| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-78391 🧪 | Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook | ransomlook | ransomlook | High | 8.8 | 2026-08-24 14:13:20 | Deep Dive |
| CVE-2026-78387 🧪 | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification | ransomlook | ransomlook | Critical | 9.4 | 2026-08-24 14:04:17 | Deep Dive |
| CVE-2026-67602 🧪 | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache | phpipam | phpipam | Critical | 9.1 | 2026-08-24 13:57:42 | Deep Dive |
| CVE-2026-78386 🧪 | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook API | ransomlook | ransomlook | High | 8.7 | 2026-08-24 13:55:57 | Deep Dive |
| CVE-2026-17033 | CVE-2026-17033 CVE Record | Grafana | Grafana OSS | Medium | 6.8 | 2026-08-24 13:52:27 | Deep Dive |
| CVE-2026-78385 🧪 | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local File Access | ransomlook | ransomlook | High | 8.2 | 2026-08-24 13:49:51 | Deep Dive |
| CVE-2026-78367 🧪 | Rpm: rpmbuild gettarspec() crafted tar member name → macro injection | Red Hat | Red Hat Enterprise Linux 10 | High | 7.0 | 2026-08-24 13:48:52 | Deep Dive |
| CVE-2026-59568 | Remote Code Execution | Zscaler | Client Connector | Critical | 9.1 | 2026-08-24 13:44:22 | Deep Dive |
| CVE-2025-68833 | HCL Hive is affected by use of a cryptographic primitive with a risky implementation | HCLSoftware | HCL Hive | Medium | 5.3 | 2026-08-24 13:42:32 | Deep Dive |
| CVE-2026-59567 | Local privilege escalation | Zscaler | Client Connector | High | 8.8 | 2026-08-24 13:41:39 | Deep Dive |
| CVE-2026-59566 | Local denial-of-service | Zscaler | Client Connector | High | 8.4 | 2026-08-24 13:41:05 | Deep Dive |
| CVE-2026-59565 | Local and kernel denial-of-service | Zscaler | Client Connector | High | 8.8 | 2026-08-24 13:40:24 | Deep Dive |
| CVE-2026-59564 | Authentication bypass between ZCC and client connector portal | Zscaler | Client Connector | Critical | 9.1 | 2026-08-24 13:39:16 | Deep Dive |
| CVE-2026-78381 🧪 | RansomLook Arbitrary File Read via Path Traversal in Post screen Field | ransomlook | ransomlook | High | 8.2 | 2026-08-24 13:32:55 | Deep Dive |
| CVE-2026-78376 | Webkitgtk: use-after-free of jscvalue function parameters | Red Hat | Red Hat Enterprise Linux 6 | High | 8.8 | 2026-08-24 13:29:17 | Deep Dive |
| CVE-2026-78380 🧪 | Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLook | ransomlook | ransomlook | High | 8.7 | 2026-08-24 13:26:56 | Deep Dive |
| CVE-2026-78378 | Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data | ransomlook | ransomlook | Medium | 6.9 | 2026-08-24 13:19:02 | Deep Dive |
| CVE-2026-21751 | HCL Hive is affected by use of a cryptographic primitive with a risky implementation | HCLSoftware | HCL Hive | High | 7.4 | 2026-08-24 13:18:16 | Deep Dive |
| CVE-2026-78250 | bytebot-ai bytebot Agent Execution Workflow infinite loop | bytebot-ai | bytebot | Medium | 4.3 | 2026-08-24 13:15:09 | Deep Dive |
| CVE-2026-76848 🧪 | TypeORM 0.2.21 through 1.1.0 SQL Injection via SelectQueryBuilder.distinctOn | typeorm | typeorm | High | 7.5 | 2026-08-24 13:12:03 | Deep Dive |