| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39454 | SKYSEA Client View 安全漏洞 | Sky Co.,LTD. | SKYSEA Client View | - | - | 2026-04-20 08:04:57 | Deep Dive |
| CVE-2026-6619 | langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting | langgenius | dify | Low | 3.5 | 2026-04-20 08:00:17 | Deep Dive |
| CVE-2026-6618 | langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery | langgenius | dify | Medium | 6.3 | 2026-04-20 07:45:17 | Deep Dive |
| CVE-2026-5967 | TeamT5|ThreatSonar Anti-Ransomware - Privilege Escalation | TeamT5 | ThreatSonar Anti-Ransomware | High | 8.8 | 2026-04-20 07:44:20 | Deep Dive |
| CVE-2026-5966 | TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File Deletion | TeamT5 | ThreatSonar Anti-Ransomware | High | 8.1 | 2026-04-20 07:40:33 | Deep Dive |
| CVE-2026-5964 | Digiwin|EasyFlow .NET - SQL Injection | Digiwin | EasyFlow .NET | Critical | 9.8 | 2026-04-20 07:36:58 | Deep Dive |
| CVE-2026-5963 | Digiwin|EasyFlow .NET - SQL Injection | Digiwin | EasyFlow .NET | Critical | 9.8 | 2026-04-20 07:32:20 | Deep Dive |
| CVE-2026-6617 | langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgery | langgenius | dify | Medium | 6.3 | 2026-04-20 07:30:12 | Deep Dive |
| CVE-2026-6616 | TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery | TransformerOptimus | SuperAGI | Medium | 6.3 | 2026-04-20 07:15:12 | Deep Dive |
| CVE-2026-41282 | Nuclei 安全漏洞 | ProjectDiscovery | Nuclei | Medium | 4.0 | 2026-04-20 07:10:30 | Deep Dive |
| CVE-2026-6615 | TransformerOptimus SuperAGI Multipart Upload resources.py upload path traversal | TransformerOptimus | SuperAGI | High | 7.3 | 2026-04-20 07:00:16 | Deep Dive |
| CVE-2026-6644 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM | ASUSTOR Inc. | ADM | - | - | 2026-04-20 06:54:43 | Deep Dive |
| CVE-2026-6614 | TransformerOptimus SuperAGI project.py get_projects_organisation authorization | TransformerOptimus | SuperAGI | Medium | 6.3 | 2026-04-20 06:45:12 | Deep Dive |
| CVE-2026-6643 | A stack-based buffer overflow vulnerability in the VPN Clients on the ADM | ASUSTOR Inc. | ADM | - | - | 2026-04-20 06:34:28 | Deep Dive |
| CVE-2026-6613 | TransformerOptimus SuperAGI agent.py get_schedule_data authorization | TransformerOptimus | SuperAGI | Medium | 6.3 | 2026-04-20 06:30:15 | Deep Dive |
| CVE-2026-6612 | TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization | TransformerOptimus | SuperAGI | Medium | 6.3 | 2026-04-20 06:15:10 | Deep Dive |
| CVE-2026-6611 | liangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded key | liangliangyy | DjangoBlog | Low | 3.1 | 2026-04-20 06:00:18 | Deep Dive |
| CVE-2024-7083 | Email Encoder < 2.3.4 - Admin+ Stored XSS | Unknown | Email Encoder | - | - | 2026-04-20 06:00:07 | Deep Dive |
| CVE-2026-6610 | liangliangyy DjangoBlog Setting settings.py hard-coded credentials | liangliangyy | DjangoBlog | Low | 3.7 | 2026-04-20 05:45:19 | Deep Dive |
| CVE-2026-6609 | liangliangyy DjangoBlog views.py form_valid improper authorization | liangliangyy | DjangoBlog | Medium | 6.3 | 2026-04-20 05:30:17 | Deep Dive |