| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-18916 | Remote TCP DoS by throttling the TCP receive window | NLnet Labs | NSD | Medium | 6.9 | 2026-08-26 08:39:12 | Deep Dive |
| CVE-2026-18664 | Wrong interpretation of ACL ranges | NLnet Labs | NSD | High | 8.2 | 2026-08-26 08:34:23 | Deep Dive |
| CVE-2026-80237 | Thinking Software Technology|Efence - Arbitrary File Upload | Thinking Software Technology | Efence | High | 8.8 | 2026-08-26 08:28:14 | Deep Dive |
| CVE-2026-80236 | Thinking Software Technology|Efence - SQL Injection | Thinking Software Technology | Efence | High | 8.2 | 2026-08-26 08:27:13 | Deep Dive |
| CVE-2026-80235 | Thinking Software Technology|EFence - Arbitrary File Upload | Thinking Software Technology | EFence | Critical | 9.8 | 2026-08-26 08:26:13 | Deep Dive |
| CVE-2026-80234 | CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication | CAYIN Technology | CAYIN CMS-WS | Medium | 5.3 | 2026-08-26 08:22:13 | Deep Dive |
| CVE-2026-80233 | CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload | CAYIN Technology | CAYIN CMS-WS | High | 7.2 | 2026-08-26 08:19:40 | Deep Dive |
| CVE-2026-9668 | SQL injection vulnerability in ZTE SCP product | ZTE | SCP | Medium | 6.3 | 2026-08-26 08:02:08 | Deep Dive |
| CVE-2026-75977 | Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie | kitae-park | Mang Board WP | High | 8.8 | 2026-08-26 07:42:01 | Deep Dive |
| CVE-2026-6178 | Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode | MuffinGroup | Betheme | Medium | 6.4 | 2026-08-26 07:42:01 | Deep Dive |
| CVE-2026-18884 | WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters | wpgenie | WooCommerce Lottery | High | 7.5 | 2026-08-26 07:42:00 | Deep Dive |
| CVE-2026-78237 | Insufficient input validation in Admin By Request (ABR) | Admin By Request (ABR) | Admin By Request (ABR) | High | 7.8 | 2026-08-26 07:24:32 | Deep Dive |
| CVE-2026-78236 | Insecure PIN derivation mechanism in Admin By Request (ABR) | Admin By Request (ABR) | Admin By Request (ABR) | High | 8.8 | 2026-08-26 07:20:59 | Deep Dive |
| CVE-2026-58108 | Personal access token delete filters on Session columns while deleting from PersonalAccessTokenDB | Ericsson | CodeChecker | Low | 1.2 | 2026-08-26 06:48:06 | Deep Dive |
| CVE-2026-15366 | Samsung Kids Mode网页越权漏洞(含版本影响) | vivo | Kids Mode | Low | 2.4 | 2026-08-26 06:46:55 | Deep Dive |
| CVE-2026-15365 | 小米Kids Mode密码绕过漏洞(Quick Apps) | vivo | Kids Mode | Low | 2.4 | 2026-08-26 06:45:35 | Deep Dive |
| CVE-2026-18331 | Formidable Forms <= 6.33.1 - Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter | strategy11team | Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More | High | 7.2 | 2026-08-26 06:08:29 | Deep Dive |
| CVE-2026-18431 | Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write | themefusion | Avada (Fusion) Builder | Critical | 9.8 | 2026-08-26 06:08:28 | Deep Dive |
| CVE-2026-3002 | Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks | jegstudio | Gutenverse – WordPress Blocks, Page Builder & Site Editor | Medium | 6.4 | 2026-08-26 06:08:28 | Deep Dive |
| CVE-2026-78146 | Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page | Unknown | Simple Newsletter Plugin | - | - | 2026-08-26 06:00:23 | Deep Dive |