| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-78676 🧪 | GitPython before 3.1.59 Remote Code Execution via Config Injection | gitpython-developers | GitPython | Critical | 9.8 | 2026-08-25 01:30:34 | Deep Dive |
| CVE-2026-56710 | Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock | getgrav | grav | Critical | 9.8 | 2026-08-25 01:30:11 | Deep Dive |
| CVE-2026-56705 🧪 | Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection | vrana | adminer | Critical | 9.8 | 2026-08-25 01:30:04 | Deep Dive |
| CVE-2026-78267 🧪 | WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability | Cozmoslabs | TranslatePress | Critical | 9.8 | 2026-08-24 21:31:34 | Deep Dive |
| CVE-2026-78265 | WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnerability | Nexcess | The Events Calendar | Critical | 9.8 | 2026-08-24 21:31:33 | Deep Dive |
| CVE-2026-78262 | WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability | weDevs | WP Project Manager | Critical | 9.8 | 2026-08-24 21:31:31 | Deep Dive |
| CVE-2026-32563 | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection vulnerability | A CPT | ACPT (Pro) - Custom Post Types Plugin for WordPress | Critical | 9.8 | 2026-08-24 21:31:29 | Deep Dive |
| CVE-2026-32559 | WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability | tophive | UltimateAI | Critical | 9.9 | 2026-08-24 21:31:27 | Deep Dive |
| CVE-2026-32555 | WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability | PixelYourSite Professional | Boost | Critical | 9.3 | 2026-08-24 21:31:26 | Deep Dive |
| CVE-2026-32554 | WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnerability | WBW | WooBeWoo Product Filter Pro | Critical | 9.3 | 2026-08-24 21:31:25 | Deep Dive |
| CVE-2026-77337 🧪 | CakePHP: Potential Authentication bypass with CookieAuthenticator | cakephp | authentication | Critical | 9.1 | 2026-08-24 21:30:07 | Deep Dive |
| CVE-2026-77635 🧪 | CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver | cakephp | cakephp | Critical | 9.2 | 2026-08-24 20:30:34 | Deep Dive |
| CVE-2026-78555 🧪 | RansomLook API Key Disclosure Through /admin/apikeys HTML Source | ransomlook | ransomlook | Critical | 9.4 | 2026-08-24 19:38:50 | Deep Dive |
| CVE-2026-39975 | Combodo iTop: Remote code execution using external auth variable value | Combodo | iTop | Critical | 9.4 | 2026-08-24 18:50:49 | Deep Dive |
| CVE-2026-76835 🧪 | OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the Default Trusted Proxy Set | oauth2-proxy | oauth2-proxy | Critical | 9.1 | 2026-08-24 17:55:40 | Deep Dive |
| CVE-2026-71933 | DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions | DrayTek Corporation | VigorSwitch G2540xs | Critical | 9.1 | 2026-08-24 17:07:59 | Deep Dive |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | DrayTek Corporation | VigorSwitch G2540xs | Critical | 9.8 | 2026-08-24 17:07:51 | Deep Dive |
| CVE-2026-71914 | DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm | DrayTek Corporation | VigorAP 918R | Critical | 9.8 | 2026-08-24 17:07:46 | Deep Dive |
| CVE-2025-36939 | Google Nest 缓冲区错误漏洞 | Nest | Critical | 10.0 | 2026-08-24 16:38:46 | Deep Dive | |
| CVE-2026-77915 🧪 | rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php | rconfig | rconfig | Critical | 9.8 | 2026-08-24 16:11:45 | Deep Dive |