| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73187 | WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability | gingerplugins | Sticky Chat Widget | Critical | 9.3 | 2026-08-18 14:00:02 | Deep Dive |
| CVE-2026-66627 | WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability | EDGE22 Studios Ltd. | GP Premium | Critical | 9.9 | 2026-08-18 13:59:38 | Deep Dive |
| CVE-2026-32474 | WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability | wpWax | Templatiq | Critical | 9.9 | 2026-08-18 13:59:27 | Deep Dive |
| CVE-2026-32470 | WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability | Roxnor | FundEngine | Critical | 9.8 | 2026-08-18 13:59:24 | Deep Dive |
| CVE-2026-32463 | WordPress Sync Post With Other Site plugin <= 1.9.3 - Arbitrary File Upload vulnerability | Kamlesh Parmar | Sync Post With Other Site | Critical | 9.9 | 2026-08-18 13:59:13 | Deep Dive |
| CVE-2026-32444 | WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability | Cwicly | Cwicly | Critical | 9.9 | 2026-08-18 13:59:11 | Deep Dive |
| CVE-2026-28192 | WordPress Piotnet Addons For Elementor Pro plugin <= 7.1.67 - Arbitrary File Upload vulnerability | Piotnet | Piotnet Addons For Elementor Pro | Critical | 9.6 | 2026-08-18 13:59:02 | Deep Dive |
| CVE-2026-75783 🧪 | TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow | TRENDnet | TEW-WLC100P | Critical | 9.6 | 2026-08-18 12:45:11 | Deep Dive |
| CVE-2026-75854 🧪 | ArcadeDB Redis Wire-Protocol Plugin Missing Authentication | ArcadeData | arcadedb | Critical | 9.8 | 2026-08-18 11:19:57 | Deep Dive |
| CVE-2026-75852 🧪 | ArcadeDB MongoDB wire protocol authentication bypass cross-database | ArcadeData | arcadedb | Critical | 9.8 | 2026-08-18 11:19:56 | Deep Dive |
| CVE-2026-75851 🧪 | ArcadeDB before 26.8.1 Authentication Bypass via Async Command | ArcadeData | arcadedb | Critical | 9.9 | 2026-08-18 11:19:55 | Deep Dive |
| CVE-2026-75843 🧪 | ArcadeDB before 26.8.1 Privilege Escalation via gRPC Transaction | ArcadeData | arcadedb | Critical | 9.9 | 2026-08-18 11:19:51 | Deep Dive |
| CVE-2026-75837 🧪 | Grav before 2.0.14 Privilege Escalation via Group Access Field | getgrav | grav | Critical | 9.1 | 2026-08-18 11:19:47 | Deep Dive |
| CVE-2026-75627 🧪 | Bastillion Authentication Bypass via Path-Prefix Routing Mismatch | bastillion-io | Bastillion | Critical | 9.8 | 2026-08-18 10:46:55 | Deep Dive |
| CVE-2026-75626 🧪 | SpiderFoot Stored Cross-Site Scripting via Correlation Titles | smicallef | spiderfoot | Critical | 9.3 | 2026-08-18 10:46:54 | Deep Dive |
| CVE-2026-15748 | Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Critical | 9.8 | 2026-08-18 05:31:20 | Deep Dive |
| CVE-2026-75094 🧪 | COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection | COMFAST | CF-N1-S | Critical | 9.1 | 2026-08-18 01:45:10 | Deep Dive |
| CVE-2026-71424 🧪 | Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers | onyx-dot-app | onyx | Critical | 9.6 | 2026-08-17 21:28:33 | Deep Dive |
| CVE-2026-64849 KEV 📌 💣 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | mlflow | mlflow | Critical | 9.3 | 2026-08-17 21:16:11 | Deep Dive |
| CVE-2026-47686 🧪 | vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE | patriksimek | vm2 | Critical | 9.9 | 2026-08-17 20:54:39 | Deep Dive |