| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway OS Command Injection | Haiwell | Haiwell IoT Cloud HMI Gateway | Critical | 10.0 | 2026-08-14 18:20:49 | Deep Dive |
| CVE-2026-48528 🧪 | Metacat has an unauthenticated SQL injection vulnerability | NCEAS | metacat | Critical | 9.8 | 2026-08-14 17:56:35 | Deep Dive |
| CVE-2026-19682 | Command Injection | Tenable, Inc. | Security Center | Critical | 9.9 | 2026-08-14 17:51:56 | Deep Dive |
| CVE-2026-19681 💣 | Command Injection | Tenable, Inc. | Security Center | Critical | 9.9 | 2026-08-14 17:45:38 | Deep Dive |
| CVE-2026-73849 🧪 | emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. | emlog | emlog | Critical | 9.8 | 2026-08-14 17:37:20 | Deep Dive |
| CVE-2026-19626 💣 | Remote Code Execution | Tenable, Inc. | Security Center | Critical | 9.9 | 2026-08-14 16:55:37 | Deep Dive |
| CVE-2026-19871 🧪 | Use of hard-coded credentials in Prospero Flow CRM employee onboarding | Roskus | Prospero Flow CRM | Critical | 9.3 | 2026-08-14 14:00:56 | Deep Dive |
| CVE-2026-72811 | SiYuan before v3.7.4 SQL Injection via backlink search | siyuan-note | siyuan | Critical | 10.0 | 2026-08-14 11:35:25 | Deep Dive |
| CVE-2026-12949 | Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter | Wishlist Member | Wishlist Member | Critical | 9.8 | 2026-08-14 05:30:44 | Deep Dive |
| CVE-2026-73302 🧪 | Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified | Budibase | budibase | Critical | 9.0 | 2026-08-13 22:04:50 | Deep Dive |
| CVE-2026-73421 🧪 | NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) | nextauthjs | next-auth | Critical | 9.1 | 2026-08-13 22:04:37 | Deep Dive |
| CVE-2026-73420 🧪 | NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass | nextauthjs | next-auth | Critical | 9.1 | 2026-08-13 22:04:15 | Deep Dive |
| CVE-2026-73843 🧪 | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs | openchoreo | openchoreo | Critical | 9.6 | 2026-08-13 22:02:41 | Deep Dive |
| CVE-2026-73842 🧪 | OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation | openchoreo | openchoreo | Critical | 9.0 | 2026-08-13 21:59:24 | Deep Dive |
| CVE-2026-72851 🧪 | Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook | budibase | server | Critical | 10.0 | 2026-08-13 21:54:43 | Deep Dive |
| CVE-2026-72850 🧪 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | budibase | server | Critical | 9.1 | 2026-08-13 21:54:43 | Deep Dive |
| CVE-2026-72842 🧪 | OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass | openwrt | luci | Critical | 9.9 | 2026-08-13 21:54:41 | Deep Dive |
| CVE-2026-72841 🧪 | luci-app-openvpn Path Traversal RCE via instance_name2 | openwrt | luci | Critical | 9.9 | 2026-08-13 21:54:41 | Deep Dive |
| CVE-2026-72839 🧪 | filebrowser through 2.63.16 Privilege Escalation via Signup | filebrowser | filebrowser | Critical | 9.8 | 2026-08-13 21:54:39 | Deep Dive |
| CVE-2026-73665 🧪 | FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection | FreePBX | ucp | Critical | 9.3 | 2026-08-13 21:32:02 | Deep Dive |