| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71960 | Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT | Shenzhen Cudy Technology Co., Ltd. | WR3000 2.0 | Critical | 9.1 | 2026-08-19 14:27:58 | Deep Dive |
| CVE-2026-76244 🧪 | stigmem-node Insecure Federation Transport Configuration | eidetic-labs | stigmem | Critical | 9.1 | 2026-08-19 14:02:21 | Deep Dive |
| CVE-2026-76243 🧪 | stigmem before 0.9.0a2 Authentication Bypass via Disabled Auth | eidetic-labs | stigmem | Critical | 9.2 | 2026-08-19 14:02:20 | Deep Dive |
| CVE-2026-76242 🧪 | stigmem Federation Peer Registration Authentication Bypass | eidetic-labs | stigmem | Critical | 9.1 | 2026-08-19 14:02:19 | Deep Dive |
| CVE-2026-16019 | SQL Injection in Faydam Innovation's FAYDAM Datalogger | Faydam Innovation Inc. | FAYDAM Datalogger | Critical | 9.8 | 2026-08-19 13:56:55 | Deep Dive |
| CVE-2026-74803 🧪 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 | yootheme.com | Zoo extension for Joomla | Critical | 10.0 | 2026-08-19 13:39:24 | Deep Dive |
| CVE-2026-74804 | Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 | yootheme.com | Zoo extension for Joomla | Critical | 9.3 | 2026-08-19 13:35:50 | Deep Dive |
| CVE-2026-67364 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 | balbooa.com | Balbooa Forms extension for Joomla | Critical | 10.0 | 2026-08-19 13:00:55 | Deep Dive |
| CVE-2026-19490 KEV | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 | NetScaler | ADC | Critical | 9.3 | 2026-08-19 12:54:40 | Deep Dive |
| CVE-2026-73390 | WordPress Total Donations plugin <= 2.0.5 - Privilege Escalation vulnerability | KlbTheme | Total Donations | Critical | 9.8 | 2026-08-19 12:38:57 | Deep Dive |
| CVE-2026-73391 | WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability | KlbTheme | Total Donations | Critical | 9.3 | 2026-08-19 12:38:57 | Deep Dive |
| CVE-2026-73389 | WordPress Kalles Addons plugin <= 1.0.6 - PHP Object Injection vulnerability | The4 | Kalles Addons | Critical | 9.8 | 2026-08-19 12:38:56 | Deep Dive |
| CVE-2026-73388 | WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability | TeconceTheme | Nikstore Core | Critical | 9.3 | 2026-08-19 12:38:55 | Deep Dive |
| CVE-2026-73364 | WordPress Flexible Subscriptions plugin <= 1.8.1 - PHP Object Injection vulnerability | wpdesk | Flexible Subscriptions | Critical | 9.8 | 2026-08-19 12:38:52 | Deep Dive |
| CVE-2026-73347 | WordPress TrueBooker plugin <= 1.2.6 - Privilege Escalation vulnerability | ThemetechMount | TrueBooker | Critical | 9.8 | 2026-08-19 12:38:50 | Deep Dive |
| CVE-2026-73185 | WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability | wpo-HR | NGG Smart Image Search | Critical | 9.3 | 2026-08-19 12:38:49 | Deep Dive |
| CVE-2026-73183 | WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability | Get Maps Marker Pro | Maps Marker Pro | Critical | 9.3 | 2026-08-19 12:38:48 | Deep Dive |
| CVE-2026-66613 🧪 | WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability | Crocoblock. Jetimpex Inc. | JetEngine | Critical | 9.8 | 2026-08-19 12:38:45 | Deep Dive |
| CVE-2026-76008 🧪 | Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow | Comfast | CF-N1-S | Critical | 10.0 | 2026-08-19 02:30:09 | Deep Dive |
| CVE-2026-76004 🧪 | UTT HiPER 1250GW HTTP aspApBasicConfigUrcp strcpy stack-based overflow | UTT | HiPER 1250GW | Critical | 9.9 | 2026-08-19 02:15:10 | Deep Dive |