| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-68569 | Apache Tomcat: Principal lookup can fail open in some cases | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:59:17 | Deep Dive |
| CVE-2026-80185 | Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root | Red Hat | Red Hat Enterprise Linux 10 | Medium | 5.7 | 2026-08-25 21:58:17 | Deep Dive |
| CVE-2026-80186 🧪 | Bluez: stack overflow in name2utf8 causes dos and potential code execution | Red Hat | Red Hat Enterprise Linux 10 | High | 7.6 | 2026-08-25 21:58:17 | Deep Dive |
| CVE-2026-68525 | Apache Tomcat: Redirect after FORM auth may bypass method specific constraints | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:57:19 | Deep Dive |
| CVE-2026-66422 | Apache Tomcat: Servlet role references can bypass declarative role constraints | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:55:17 | Deep Dive |
| CVE-2026-65927 | Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:53:06 | Deep Dive |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | baptisteArno | typebot.io | High | 8.7 | 2026-08-25 21:52:17 | Deep Dive |
| CVE-2026-65905 | Apache Tomcat: Limited replay attack possible with DIGEST authentication | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:51:33 | Deep Dive |
| CVE-2026-65637 | Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:49:13 | Deep Dive |
| CVE-2026-62861 | TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomain | baptisteArno | typebot.io | Medium | 6.4 | 2026-08-25 21:46:25 | Deep Dive |
| CVE-2026-65183 | Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:44:49 | Deep Dive |
| CVE-2026-65182 | Apache Tomcat: Bypass longest prefix security constraint | Apache Software Foundation | Apache Tomcat | - | - | 2026-08-25 21:43:37 | Deep Dive |
| CVE-2026-62862 | TypeBot: Account takeover via brute-forceable 6-digit magic-link code | baptisteArno | typebot.io | Critical | 9.1 | 2026-08-25 21:43:21 | Deep Dive |
| CVE-2026-79804 🧪 | SililaWijesinghe Food Ordering System search.php sql injection | SililaWijesinghe | Food Ordering System | High | 7.3 | 2026-08-25 21:30:10 | Deep Dive |
| CVE-2026-80184 | OpenStack Keystone越权漏洞 | OpenStack | Keystone | High | 7.6 | 2026-08-25 21:29:29 | Deep Dive |
| CVE-2026-78655 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session | - | - | - | - | 2026-08-25 21:23:48 | Deep Dive |
| CVE-2026-78619 | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically | - | - | - | - | 2026-08-25 21:21:08 | Deep Dive |
| CVE-2026-80182 | OpenStack Keystone <29.0.3 越权漏洞 | OpenStack | Keystone | High | 7.6 | 2026-08-25 21:19:10 | Deep Dive |
| CVE-2026-32637 | Velero vulnerable to file path traversal when extracting from backup's tarball | velero-io | velero | Medium | 5.9 | 2026-08-25 21:15:32 | Deep Dive |
| CVE-2026-72924 | GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default | cli | cli | Low | 2.1 | 2026-08-25 21:03:12 | Deep Dive |