| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-16640 | Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082 | Drupal | Search API Autocomplete | - | - | 2026-08-25 22:22:09 | Deep Dive |
| CVE-2026-16646 | PanKM - Critical - Unsupported - SA-CONTRIB-2026-083 | Drupal | PanKM | - | - | 2026-08-25 22:22:06 | Deep Dive |
| CVE-2026-16641 | Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084 | Drupal | Commerce Elavon | - | - | 2026-08-25 22:22:03 | Deep Dive |
| CVE-2026-16642 | Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085 | Drupal | Email Login OTP | - | - | 2026-08-25 22:21:59 | Deep Dive |
| CVE-2026-16643 | Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086 | Drupal | Lunr exposed filters | - | - | 2026-08-25 22:21:55 | Deep Dive |
| CVE-2026-16644 | Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087 | Drupal | Webform REST | - | - | 2026-08-25 22:21:51 | Deep Dive |
| CVE-2026-16645 | PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypass - SA-CONTRIB-2026-088 | Drupal | PhotoSwipe - Responsive JavaScript Modal Image Gallery | - | - | 2026-08-25 22:21:47 | Deep Dive |
| CVE-2026-15088 | Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089 | Drupal | Development Environment | - | - | 2026-08-25 22:21:44 | Deep Dive |
| CVE-2026-18259 | Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090 | Drupal | Token Content Access | - | - | 2026-08-25 22:21:40 | Deep Dive |
| CVE-2026-18260 | Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091 | Drupal | Disable Login Page | - | - | 2026-08-25 22:21:35 | Deep Dive |
| CVE-2026-18261 | Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092 | Drupal | Powerful Surveys | - | - | 2026-08-25 22:21:28 | Deep Dive |
| CVE-2026-18985 | Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093 | Drupal | Edit in-place field | - | - | 2026-08-25 22:19:32 | Deep Dive |
| CVE-2026-79911 🧪 | TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow | TOTOLINK | N600R | Critical | 10.0 | 2026-08-25 22:15:13 | Deep Dive |
| CVE-2026-80138 🧪 | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | MacWarrior | clipbucket-v5 | Critical | 9.8 | 2026-08-25 22:12:24 | Deep Dive |
| CVE-2026-70665 | Doorkeeper OpenID Connect: DCR endpoint persists unvalidated client-supplied scopes | doorkeeper-gem | doorkeeper-openid_connect | Medium | 4.2 | 2026-08-25 22:09:53 | Deep Dive |
| CVE-2026-63403 🧪 | Faktory: Unrecovered panic in command handlers allows full-server denial of service | contribsys | faktory | High | 8.7 | 2026-08-25 22:04:48 | Deep Dive |
| CVE-2026-73180 | Apache Tomcat: Authenticated WebSocket session survives end of HTTP session | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 22:01:58 | Deep Dive |
| CVE-2026-63404 🧪 | Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hijack (network exposure / root RCE primitive) | contribsys | faktory | High | 7.3 | 2026-08-25 22:01:19 | Deep Dive |
| CVE-2026-68763 | Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 22:00:37 | Deep Dive |
| CVE-2026-79845 | code-projects Simple Inventory System edit.php sql injection | code-projects | Simple Inventory System | High | 7.3 | 2026-08-25 22:00:11 | Deep Dive |