| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-66153 | SonicWall NetExtender Linux文件路径操纵漏洞 | SonicWall | NetExtender | - | - | 2026-08-25 20:01:16 | Deep Dive |
| CVE-2026-66152 | SonicWall NetExtender Linux客户端路径穿越漏洞 | SonicWall | NetExtender | - | - | 2026-08-25 19:58:47 | Deep Dive |
| CVE-2026-59981 🧪 | OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 19:58:37 | Deep Dive |
| CVE-2026-68514 | OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision in deep images | AcademySoftwareFoundation | openexr | Medium | 5.5 | 2026-08-25 19:40:04 | Deep Dive |
| CVE-2026-68515 🧪 | OpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel union | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 19:34:15 | Deep Dive |
| CVE-2026-55099 🧪 | icalendar: Algorithmic Complexity in Equality | collective | icalendar | High | 7.5 | 2026-08-25 19:27:02 | Deep Dive |
| CVE-2026-65367 | iOS/iPadOS空指针解引用致崩溃漏洞 | Apple | iOS and iPadOS | - | - | 2026-08-25 19:24:55 | Deep Dive |
| CVE-2026-64705 | macOS序列号/子版本缓冲区溢出漏洞 | Apple | macOS | - | - | 2026-08-25 19:24:54 | Deep Dive |
| CVE-2026-43657 | iOS/iPadOS 26.5应用枚举漏洞 | Apple | iOS and iPadOS | - | - | 2026-08-25 19:24:52 | Deep Dive |
| CVE-2026-43670 | Safari 26.5内容安全策略绕过漏洞 | Apple | Safari | - | - | 2026-08-25 19:24:48 | Deep Dive |
| CVE-2026-45019 🧪 | Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access | Chainlit | chainlit | High | 7.2 | 2026-08-25 19:20:59 | Deep Dive |
| CVE-2026-45018 | Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | Chainlit | chainlit | Critical | 9.8 | 2026-08-25 19:18:46 | Deep Dive |
| CVE-2026-68513 🧪 | OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 19:06:12 | Deep Dive |
| CVE-2026-78379 | Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools | Amazon | strands-agents-tools | High | 8.1 | 2026-08-25 19:05:58 | Deep Dive |
| CVE-2026-65979 | OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN) | AcademySoftwareFoundation | openexr | Medium | 6.7 | 2026-08-25 18:58:26 | Deep Dive |
| CVE-2026-55609 | sublinear-time-solver: Arbitrary file write in consciousness-explorer / sublinear-time-solver MCP export_state | ruvnet | sublinear-time-solver | High | 7.1 | 2026-08-25 18:34:48 | Deep Dive |
| CVE-2026-62986 | OpenEXR: PyOpenEXR deep prefixed RGB stale lane disclosure | AcademySoftwareFoundation | openexr | Medium | 4.3 | 2026-08-25 18:27:19 | Deep Dive |
| CVE-2026-55620 🧪 | eml_parser: DoS via deeply nested parens in Received headers | GOVCERT-LU | eml_parser | High | 7.5 | 2026-08-25 18:26:55 | Deep Dive |
| CVE-2026-55619 | eml_parser: Parser DoS via deeply nested parentheses in e-mail headers | GOVCERT-LU | eml_parser | Medium | 5.3 | 2026-08-25 18:24:30 | Deep Dive |
| CVE-2026-80050 | ContiNew Admin through 4.1.0 Missing Authorization and File-Type Allowlist on Multipart Upload Endpoints | continew-org | continew-admin | Medium | 6.5 | 2026-08-25 18:23:17 | Deep Dive |