "HTML5 Video Player vs. Powermail" | Critical | 9.3 | 2026-08-25 09:00:38 | Deep Dive |
| CVE-2026-63586 | Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface | Weidmueller Interface | IE-SR-2TX-WL | Critical | 9.8 | 2026-08-25 08:54:56 | Deep Dive |
| CVE-2026-59769 | FURUNO ELECTRIC FA-50 信任管理问题漏洞 | FURUNO ELECTRIC CO., LTD. | FA-50 | Critical | 9.1 | 2026-08-25 07:43:10 | Deep Dive |
| CVE-2026-13214 | Stack buffer overflow in OCPP GetConfiguration key parsing | zephyrproject | zephyr | Critical | 9.8 | 2026-08-25 04:37:21 | Deep Dive |
| CVE-2026-78683 🧪 | NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization | nltk | nltk | Critical | 9.6 | 2026-08-25 01:30:39 | Deep Dive |