| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-62682 🧪 | Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:40:17 | Deep Dive |
| CVE-2025-14600 🧪 | Admin Account Takeover via Path Traversal in vsDesk | vsDesk | vsDesk | Critical | 9.3 | 2026-08-19 17:39:43 | Deep Dive |
| CVE-2026-72717 🧪 | Orval: Import-time RCE via schema default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:39:23 | Deep Dive |
| CVE-2026-71867 🧪 | Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:38:36 | Deep Dive |
| CVE-2026-71868 🧪 | Orval: Import-time RCE via enum-typed default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:37:34 | Deep Dive |
| CVE-2026-71865 🧪 | Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:36:48 | Deep Dive |
| CVE-2026-71869 🧪 | Orval: Import-time RCE via array-items default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:36:07 | Deep Dive |
| CVE-2026-71864 🧪 | Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:34:55 | Deep Dive |
| CVE-2026-71871 🧪 | Orval: Import-time RCE via header-parameter default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:33:56 | Deep Dive |
| CVE-2026-72716 🧪 | Orval: Import-time RCE via query-parameter default -> zod module-level template literal | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:33:02 | Deep Dive |
| CVE-2026-62681 🧪 | Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:31:03 | Deep Dive |
| CVE-2026-66794 | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route | Red Hat | multicluster engine for Kubernetes 2.1 | Critical | 9.3 | 2026-08-19 17:30:08 | Deep Dive |
| CVE-2026-71866 🧪 | Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client | orval-labs | orval | Critical | 9.3 | 2026-08-19 17:27:28 | Deep Dive |
| CVE-2026-32475 📌 💣 | WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability | Elementor | Elementor Pro | Critical | 9.0 | 2026-08-19 17:24:56 | Deep Dive |
| CVE-2026-71470 | Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | Critical | 9.1 | 2026-08-19 17:11:03 | Deep Dive |
| CVE-2026-72530 KEV | TrueConf server 代码注入漏洞 | TrueConf | TrueConf Server | Critical | 9.0 | 2026-08-19 16:56:53 | Deep Dive |
| CVE-2026-72529 KEV | TrueConf server 授权问题漏洞 | TrueConf | TrueConf Server | Critical | 9.8 | 2026-08-19 16:55:15 | Deep Dive |
| CVE-2026-75143 | FFmpeg Heap Buffer Overflow via RIST Protocol Reader | FFmpeg | FFmpeg | Critical | 9.8 | 2026-08-19 16:26:12 | Deep Dive |
| CVE-2026-49441 🧪 | Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager | wazuh | wazuh | Critical | 9.1 | 2026-08-19 16:19:37 | Deep Dive |
| CVE-2026-20315 | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities | Cisco | Cisco Secure Workload | Critical | 10.0 | 2026-08-19 16:19:37 | Deep Dive |