| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-76071 🧪 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | Netis Systems | NC63 | Critical | 9.8 | 2026-08-24 15:42:33 | Deep Dive |
| CVE-2026-76070 🧪 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter | Netis Systems | NC63 | Critical | 9.8 | 2026-08-24 15:41:17 | Deep Dive |
| CVE-2026-78387 🧪 | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification | ransomlook | ransomlook | Critical | 9.4 | 2026-08-24 14:04:17 | Deep Dive |
| CVE-2026-67602 🧪 | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache | phpipam | phpipam | Critical | 9.1 | 2026-08-24 13:57:42 | Deep Dive |
| CVE-2026-59568 | Remote Code Execution | Zscaler | Client Connector | Critical | 9.1 | 2026-08-24 13:44:22 | Deep Dive |
| CVE-2026-59564 | Authentication bypass between ZCC and client connector portal | Zscaler | Client Connector | Critical | 9.1 | 2026-08-24 13:39:16 | Deep Dive |
| CVE-2026-76840 🧪 | RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileContentsResponse Length | rustdesk | rustdesk | Critical | 9.6 | 2026-08-24 13:11:58 | Deep Dive |
| CVE-2026-78372 🧪 | RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data | ransomlook | ransomlook | Critical | 9.2 | 2026-08-24 13:09:23 | Deep Dive |
| CVE-2026-77995 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 | miniorange.com | miniOrange OAuth Client (free) extension for Joomla | Critical | 10.0 | 2026-08-24 13:05:27 | Deep Dive |
| CVE-2026-78370 🧪 | RansomLook Unauthenticated Database Export Exposes Private Data | ransomlook | ransomlook | Critical | 9.2 | 2026-08-24 13:03:24 | Deep Dive |
| CVE-2026-78365 🧪 | IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification | Roskus | Prospero Flow CRM | Critical | 9.3 | 2026-08-24 12:49:37 | Deep Dive |
| CVE-2026-66650 | WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability | Theme-Rex | FreightCo | Critical | 9.8 | 2026-08-24 11:54:58 | Deep Dive |
| CVE-2026-66648 | WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability | MVPThemes | Jawn | Critical | 9.8 | 2026-08-24 11:54:57 | Deep Dive |
| CVE-2026-66587 | WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability | WPCafe | WP Cafe Pro | Critical | 9.8 | 2026-08-24 11:54:56 | Deep Dive |
| CVE-2026-32558 | WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation vulnerability | RedefiningTheWeb | Affiliate Pro - Affiliate Program for WooCommerce & WordPress | Critical | 9.8 | 2026-08-24 11:54:54 | Deep Dive |
| CVE-2026-32551 | WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability | DiviNext | Woo Essential | Critical | 9.3 | 2026-08-24 11:54:54 | Deep Dive |
| CVE-2026-28165 | WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability | UnitedOver, LLC | Digits | Critical | 9.8 | 2026-08-24 11:54:47 | Deep Dive |
| CVE-2026-66897 🧪 | Instance template path traversal allows arbitrary host file write as root | Canonical | LXD | Critical | 9.9 | 2026-08-24 09:08:04 | Deep Dive |
| CVE-2026-77994 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 | joomlack.fr | Page Builder CK extension for Joomla | Critical | 9.3 | 2026-08-24 07:55:07 | Deep Dive |
| CVE-2026-78251 | DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory | DJI | Neo | Critical | 9.3 | 2026-08-24 07:04:32 | Deep Dive |