| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-80197 | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints | kimai | kimai | Medium | 4.3 | 2026-08-25 23:19:04 | Deep Dive |
| CVE-2026-80198 🧪 | Kimai before 2.56.0 Information Disclosure via config() Twig Function | kimai | kimai | High | 7.5 | 2026-08-25 23:19:04 | Deep Dive |
| CVE-2026-80196 🧪 | Kimai before 2.58.0 Authentication Bypass via Password Reset Link | kimai | kimai | High | 7.5 | 2026-08-25 23:19:03 | Deep Dive |
| CVE-2026-80194 | Kimai before 2.64.0 Missing Authorization via ProjectViewController export | kimai | kimai | Medium | 4.3 | 2026-08-25 23:19:02 | Deep Dive |
| CVE-2026-80195 | Kimai before 2.63.0 Team Membership Removal via API | kimai | kimai | Medium | 5.4 | 2026-08-25 23:19:02 | Deep Dive |
| CVE-2026-80193 🧪 | Kimai before 2.62.0 Authorization Bypass via QuickEntry | kimai | kimai | High | 8.8 | 2026-08-25 23:19:01 | Deep Dive |
| CVE-2026-80192 | better-auth SSO before 1.6.27 Domain Ownership Authentication Bypass | better-auth | sso | High | 8.1 | 2026-08-25 23:19:00 | Deep Dive |
| CVE-2026-80191 🧪 | GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthenticated Requests | GROWI, Inc. | GROWI | High | 7.5 | 2026-08-25 23:19:00 | Deep Dive |
| CVE-2026-80189 | LeafWiki 0.10.0 through 0.12.0 Uncontrolled Resource Consumption via Unbounded ZIP Extraction | perber | leafwiki | Medium | 6.5 | 2026-08-25 23:18:59 | Deep Dive |
| CVE-2026-57170 🧪 | Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) | oscal-compass | compliance-trestle | High | 7.8 | 2026-08-25 23:18:29 | Deep Dive |
| CVE-2026-52776 🧪 | Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 | oscal-compass | compliance-trestle | High | 8.6 | 2026-08-25 23:12:25 | Deep Dive |
| CVE-2026-54757 🧪 | Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data | oscal-compass | compliance-trestle | High | 7.8 | 2026-08-25 23:02:12 | Deep Dive |
| CVE-2026-44476 | Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secret | doorkeeper-gem | doorkeeper-openid_connect | Medium | 6.3 | 2026-08-25 22:47:55 | Deep Dive |
| CVE-2026-41707 | Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay | Spring | Spring Security | High | 7.4 | 2026-08-25 22:34:31 | Deep Dive |
| CVE-2026-79912 🧪 | TOTOLINK N600R cstecgi.cgi getCurrentTime command injection | TOTOLINK | N600R | High | 8.3 | 2026-08-25 22:30:12 | Deep Dive |
| CVE-2026-15916 | Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010 | Drupal | Drupal core | - | - | 2026-08-25 22:22:27 | Deep Dive |
| CVE-2026-15917 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011 | Drupal | Drupal core | - | - | 2026-08-25 22:22:24 | Deep Dive |
| CVE-2026-55805 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012 | Drupal | Drupal core | - | - | 2026-08-25 22:22:21 | Deep Dive |
| CVE-2026-16638 | Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080 | Drupal | Media Folders | - | - | 2026-08-25 22:22:18 | Deep Dive |
| CVE-2026-16639 | Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 | Drupal | Internationalization Single Sign-On | - | - | 2026-08-25 22:22:13 | Deep Dive |