| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-58262🧪 | Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum | klever-io | klever-go | High | 7.1 | 2026-08-07 22:00:57 | Deep Dive |
| CVE-2026-64676 | Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory | kata-containers | kata-containers | Medium | 5.7 | 2026-08-07 21:47:21 | Deep Dive |
| CVE-2026-47243🧪 | Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs | kata-containers | kata-containers | Critical | 9.2 | 2026-08-07 21:36:50 | Deep Dive |
| CVE-2026-48170🧪 | scimPatch vulnerable to prototype pollution via unfiltered keys in patch | thomaspoignant | scim-patch | Critical | 9.1 | 2026-08-07 21:26:55 | Deep Dive |
| CVE-2026-48169🧪 | PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API | MervinPraison | praisonai-platform | High | 8.8 | 2026-08-07 21:22:04 | Deep Dive |
| CVE-2026-45808🧪 | OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL | openbao | openbao | High | 7.1 | 2026-08-07 21:15:01 | Deep Dive |
| CVE-2026-46405 | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens | openbao | openbao | Medium | 5.3 | 2026-08-07 21:14:36 | Deep Dive |
| CVE-2026-11743 | Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write | zephyrproject | zephyr | Medium | 6.6 | 2026-08-07 21:10:23 | Deep Dive |
| CVE-2026-11742 | Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock | zephyrproject | zephyr | Low | 3.6 | 2026-08-07 21:10:23 | Deep Dive |
| CVE-2026-19246 | HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery | HKUDS | nanobot | Medium | 6.3 | 2026-08-07 21:00:14 | Deep Dive |
| CVE-2026-50540🧪 | Kata Containers: Config Path Annotation Arbitrary File Loading | kata-containers | kata-containers | Critical | 9.6 | 2026-08-07 20:56:26 | Deep Dive |
| CVE-2026-54338 | JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login | jupyterhub | jupyterhub | Medium | 5.3 | 2026-08-07 20:52:55 | Deep Dive |
| CVE-2026-69207 | Hono: ReDoS in CORS middleware via Access-Control-Request-Headers | honojs | hono | Medium | 5.3 | 2026-08-07 20:51:04 | Deep Dive |
| CVE-2026-19245 | HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure | HKUDS | nanobot | Low | 3.3 | 2026-08-07 20:45:13 | Deep Dive |
| CVE-2026-66061🧪 | Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution | home-assistant | core | High | 7.1 | 2026-08-07 20:43:42 | Deep Dive |
| CVE-2026-9031 | Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 | TP-Link Systems Inc. | Archer A6 v4 | Medium | 6.8 | 2026-08-07 20:40:19 | Deep Dive |
| CVE-2026-9030 | Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 | TP-Link Systems Inc. | Archer A6 v4 | Medium | 6.8 | 2026-08-07 20:38:35 | Deep Dive |
| CVE-2026-66060 | Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers | home-assistant | core | High | 7.1 | 2026-08-07 20:35:47 | Deep Dive |
| CVE-2026-46358 | OpenBao's Inline Auth Incorrectly Redacted Headers | openbao | openbao | Medium | 5.4 | 2026-08-07 20:32:37 | Deep Dive |
| CVE-2026-19244 | HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control | HKUDS | nanobot | Medium | 4.7 | 2026-08-07 20:30:14 | Deep Dive |