| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73263 | Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path | prowler-cloud | prowler | Critical | 9.9 | 2026-08-12 14:26:48 | Deep Dive |
| CVE-2026-50561 🧪 | Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse | xerrors | Yuxi | Critical | 9.4 | 2026-08-12 14:07:08 | Deep Dive |
| CVE-2026-67285 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 | joomshaper.com | SP Page Builder extension for Joomla | Critical | 9.2 | 2026-08-12 13:54:49 | Deep Dive |
| CVE-2026-67282 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 | fabrikar.com | Fabrik extension for Joomla | Critical | 10.0 | 2026-08-12 09:05:35 | Deep Dive |
| CVE-2025-41769 | Unauthenticated Buffer Overflow in PROFINET Service | Phoenix Contact | AXC F 1152 | Critical | 9.8 | 2026-08-12 08:05:54 | Deep Dive |
| CVE-2026-66659 🧪 | WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability | Essekia | Tablesome Table | Critical | 9.3 | 2026-08-12 06:01:41 | Deep Dive |
| CVE-2026-70398 | Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | Critical | 9.6 | 2026-08-12 01:10:33 | Deep Dive |
| CVE-2026-72526 | Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | Critical | 9.9 | 2026-08-12 01:10:29 | Deep Dive |
| CVE-2026-68431 | ksmbd: validate minimum PDU size for transform requests | Linux | Linux | Critical | 9.1 | 2026-08-12 00:07:17 | Deep Dive |
| CVE-2026-67568 | Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | Critical | 9.1 | 2026-08-11 21:25:11 | Deep Dive |
| CVE-2026-68067 | Mira Hormone Monitor, Mira Android App Weak Authentication | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | Critical | 9.8 | 2026-08-11 21:23:06 | Deep Dive |
| CVE-2026-48765 | TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding | baptisteArno | typebot.io | Critical | 9.9 | 2026-08-11 20:37:48 | Deep Dive |
| CVE-2026-16230 | Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field | Strategy11 | Formidable Digital Signatures | Critical | 9.8 | 2026-08-11 19:37:28 | Deep Dive |
| CVE-2026-73034 📌 💣 | DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header | eosphoros-ai | DB-GPT | Critical | 9.8 | 2026-08-11 19:31:49 | Deep Dive |
| CVE-2026-45618 🧪 | LiquidJS is Vulnerable to Remote Code Execution | harttle | liquidjs | Critical | 10.0 | 2026-08-11 19:27:10 | Deep Dive |
| CVE-2026-73032 🧪 | PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() | papersgpt | papersgpt-for-zotero | Critical | 9.6 | 2026-08-11 19:19:02 | Deep Dive |
| CVE-2026-69102 🧪 | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust | dromara | MaxKey | Critical | 9.8 | 2026-08-11 18:04:26 | Deep Dive |
| CVE-2026-71362 📌 💣 | Adobe Commerce | Incorrect Authorization (CWE-863) | Adobe | Adobe Commerce | Critical | 9.1 | 2026-08-11 17:52:48 | Deep Dive |
| CVE-2026-48381 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) | Adobe | Adobe Campaign Classic | Critical | 9.0 | 2026-08-11 17:46:48 | Deep Dive |
| CVE-2026-71398 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) | Adobe | Adobe Campaign Classic | Critical | 10.0 | 2026-08-11 17:46:47 | Deep Dive |