| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-79771 | Nokogiri before 1.19.3 Memory Leak via XSLT Transform | sparklemotion | nokogiri | Medium | 5.3 | 2026-08-25 15:16:04 | Deep Dive |
| CVE-2026-79772 | Nokogiri before 1.19.1 Unchecked Return Value canonicalize | sparklemotion | nokogiri | Medium | 5.3 | 2026-08-25 15:16:04 | Deep Dive |
| CVE-2026-79770 🧪 | Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer | sparklemotion | nokogiri | High | 7.5 | 2026-08-25 15:16:03 | Deep Dive |
| CVE-2026-79769 | Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args | sparklemotion | nokogiri | Medium | 5.5 | 2026-08-25 15:16:02 | Deep Dive |
| CVE-2026-79676 | NLTK before 3.10.3 Path Traversal via Symlink Bypass | nltk | nltk | Medium | 5.9 | 2026-08-25 15:16:02 | Deep Dive |
| CVE-2026-79675 🧪 | NLTK before 3.10.3 JVM Argument Injection via Per-Call Options | nltk | nltk | Critical | 9.8 | 2026-08-25 15:16:01 | Deep Dive |
| CVE-2026-79674 🧪 | NLTK 3.10.2 Path Traversal via corpus-reader constructors | nltk | nltk | High | 8.2 | 2026-08-25 15:16:00 | Deep Dive |
| CVE-2025-71406 | Nokogiri before 1.18.4 Use-After-Free via libxslt | sparklemotion | nokogiri | High | 7.8 | 2026-08-25 15:15:59 | Deep Dive |
| CVE-2025-71407 | Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free | sparklemotion | nokogiri | Critical | 9.8 | 2026-08-25 15:15:59 | Deep Dive |
| CVE-2025-71346 | Nokogiri before 1.18.8 Heap Buffer Under-read via XML Schema | sparklemotion | nokogiri | Low | 2.9 | 2026-08-25 15:15:58 | Deep Dive |
| CVE-2024-58377 | Nokogiri before 1.16.5 libxml2 Dependency Update | sparklemotion | nokogiri | Medium | 5.5 | 2026-08-25 15:15:57 | Deep Dive |
| CVE-2024-58378 | Nokogiri before 1.16.2 Use-After-Free via xmlTextReader | sparklemotion | nokogiri | Critical | 9.8 | 2026-08-25 15:15:57 | Deep Dive |
| CVE-2023-54354 | Nokogiri before 1.14.3 Null Pointer Dereference via libxml2 | sparklemotion | nokogiri | High | 7.5 | 2026-08-25 15:15:56 | Deep Dive |
| CVE-2022-51000 | Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt | sparklemotion | nokogiri | Critical | 9.8 | 2026-08-25 15:15:55 | Deep Dive |
| CVE-2022-50999 | Nokogiri before 1.13.5 Integer Overflow via libxml2 | sparklemotion | nokogiri | High | 8.6 | 2026-08-25 15:15:55 | Deep Dive |
| CVE-2022-50998 | Nokogiri before 1.13.9 Multiple Vulnerabilities via libxml2 | sparklemotion | nokogiri | High | 7.5 | 2026-08-25 15:15:54 | Deep Dive |
| CVE-2021-47996 | Nokogiri before 1.11.4 Multiple Vulnerabilities via libxml2 | sparklemotion | nokogiri | High | 7.5 | 2026-08-25 15:15:53 | Deep Dive |
| CVE-2026-55533 | PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret | MervinPraison | PraisonAI | High | 8.2 | 2026-08-25 15:15:35 | Deep Dive |
| CVE-2026-55539 | PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete | MervinPraison | PraisonAI | High | 8.6 | 2026-08-25 15:14:07 | Deep Dive |
| CVE-2026-69104 | Potential unauthorized repository migration in JFrog Artifactory | jfrog | artifactory | High | 7.6 | 2026-08-25 15:09:29 | Deep Dive |