| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-71909 | DrayTek VigorAP Multiple Models OS Command Injection via InquierTime | DrayTek Corporation | VigorAP 918R | High | 7.2 | 2026-08-24 17:07:43 | Deep Dive |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | DrayTek Corporation | VigorAP 918R | High | 7.2 | 2026-08-24 17:07:42 | Deep Dive |
| CVE-2026-71907 | DrayTek VigorAP Multiple Models OS Command Injection via setcamset | DrayTek Corporation | VigorAP 918R | High | 7.2 | 2026-08-24 17:07:42 | Deep Dive |
| CVE-2026-71906 | DrayTek VigorAP Multiple Models OS Command Injection via setLan | DrayTek Corporation | VigorAP 918R | High | 7.2 | 2026-08-24 17:07:41 | Deep Dive |
| CVE-2026-71904 | DrayTek VigorAP Multiple Models OS Command Injection via tr069TestInform | DrayTek Corporation | VigorAP 918R | High | 7.2 | 2026-08-24 17:07:40 | Deep Dive |
| CVE-2026-71905 | DrayTek VigorAP Multiple Models OS Command Injection via ExportSettings | DrayTek Corporation | VigorAP 918R | High | 7.2 | 2026-08-24 17:07:40 | Deep Dive |
| CVE-2026-75099 | Apache Allura: Unauthenticated REST disclosure | Apache Software Foundation | Apache Allura | - | - | 2026-08-24 16:42:21 | Deep Dive |
| CVE-2025-36939 | OpenThread MLE包处理漏洞:DoS及栈溢出 | Nest | Critical | 10.0 | 2026-08-24 16:38:46 | Deep Dive | |
| CVE-2025-36940 | Fuchsia zircon内核页面代理Use-After-Free漏洞可导致提权 | Android | - | - | 2026-08-24 16:33:54 | Deep Dive | |
| CVE-2026-15469 | Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800 | TP-Link Systems Inc. | Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 | High | 7.7 | 2026-08-24 16:32:13 | Deep Dive |
| CVE-2026-78465 | Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit | Red Hat | Red Hat Enterprise Linux 6 | High | 7.0 | 2026-08-24 16:28:13 | Deep Dive |
| CVE-2026-78329 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:22:18 | Deep Dive |
| CVE-2026-71300 | Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:21:17 | Deep Dive |
| CVE-2026-63621 | Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:17:26 | Deep Dive |
| CVE-2026-66908 | Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:14:18 | Deep Dive |
| CVE-2026-66907 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:13:05 | Deep Dive |
| CVE-2026-19685 | Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615) | Red Hat | Red Hat Enterprise Linux 10 | High | 7.1 | 2026-08-24 16:12:38 | Deep Dive |
| CVE-2026-66906 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:12:10 | Deep Dive |
| CVE-2026-77915 🧪 | rConfig 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php | rconfig | rconfig | Critical | 9.8 | 2026-08-24 16:11:45 | Deep Dive |
| CVE-2026-60093 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir | Apache Software Foundation | Apache Camel | - | - | 2026-08-24 16:11:24 | Deep Dive |