| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-80049 🧪 | Airbyte Platform through 2.0.0 Cross-Workspace Authorization Bypass via Caller-Supplied workspaceId | airbytehq | airbyte-platform | High | 8.8 | 2026-08-25 18:23:17 | Deep Dive |
| CVE-2026-79788 🧪 | Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via Unrestricted AI Provider Address | dradis | dradis-ce | High | 7.1 | 2026-08-25 18:23:16 | Deep Dive |
| CVE-2026-79787 🧪 | Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature | Alluxio | alluxio | Critical | 9.8 | 2026-08-25 18:23:15 | Deep Dive |
| CVE-2026-79786 🧪 | Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration | coroot | coroot | High | 7.1 | 2026-08-25 18:23:14 | Deep Dive |
| CVE-2026-55618 | eml_parser: URL extraction bypass via HTML entities in URLs | GOVCERT-LU | eml_parser | Medium | 6.5 | 2026-08-25 18:21:56 | Deep Dive |
| CVE-2026-61555 | OpenEXR: Empty multiView viewFromChannelName file crash | AcademySoftwareFoundation | openexr | Medium | 5.5 | 2026-08-25 18:19:31 | Deep Dive |
| CVE-2026-59985 | OpenEXR: Heap out-of-bounds read in OpenEXRCore RLE decoding on ILP32 | AcademySoftwareFoundation | openexr | Medium | 5.5 | 2026-08-25 18:16:38 | Deep Dive |
| CVE-2026-55663 | mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation) | versatica | mediasoup | Medium | 5.6 | 2026-08-25 18:15:16 | Deep Dive |
| CVE-2026-59984 | OpenEXR: Scratch buffer overflow decoding B44-compressed InputFile on ILP32 | AcademySoftwareFoundation | openexr | Medium | 5.5 | 2026-08-25 18:13:02 | Deep Dive |
| CVE-2026-55637 🧪 | genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport | GeiserX | genieacs-mcp | High | 8.8 | 2026-08-25 18:03:35 | Deep Dive |
| CVE-2026-59983 | OpenEXR: Out-of-bounds read in DeepTiledInputFile sample-count table decode on ILP32 | AcademySoftwareFoundation | openexr | Medium | 5.5 | 2026-08-25 18:02:43 | Deep Dive |
| CVE-2026-59982 🧪 | OpenEXR: DWAA InputFile AC buffer overflow on ILP32 platforms | AcademySoftwareFoundation | openexr | High | 7.1 | 2026-08-25 17:59:25 | Deep Dive |
| CVE-2026-75750 | Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:16 | Deep Dive |
| CVE-2026-75767 | Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:15 | Deep Dive |
| CVE-2026-75768 | Substance3D - Painter | Untrusted Search Path (CWE-426) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:15 | Deep Dive |
| CVE-2026-75766 | Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:14 | Deep Dive |
| CVE-2026-75769 | Substance3D - Painter | Heap-based Buffer Overflow (CWE-122) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:13 | Deep Dive |
| CVE-2026-75752 | Substance3D - Painter | Out-of-bounds Read (CWE-125) | Adobe | Substance3D - Painter | Medium | 5.5 | 2026-08-25 17:58:12 | Deep Dive |
| CVE-2026-75770 | Substance3D - Painter | Out-of-bounds Write (CWE-787) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:12 | Deep Dive |
| CVE-2026-75749 | Substance3D - Painter | Out-of-bounds Write (CWE-787) | Adobe | Substance3D - Painter | High | 7.8 | 2026-08-25 17:58:11 | Deep Dive |