| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73663 🧪 | FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover | FreePBX | missedcall | Critical | 9.3 | 2026-08-13 21:29:14 | Deep Dive |
| CVE-2026-72776 🧪 | AgenticSeek Unauthenticated RCE via /query API Endpoint | Fosowl | AgenticSeek | Critical | 9.8 | 2026-08-13 21:14:18 | Deep Dive |
| CVE-2026-19297 | Insufficient Authentication Brute Force Protection on Login Endpoint | IBM | Langflow OSS | Critical | 9.1 | 2026-08-13 20:46:45 | Deep Dive |
| CVE-2026-17482 | IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution | IBM | Documentation Offline | Critical | 9.8 | 2026-08-13 20:39:46 | Deep Dive |
| CVE-2026-8715 | Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath | HashiCorp | Tooling | Critical | 9.6 | 2026-08-13 20:27:39 | Deep Dive |
| CVE-2026-73656 | Trigger.dev: Cross-project deployment worker registration can modify another project's deployment state | triggerdotdev | trigger.dev | Critical | 9.9 | 2026-08-13 19:56:04 | Deep Dive |
| CVE-2026-19747 🧪 | Tenda CH7 ATE Module Kylin HandleCmd command injection | Tenda | CH7 | Critical | 9.8 | 2026-08-13 19:45:09 | Deep Dive |
| CVE-2026-14525 | IBM WebSphere Application Server Liberty is affected by an authenication bypass | IBM | WebSphere Application Server - Liberty | Critical | 9.4 | 2026-08-13 19:37:34 | Deep Dive |
| CVE-2026-73653 🧪 | Vitest: Browser Mode provider commands bypass the file-access permission gate | vitest-dev | vitest | Critical | 9.4 | 2026-08-13 18:19:00 | Deep Dive |
| CVE-2026-73649 🧪 | Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix) | shepherdwind | velocity.js | Critical | 9.8 | 2026-08-13 18:05:32 | Deep Dive |
| CVE-2026-73644 🧪 | OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant | OpenIdentityPlatform | OpenDJ | Critical | 9.6 | 2026-08-13 17:52:49 | Deep Dive |
| CVE-2026-73567 🧪 | sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock | JuneAndGreen | sm-crypto | Critical | 9.1 | 2026-08-13 17:40:54 | Deep Dive |
| CVE-2026-67614 🧪 | CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal | usmannasir | cyberpanel | Critical | 9.8 | 2026-08-13 17:08:40 | Deep Dive |
| CVE-2026-73532 | Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build | WPManageNinja | Fluent Forms Pro | Critical | 9.8 | 2026-08-13 16:01:20 | Deep Dive |
| CVE-2026-73533 | Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build | WPManageNinja | Ninja Tables Pro | Critical | 9.8 | 2026-08-13 16:00:48 | Deep Dive |
| CVE-2026-53791 🧪 | rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header | RsyncProject | rsync | Critical | 9.1 | 2026-08-13 14:38:10 | Deep Dive |
| CVE-2026-66691 | WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability | scriptsbundle | Nokri | Critical | 9.8 | 2026-08-13 13:37:17 | Deep Dive |
| CVE-2026-66478 | WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability | andy_moyle | Church Admin | Critical | 9.3 | 2026-08-13 13:37:10 | Deep Dive |
| CVE-2026-66472 | WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability | everestthemes | Everest Backup | Critical | 9.3 | 2026-08-13 13:37:09 | Deep Dive |
| CVE-2026-66465 | WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability | AgniHD | Cartify | Critical | 9.8 | 2026-08-13 13:37:05 | Deep Dive |