| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-74896 🧪 | openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:58 | Deep Dive |
| CVE-2026-74895 🧪 | openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:57 | Deep Dive |
| CVE-2026-74894 🧪 | openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:57 | Deep Dive |
| CVE-2026-74891 🧪 | openssl_encrypt before 1.4.0 Hardcoded Database Credentials | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:55 | Deep Dive |
| CVE-2026-74889 🧪 | openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:53 | Deep Dive |
| CVE-2026-74886 🧪 | openssl_encrypt before 1.4.0 Plugin Import Guard Bypass | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:51 | Deep Dive |
| CVE-2026-74880 🧪 | openssl_encrypt before 1.4.0 Token Leakage via Query Parameters | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:47 | Deep Dive |
| CVE-2026-74878 🧪 | openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:46 | Deep Dive |
| CVE-2026-74875 🧪 | openssl_encrypt before 1.4.0 Schema Validation Bypass | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:44 | Deep Dive |
| CVE-2026-74876 🧪 | openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:44 | Deep Dive |
| CVE-2026-74872 🧪 | openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool | jahlives | openssl_encrypt | Critical | 9.8 | 2026-08-17 11:04:42 | Deep Dive |
| CVE-2026-74800 | SiYuan before v3.7.4 Stored XSS via assets endpoint | siyuan-note | siyuan | Critical | 9.0 | 2026-08-17 11:04:36 | Deep Dive |
| CVE-2026-74799 | SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure | siyuan-note | siyuan | Critical | 9.3 | 2026-08-17 11:04:35 | Deep Dive |
| CVE-2026-15623 | Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service | Google Cloud | Google SecOps (Chronicle SOAR) | Critical | 9.4 | 2026-08-17 06:27:01 | Deep Dive |
| CVE-2026-19977 🧪 | EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication | EFM | ipTIME A3004T | Critical | 10.0 | 2026-08-17 03:00:10 | Deep Dive |
| CVE-2026-19961 | Edimax EW-7478APC formWlSiteSurvey buffer overflow | Edimax | EW-7478APC | Critical | 9.9 | 2026-08-16 23:00:16 | Deep Dive |
| CVE-2026-19959 | Edimax EW-7478APC formWanTcpipSetup stack-based overflow | Edimax | EW-7478APC | Critical | 9.9 | 2026-08-16 22:30:15 | Deep Dive |
| CVE-2026-74790 🧪 | Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache | scriban | scriban | Critical | 9.1 | 2026-08-16 13:14:14 | Deep Dive |
| CVE-2026-73061 🧪 | Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor | scriban | scriban | Critical | 9.8 | 2026-08-16 13:14:08 | Deep Dive |
| CVE-2026-73056 | SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token | siyuan-note | siyuan | Critical | 9.8 | 2026-08-16 13:14:05 | Deep Dive |