| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-60721 | Oracle Identity Manager 安全漏洞 | Oracle Corporation | Oracle Identity Manager | Critical | 9.8 | 2026-08-18 20:59:01 | Deep Dive |
| CVE-2026-60720 | Oracle Identity Manager 安全漏洞 | Oracle Corporation | Oracle Identity Manager | Critical | 9.9 | 2026-08-18 20:59:01 | Deep Dive |
| CVE-2026-60702 | Oracle WebLogic Server 安全漏洞 | Oracle Corporation | Oracle WebLogic Server | Critical | 9.9 | 2026-08-18 20:59:00 | Deep Dive |
| CVE-2026-60696 | Oracle WebLogic Server 安全漏洞 | Oracle Corporation | Oracle WebLogic Server | Critical | 9.8 | 2026-08-18 20:58:59 | Deep Dive |
| CVE-2026-60698 | Oracle WebLogic Server 安全漏洞 | Oracle Corporation | Oracle WebLogic Server | Critical | 9.8 | 2026-08-18 20:58:59 | Deep Dive |
| CVE-2026-60672 | Oracle WebLogic Server 安全漏洞 | Oracle Corporation | Oracle WebLogic Server | Critical | 9.8 | 2026-08-18 20:58:57 | Deep Dive |
| CVE-2026-60591 | Oracle Hospitality Simphony 安全漏洞 | Oracle Corporation | Oracle Hospitality Simphony | Critical | 9.1 | 2026-08-18 20:58:56 | Deep Dive |
| CVE-2026-62988 🧪 | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints | froxlor | froxlor | Critical | 9.0 | 2026-08-18 20:10:38 | Deep Dive |
| CVE-2026-67443 🧪 | FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution) | frangoteam | FUXA | Critical | 9.2 | 2026-08-18 20:06:16 | Deep Dive |
| CVE-2026-75877 🧪 | TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow | TRENDnet | TV-IP751WIC | Critical | 9.9 | 2026-08-18 19:45:08 | Deep Dive |
| CVE-2026-52735 🧪 | ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser | ZcashFoundation | zebra | Critical | 9.3 | 2026-08-18 19:23:11 | Deep Dive |
| CVE-2026-55166 🧪 | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR | Netflix | lemur | Critical | 9.9 | 2026-08-18 18:51:41 | Deep Dive |
| CVE-2026-47627 🧪 | NVIDIA Triton Inference Server 路径遍历漏洞 | NVIDIA | Triton Inference Server | Critical | 9.8 | 2026-08-18 18:23:58 | Deep Dive |
| CVE-2026-75130 | Context7 2.1.2 Prompt Injection via Custom AI Instructions | Uptash | Context7 | Critical | 9.0 | 2026-08-18 18:02:37 | Deep Dive |
| CVE-2026-75625 🧪 | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass | uber | kraken | Critical | 9.0 | 2026-08-18 17:56:54 | Deep Dive |
| CVE-2026-50161 🧪 | libre: Integer overflow in websock_decode() masked frame length check leads to heap buffer overflow | baresip | re | Critical | 9.3 | 2026-08-18 17:53:02 | Deep Dive |
| CVE-2026-71879 🧪 | Authentication bypass in Integrated Publishing Toolkit | GBIF | Integrated Publishing Toolkit | Critical | 9.1 | 2026-08-18 17:41:48 | Deep Dive |
| CVE-2026-71878 🧪 | Authentication bypass in Integrated Publishing Toolkit | GBIF | Integrated Publishing Toolkit | Critical | 9.2 | 2026-08-18 17:41:34 | Deep Dive |
| CVE-2026-18963 📌 💣 | Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass | Red Hat | Red Hat build of Keycloak 26.4 | Critical | 9.1 | 2026-08-18 17:05:07 | Deep Dive |
| CVE-2026-57580 🧪 | authentik: Account Takeover via SAML NameID Comment Truncation | goauthentik | authentik | Critical | 9.4 | 2026-08-18 17:00:19 | Deep Dive |