| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73486 🧪 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:06 | Deep Dive |
| CVE-2026-73485 🧪 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | FlowiseAI | Flowise | Critical | 9.0 | 2026-08-13 11:28:05 | Deep Dive |
| CVE-2026-73483 🧪 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | FlowiseAI | Flowise | Critical | 9.4 | 2026-08-13 11:28:04 | Deep Dive |
| CVE-2026-59507 | Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | Critical | 9.3 | 2026-08-13 09:44:24 | Deep Dive |
| CVE-2026-59506 | Priority – CWE-306: Missing Authentication for Critical Function | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | Critical | 9.3 | 2026-08-13 09:41:13 | Deep Dive |
| CVE-2026-59504 | Priority – CWE-602: Client-Side Enforcement of Server-Side Security | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | Critical | 9.1 | 2026-08-13 09:33:51 | Deep Dive |
| CVE-2026-59503 | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | Critical | 9.1 | 2026-08-13 09:30:48 | Deep Dive |
| CVE-2026-59500 | Priority - CWE-287: Improper Authentication | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | Critical | 10.0 | 2026-08-13 09:18:38 | Deep Dive |
| CVE-2026-15413 | Link Factory - Backdoor | Unknown | Link Factory | Critical | 10.0 | 2026-08-13 08:13:12 | Deep Dive |
| CVE-2026-49819 🧪 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | seriousm4x | UpSnap | Critical | 9.8 | 2026-08-12 23:13:46 | Deep Dive |
| CVE-2026-49481 🧪 | UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd | seriousm4x | UpSnap | Critical | 9.6 | 2026-08-12 23:08:45 | Deep Dive |
| CVE-2026-71193 | OpenStack Designate 授权问题漏洞 | OpenStack | Designate | Critical | 9.6 | 2026-08-12 22:17:13 | Deep Dive |
| CVE-2026-71471 | Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | Critical | 9.0 | 2026-08-12 21:40:12 | Deep Dive |
| CVE-2026-73501 🧪 | kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default | getkin | kin-openapi | Critical | 9.1 | 2026-08-12 21:23:41 | Deep Dive |
| CVE-2024-27253 | IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews delete request | IBM | DOORS Next | Critical | 10.0 | 2026-08-12 21:23:03 | Deep Dive |
| CVE-2026-73519 🧪 | WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret | wolfsoftwaresystemsltd | WolfStack | Critical | 9.8 | 2026-08-12 21:15:33 | Deep Dive |
| CVE-2026-19001 🧪 | MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names | MongoDB | BI Connector ODBC Driver | Critical | 9.8 | 2026-08-12 20:27:03 | Deep Dive |
| CVE-2026-66898 🧪 | Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE | Canonical | LXD | Critical | 9.9 | 2026-08-12 20:07:33 | Deep Dive |
| CVE-2026-63293 🧪 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | Canonical | LXD | Critical | 9.9 | 2026-08-12 20:00:09 | Deep Dive |
| CVE-2026-63294 🧪 | Root RCE via image backup.yaml symlink | Canonical | LXD | Critical | 9.9 | 2026-08-12 19:57:08 | Deep Dive |