| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-48755 🧪 | Incus has an argument injection in backup compression algorithm leading to AFW and ACE | lxc | incus | Critical | 9.9 | 2026-08-21 14:37:25 | Deep Dive |
| CVE-2026-48753 🧪 | Incus has an arbitrary file write via path traversal in S3 multipart upload | lxc | incus | Critical | 9.9 | 2026-08-21 14:34:40 | Deep Dive |
| CVE-2026-48752 🧪 | Incus has arbitrary file read+write on host via templates/ symlink in malicious image | lxc | incus | Critical | 9.9 | 2026-08-21 14:31:58 | Deep Dive |
| CVE-2026-48751 🧪 | Incus has a restricted project bypass leading to arbitrary command execution | lxc | incus | Critical | 9.9 | 2026-08-21 14:21:03 | Deep Dive |
| CVE-2026-48750 🧪 | Incus has an arbitrary file write on host via `exec-output` symlink in crafted image | lxc | incus | Critical | 9.9 | 2026-08-21 14:19:45 | Deep Dive |
| CVE-2026-48749 🧪 | Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image | lxc | incus | Critical | 9.9 | 2026-08-21 14:17:54 | Deep Dive |
| CVE-2026-77812 | Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE | DJI | Neo | Critical | 9.4 | 2026-08-21 14:06:56 | Deep Dive |
| CVE-2026-77806 📌 💣 | SPIP 代码注入漏洞 | SPIP | SPIP | Critical | 9.8 | 2026-08-21 13:37:43 | Deep Dive |
| CVE-2026-77776 🧪 | Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity | Headroom Labs | Headroom | Critical | 9.1 | 2026-08-21 11:22:52 | Deep Dive |
| CVE-2026-77086 | SiYuan before v3.7.4 Path Traversal via packageName | siyuan-note | siyuan | Critical | 9.1 | 2026-08-21 11:05:13 | Deep Dive |
| CVE-2026-77683 🧪 | Comfast CF-N1-S mbox-config system command injection | Comfast | CF-N1-S | Critical | 9.9 | 2026-08-21 10:15:08 | Deep Dive |
| CVE-2026-77264 | Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure | 101gen | Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code | Critical | 9.8 | 2026-08-21 07:39:25 | Deep Dive |
| CVE-2026-76158 | Datiphy Data Management Center - External Control of File Name or Path | Datiphy Inc. | Data Management Center | Critical | 9.3 | 2026-08-21 02:02:23 | Deep Dive |
| CVE-2026-76156 | Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command | Datiphy Inc. | Data Management Center | Critical | 9.4 | 2026-08-21 01:44:14 | Deep Dive |
| CVE-2026-76155 | Datiphy Data Management Center - Use of Default Credentials | Datiphy Inc. | Data Management Center | Critical | 9.3 | 2026-08-21 01:40:37 | Deep Dive |
| CVE-2026-77651 🧪 | droundy arrayref 处理逻辑错误漏洞 | droundy | arrayref | Critical | 9.8 | 2026-08-21 00:41:36 | Deep Dive |
| CVE-2026-77650 🧪 | droundy append-only-vec 处理逻辑错误漏洞 | droundy | append-only-vec | Critical | 9.8 | 2026-08-21 00:40:26 | Deep Dive |
| CVE-2026-77649 🧪 | droundy internment 处理逻辑错误漏洞 | droundy | internment | Critical | 9.8 | 2026-08-21 00:39:02 | Deep Dive |
| CVE-2026-77647 💣 | SPIP 代码注入漏洞 | SPIP | SPIP | Critical | 9.8 | 2026-08-20 22:24:40 | Deep Dive |
| CVE-2026-77645 | Critical Remote Code Execution (RCE) vulnerability reported in Windchill | PTC | Windchill PDMLink | Critical | 9.2 | 2026-08-20 22:08:42 | Deep Dive |