| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-47698 🧪 | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators | patriksimek | vm2 | Critical | 9.8 | 2026-08-17 20:53:09 | Deep Dive |
| CVE-2026-66795 | Managedcluster-import-controller: csr auto-approver does not validate certificate subject or signername (spoke→hub cluster-admin) | Red Hat | multicluster engine for Kubernetes 2.1 | Critical | 9.9 | 2026-08-17 20:45:34 | Deep Dive |
| CVE-2026-65974 🧪 | ERPNext: Server-Side Template Injection leading to Remote Code Execution | frappe | erpnext | Critical | 9.9 | 2026-08-17 20:44:21 | Deep Dive |
| CVE-2026-75110 🧪 | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET | MemTensor | MemOS | Critical | 9.8 | 2026-08-17 20:36:04 | Deep Dive |
| CVE-2026-75106 🧪 | OpnForm Editable Submission Secret Derivation via Empty Hashids Salt | OpnForm | OpnForm | Critical | 9.1 | 2026-08-17 20:36:02 | Deep Dive |
| CVE-2026-19478 📌 💣 | Improper Control of Generation of Code ('Code Injection') in GitLab EPSS 0.60 | GitLab | GitLab | Critical | 9.4 | 2026-08-17 20:04:46 | Deep Dive |
| CVE-2026-71472 | Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_mem | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | Critical | 9.1 | 2026-08-17 19:28:43 | Deep Dive |
| CVE-2026-66792 | Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() trusts user-settable annotations on managed clusters | Red Hat | Multicluster Global Hub 1.4.9 | Critical | 9.9 | 2026-08-17 18:12:36 | Deep Dive |
| CVE-2026-74253 🧪 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 | regularlabs.com | Sourcerer extension for Joomla | Critical | 10.0 | 2026-08-17 17:12:55 | Deep Dive |
| CVE-2026-74254 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 | joomlack.fr | Page Builder CK extension for Joomla | Critical | 9.3 | 2026-08-17 17:10:04 | Deep Dive |
| CVE-2026-71479 🧪 | New API: Integer overflow in quota billing yields negative charges (self-crediting) | QuantumNous | new-api | Critical | 9.1 | 2026-08-17 16:11:28 | Deep Dive |
| CVE-2026-75045 | JetBrains YouTrack 授权问题漏洞 | JetBrains | YouTrack | Critical | 9.1 | 2026-08-17 15:54:35 | Deep Dive |
| CVE-2026-64859 🧪 | New API: User List API Leaks Root User Access Token Leading to Privilege Escalation | QuantumNous | new-api | Critical | 9.1 | 2026-08-17 15:42:19 | Deep Dive |
| CVE-2026-55674 | Discourse: Cache poisoning/XSS via color scheme cookies | discourse | discourse | Critical | 9.3 | 2026-08-17 15:30:18 | Deep Dive |
| CVE-2026-71566 🧪 | KubeVirt backend is not authenticated | openshift-metal3 | fakefish | Critical | 9.3 | 2026-08-17 14:22:17 | Deep Dive |
| CVE-2026-14564 | Sensitive Data Exposure in Innotim Software's Logsign SIEM | Innotim Software Telecommunications and Consulting Trade Ltd. Co. | Logsign SIEM | Critical | 9.0 | 2026-08-17 12:26:35 | Deep Dive |
| CVE-2026-74843 🧪 | Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow | Wavlink | WN531P3 | Critical | 10.0 | 2026-08-17 11:15:08 | Deep Dive |
| CVE-2026-74901 🧪 | openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:05:00 | Deep Dive |
| CVE-2026-74899 🧪 | openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:59 | Deep Dive |
| CVE-2026-74900 🧪 | openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:59 | Deep Dive |