| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-78581 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana | Elastic | Kibana | Medium | 4.2 | 2026-08-25 13:08:12 | Deep Dive |
| CVE-2026-75803 | AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() | OpenSSL | OpenSSL | - | - | 2026-08-25 13:00:25 | Deep Dive |
| CVE-2026-63076 | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg | OpenSSL | OpenSSL | - | - | 2026-08-25 13:00:11 | Deep Dive |
| CVE-2026-79406 | macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error | macrozheng | mall | Medium | 4.3 | 2026-08-25 13:00:10 | Deep Dive |
| CVE-2026-63075 | QUIC ACK-only Packet Retention Can Cause Memory Exhaustion | OpenSSL | OpenSSL | - | - | 2026-08-25 13:00:05 | Deep Dive |
| CVE-2026-63074 | CMP Indefinite Cache Growth of ExtraCerts | OpenSSL | OpenSSL | - | - | 2026-08-25 12:59:58 | Deep Dive |
| CVE-2026-63073 | Untrusted Sender DN Used as Format String in CMP Response Validation | OpenSSL | OpenSSL | - | - | 2026-08-25 12:59:43 | Deep Dive |
| CVE-2026-63072 | Heap Buffer Overflow in CMS Key Unwrapping | OpenSSL | OpenSSL | - | - | 2026-08-25 12:59:34 | Deep Dive |
| CVE-2026-54874 | Excessive Memory Use Buffering DTLS Records for a Future Epoch | OpenSSL | OpenSSL | - | - | 2026-08-25 12:59:18 | Deep Dive |
| CVE-2026-18798 | QUIC Server May Trigger Double Free When Processing INITIAL Packet | OpenSSL | OpenSSL | - | - | 2026-08-25 12:59:05 | Deep Dive |
| CVE-2026-14457 | RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate | OpenSSL | OpenSSL | - | - | 2026-08-25 12:58:29 | Deep Dive |
| CVE-2026-57863 | Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint | crater-invoice-inc | crater | High | 8.8 | 2026-08-25 12:52:12 | Deep Dive |
| CVE-2026-77998 | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 | miniorange.com | SAML SSO Free for Joomla extension for Joomla | Critical | 10.0 | 2026-08-25 12:50:47 | Deep Dive |
| CVE-2026-78887 | liketrek TREK Journey Photo Proxy validateShareTokenForAsset authorization | liketrek | TREK | Low | 3.7 | 2026-08-25 12:45:11 | Deep Dive |
| CVE-2026-78886 | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | liketrek | TREK | Low | 3.7 | 2026-08-25 12:30:09 | Deep Dive |
| CVE-2026-78885 | liketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authentication | liketrek | TREK | Medium | 5.6 | 2026-08-25 12:15:09 | Deep Dive |
| CVE-2026-77997 | Joomla Extension - yootheme.com - Authenticated, privileged information disclosure about site modules YOOtheme Pro 1.0.0-5.0.40 | yootheme.com | YOOtheme Pro extension for Joomla | Medium | 5.1 | 2026-08-25 11:53:22 | Deep Dive |
| CVE-2026-77996 | Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 | yootheme.com | YOOtheme Pro extension for Joomla | High | 7.5 | 2026-08-25 11:52:17 | Deep Dive |
| CVE-2026-57910 | WatchGuard Agent improper authentication allows unauthenticated remote code execution | WatchGuard | WatchGuard Agent | Critical | 9.3 | 2026-08-25 11:47:49 | Deep Dive |
| CVE-2026-57909 | WatchGuard Agent path traversal allows unauthenticated remote code execution | WatchGuard | WatchGuard Agent | Critical | 9.4 | 2026-08-25 11:47:03 | Deep Dive |