| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-74251 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 | phoca.cz | Phoca Cart extension for Joomla | Critical | 9.3 | 2026-08-16 12:51:16 | Deep Dive |
| CVE-2024-13784 | Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection | reputeinfosystems | Contact Form, Survey, Quiz & Popup Form Builder – ARForms | Critical | 9.8 | 2026-08-16 08:31:06 | Deep Dive |
| CVE-2026-18316 | Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action | solacewp | Solace Extra | Critical | 9.1 | 2026-08-16 05:27:29 | Deep Dive |
| CVE-2026-14524 | ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters | prosolution | ProSolution WP Client | Critical | 9.1 | 2026-08-16 04:24:53 | Deep Dive |
| CVE-2026-16098 | ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override | prosolution | ProSolution WP Client | Critical | 9.8 | 2026-08-16 04:24:52 | Deep Dive |
| CVE-2026-18432 | Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter | shabti | Frontend Admin by DynamiApps | Critical | 9.8 | 2026-08-16 04:24:49 | Deep Dive |
| CVE-2026-19924 🧪 | Tenda AC10 httpd R7WebsSecurityHandler improper authentication | Tenda | AC10 | Critical | 9.8 | 2026-08-16 01:00:13 | Deep Dive |
| CVE-2026-73053 | SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:53 | Deep Dive |
| CVE-2026-73052 | SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:53 | Deep Dive |
| CVE-2026-73050 | SiYuan before v3.7.4 Stored XSS via select option color | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:52 | Deep Dive |
| CVE-2026-73046 | SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth | siyuan-note | siyuan | Critical | 9.8 | 2026-08-15 21:44:51 | Deep Dive |
| CVE-2026-73044 | SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:49 | Deep Dive |
| CVE-2026-73043 | SiYuan before v3.7.4 Remote Code Execution via Template Calculation | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:48 | Deep Dive |
| CVE-2026-73042 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:48 | Deep Dive |
| CVE-2026-73041 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations | siyuan-note | siyuan | Critical | 9.0 | 2026-08-15 21:44:47 | Deep Dive |
| CVE-2026-74764 🧪 | Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora | pandora-analysis | pandora | Critical | 10.0 | 2026-08-15 21:39:10 | Deep Dive |
| CVE-2026-18855 | Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter | jackdewey | Link Library | Critical | 9.1 | 2026-08-15 18:25:57 | Deep Dive |
| CVE-2026-19598 📌 💣 | Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router | sc0ttkclark | Pods – Custom Content Types and Fields | Critical | 9.8 | 2026-08-15 17:25:27 | Deep Dive |
| CVE-2026-74573 | iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE | Linux | Linux | Critical | 9.3 | 2026-08-15 12:28:12 | Deep Dive |
| CVE-2026-74570 | ntfs: harden runlist realloc size calculations | Linux | Linux | Critical | 9.8 | 2026-08-15 12:28:10 | Deep Dive |