| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-12587 | Embedded credentials in Virtuagym | Resamania | Virtuagym | High | 8.6 | 2026-08-26 12:20:52 | Deep Dive |
| CVE-2026-77658 | Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project files | GNOME | Dia | High | 7.8 | 2026-08-26 12:10:08 | Deep Dive |
| CVE-2026-15985 | Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login | RadiusTheme | Classified Listing - Mobile Number Verification | High | 8.1 | 2026-08-26 11:36:39 | Deep Dive |
| CVE-2026-63041 | Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers | Apache Software Foundation | Apache APISIX | Medium | 5.3 | 2026-08-26 11:35:00 | Deep Dive |
| CVE-2026-18080 | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment | wedevs | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce | Critical | 9.8 | 2026-08-26 11:05:45 | Deep Dive |
| CVE-2026-3235 | WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access | peterschulznl | WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards | Medium | 5.3 | 2026-08-26 11:05:44 | Deep Dive |
| CVE-2026-5092 | Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI | wpsoul | Greenshift – animation and page builder blocks | Medium | 6.4 | 2026-08-26 11:05:44 | Deep Dive |
| CVE-2026-77532 | CVE-2026-77532 | Ubiquiti Inc | EdgeMAX EdgeSwitch | Critical | 9.6 | 2026-08-26 11:01:30 | Deep Dive |
| CVE-2026-77557 | CVE-2026-77557 | Ubiquiti Inc | UniFi Protect AI Key | Critical | 9.8 | 2026-08-26 10:53:27 | Deep Dive |
| CVE-2026-77554 | CVE-2026-77554 | Ubiquiti Inc | UniFi Talk Application | Critical | 10.0 | 2026-08-26 10:45:46 | Deep Dive |
| CVE-2026-77553 | CVE-2026-77553 | Ubiquiti Inc | UniFi Access Application | Critical | 9.9 | 2026-08-26 10:42:55 | Deep Dive |
| CVE-2026-77552 | CVE-2026-77552 | Ubiquiti Inc | UniFi Enterprise Audio/Video Bridge | Critical | 9.8 | 2026-08-26 10:40:05 | Deep Dive |
| CVE-2026-77551 | CVE-2026-77551 | Ubiquiti Inc | UniFi Connect Display Cast Pro | Critical | 9.0 | 2026-08-26 10:37:20 | Deep Dive |
| CVE-2026-77550 | CVE-2026-77550 | Ubiquiti Inc | UniFi OS Server | Critical | 10.0 | 2026-08-26 10:33:30 | Deep Dive |
| CVE-2026-77549 | CVE-2026-77549 | Ubiquiti Inc | UniFi OS Server | Critical | 9.0 | 2026-08-26 10:30:07 | Deep Dive |
| CVE-2026-80206 | NLTK 3.10.2 Regular Expression Denial of Service via tgrep | nltk | nltk | Medium | 5.9 | 2026-08-26 10:28:15 | Deep Dive |
| CVE-2026-80204 | Grav before 1.0.18 Authentication Bypass via Scoped API Key | getgrav | grav | Medium | 5.4 | 2026-08-26 10:28:14 | Deep Dive |
| CVE-2026-80205 | NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex | nltk | nltk | High | 7.5 | 2026-08-26 10:28:14 | Deep Dive |
| CVE-2026-80203 | Grav before 1.0.18 Authentication Bypass via Scoped API Key | getgrav | grav | Critical | 9.8 | 2026-08-26 10:28:13 | Deep Dive |
| CVE-2026-77548 | CVE-2026-77548 | Ubiquiti Inc | UniFi Protect Application | Critical | 9.9 | 2026-08-26 10:23:38 | Deep Dive |