| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73238 | Apache Allura: XSS in code display | Apache Software Foundation | Apache Allura | - | - | 2026-08-12 16:41:59 | Deep Dive |
| CVE-2026-73239 | Apache Allura: Missing permission checks IDOR | Apache Software Foundation | Apache Allura | - | - | 2026-08-12 16:41:41 | Deep Dive |
| CVE-2026-73240 | Apache Allura: Git command injection | Apache Software Foundation | Apache Allura | - | - | 2026-08-12 16:41:19 | Deep Dive |
| CVE-2026-48552 | Nagios Core / XI DOM-based XSS via jsonquery.js | Nagios Enterprises, LLC. | Nagios Core | Medium | 5.4 | 2026-08-12 16:34:34 | Deep Dive |
| CVE-2026-48551🧪 | Nagios Core / XI CSRF Protection Bypass via Double-Submit Cookie | Nagios Enterprises, LLC. | Nagios Core | High | 7.4 | 2026-08-12 16:32:17 | Deep Dive |
| CVE-2026-73297 | Microsoft UFO: IPv6 transition address bypass of SSRF guard in URL validation | microsoft | UFO | Medium | 6.9 | 2026-08-12 16:31:35 | Deep Dive |
| CVE-2026-48550 | Nagios Core / XI cmd.cgi Reflected XSS via NagFormId Parameter | Nagios Enterprises, LLC. | Nagios Core | Medium | 6.1 | 2026-08-12 16:30:02 | Deep Dive |
| CVE-2026-73296🧪 | Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure | microsoft | UFO | Critical | 9.4 | 2026-08-12 16:29:03 | Deep Dive |
| CVE-2026-18499 | IBM WebSphere Application Server Liberty is affected by a privilege escalation | IBM | WebSphere Application Server - Liberty | High | 8.1 | 2026-08-12 16:25:07 | Deep Dive |
| CVE-2026-73295 | Material for MkDocs: DOM XSS in search suggestions via query parameter | squidfunk | mkdocs-material | Medium | 5.4 | 2026-08-12 16:15:22 | Deep Dive |
| CVE-2026-73294🧪 | Semaphore U: OS Command Injection | semaphoreui | semaphore | Critical | 9.9 | 2026-08-12 15:55:01 | Deep Dive |
| CVE-2026-69107 | Potential unauthorized artifact access in JFrog Artifactory | jfrog | artifactory | Medium | 5.9 | 2026-08-12 15:51:48 | Deep Dive |
| CVE-2026-19548 | Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing | Red Hat | Red Hat Enterprise Linux 10 | Medium | 5.5 | 2026-08-12 15:51:39 | Deep Dive |
| CVE-2026-73293🧪 | Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision | semaphoreui | semaphore | High | 8.8 | 2026-08-12 15:45:22 | Deep Dive |
| CVE-2026-59244 | Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI | Apache Software Foundation | Apache Airflow | - | - | 2026-08-12 15:43:17 | Deep Dive |
| CVE-2026-58076 | Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server | Apache Software Foundation | Apache Airflow | - | - | 2026-08-12 15:41:00 | Deep Dive |
| CVE-2026-15803 | Eclipse RDF4J XXE漏洞(CVE-2018-1000644) | Eclipse Foundation | Eclipse RDF4J | High | 8.7 | 2026-08-12 15:38:31 | Deep Dive |
| CVE-2026-73325 | Fujitsu OneCompression 1.2.0 Arbitrary Code Execution via torch.load Deserialization | Fujitsu Research | OneCompression | High | 7.8 | 2026-08-12 15:35:51 | Deep Dive |
| CVE-2026-59242 | Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint | Apache Software Foundation | Apache Airflow | - | - | 2026-08-12 15:35:01 | Deep Dive |
| CVE-2026-73292🧪 | Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation | semaphoreui | semaphore | High | 8.3 | 2026-08-12 15:34:46 | Deep Dive |