| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-12710 | Missing Authorization in Application Integration QueryEngineTask | Google Cloud | Application Integration | Critical | 9.3 | 2026-08-22 08:13:00 | Deep Dive |
| CVE-2026-49849 🧪 | xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution | 4xmen | xshop | Critical | 9.1 | 2026-08-21 21:14:24 | Deep Dive |
| CVE-2026-77415 🧪 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | jsonata-js | jsonata | Critical | 9.3 | 2026-08-21 21:01:09 | Deep Dive |
| CVE-2026-77414 🧪 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | jsonata-js | jsonata | Critical | 9.3 | 2026-08-21 20:51:44 | Deep Dive |
| CVE-2026-77413 🧪 | JSONata: Arbitrary Code Execution via crafted JSONata expressions | jsonata-js | jsonata | Critical | 9.3 | 2026-08-21 20:47:08 | Deep Dive |
| CVE-2026-61539 🧪 | Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing | xorbitsai | inference | Critical | 10.0 | 2026-08-21 20:37:03 | Deep Dive |
| CVE-2026-59989 🧪 | Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) | phalcon | cphalcon | Critical | 9.2 | 2026-08-21 20:25:45 | Deep Dive |
| CVE-2026-62283 🧪 | Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check | nezhahq | nezha | Critical | 9.9 | 2026-08-21 20:21:29 | Deep Dive |
| CVE-2026-76904 📌 💣 | GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers | geotools | geotools | Critical | 9.8 | 2026-08-21 20:13:21 | Deep Dive |
| CVE-2026-77810 🧪 | Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector | AWS | Athena Federated Query Neptune Connector | Critical | 9.9 | 2026-08-21 19:34:06 | Deep Dive |
| CVE-2026-62674 🧪 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent-ai | omnigent | Critical | 9.0 | 2026-08-21 17:47:38 | Deep Dive |
| CVE-2026-74581 | net: ipv6: clear suppressed fib6 rule result | Linux | Linux | Critical | 9.8 | 2026-08-21 16:31:55 | Deep Dive |
| CVE-2026-69502 | Azure SQL Database Elevation of Privilege Vulnerability | Microsoft | Azure SQL Database | Critical | 10.0 | 2026-08-21 16:03:57 | Deep Dive |
| CVE-2026-77087 🧪 | Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding | paperclipai | paperclip | Critical | 9.6 | 2026-08-21 15:03:08 | Deep Dive |
| CVE-2026-63343 🧪 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | lxc | incus | Critical | 9.9 | 2026-08-21 14:53:26 | Deep Dive |
| CVE-2026-63125 🧪 | Incus vulnerable to root RCE via image backup.yaml symlink | lxc | incus | Critical | 9.9 | 2026-08-21 14:49:17 | Deep Dive |
| CVE-2026-62941 🧪 | Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge | lxc | incus | Critical | 9.9 | 2026-08-21 14:47:57 | Deep Dive |
| CVE-2026-62940 🧪 | Incus has a project restriction bypass via instance migration config override | lxc | incus | Critical | 9.9 | 2026-08-21 14:47:13 | Deep Dive |
| CVE-2026-62867 🧪 | Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution | lxc | incus | Critical | 9.9 | 2026-08-21 14:45:36 | Deep Dive |
| CVE-2026-48769 🧪 | Incus has an arbitrary file write on its client due to trusted image hash | lxc | incus | Critical | 9.9 | 2026-08-21 14:38:39 | Deep Dive |