| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-57858 | Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID | Cal.com | Cal.com Self-Hosted (Cal.diy) | High | 8.9 | 2026-08-12 12:23:09 | Deep Dive |
| CVE-2026-70468 | FortiManager 7.2-7.6 绕过身份验证漏洞 | Fortinet | FortiManager | High | 8.1 | 2026-08-12 12:19:04 | Deep Dive |
| CVE-2026-26035 | FortiWeb多版本认证绕过漏洞 | Fortinet | FortiWeb | Critical | 9.8 | 2026-08-12 12:19:03 | Deep Dive |
| CVE-2026-71407 | FortiOS 7.6.1-7.6.6栈溢出漏洞 | Fortinet | FortiOS | Medium | 5.6 | 2026-08-12 12:19:03 | Deep Dive |
| CVE-2026-70466 | FortiWeb越权访问漏洞 | Fortinet | FortiWeb | Medium | 5.3 | 2026-08-12 12:19:03 | Deep Dive |
| CVE-2026-70467 | FortiSIEM多个版本SSRF漏洞 | Fortinet | FortiSIEM | Low | 3.8 | 2026-08-12 12:19:02 | Deep Dive |
| CVE-2026-71408 | FortiOS资源耗尽致DoS漏洞(7.4/7.2/7.6.0-7.6.6) | Fortinet | FortiOS | Medium | 5.3 | 2026-08-12 12:19:00 | Deep Dive |
| CVE-2026-70465 | FortiClient Windows 7.2.x-7.4.x 缓冲区溢出漏洞 | Fortinet | FortiClientWindows | High | 8.1 | 2026-08-12 11:52:26 | Deep Dive |
| CVE-2026-11325🧪 | cloudflare/pages-action is deprecated — migration required by September 18th, 2026 | Cloudflare | https://github.com/cloudflare/pages-action | High | 8.8 | 2026-08-12 11:31:15 | Deep Dive |
| CVE-2026-18044 | Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch | Unknown | Estatik Real Estate Plugin | Low | 3.7 | 2026-08-12 11:24:03 | Deep Dive |
| CVE-2026-17008 | Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN | Unknown | Quick Paypal Payments | Medium | 5.3 | 2026-08-12 11:24:02 | Deep Dive |
| CVE-2026-16990 | Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation | Unknown | Payment Button for PayPal | Medium | 5.3 | 2026-08-12 11:24:01 | Deep Dive |
| CVE-2026-16747 | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions | Unknown | Kirki | Medium | 6.5 | 2026-08-12 11:24:00 | Deep Dive |
| CVE-2026-15213 | Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback | Unknown | Welcart e-Commerce | Medium | 5.3 | 2026-08-12 11:23:59 | Deep Dive |
| CVE-2026-16621 | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler | Unknown | Payment Gateway for PayPal on WooCommerce | Medium | 5.3 | 2026-08-12 11:23:59 | Deep Dive |
| CVE-2026-15045 | Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount | Unknown | Wallet System for WooCommerce | Medium | 6.5 | 2026-08-12 11:23:58 | Deep Dive |
| CVE-2026-70560 | Ultimate POS Stored XSS via First Name Field in Leave Notifications | Ultimate Fosters | Ultimate POS (Stock Management & Point of Sale) | Medium | 5.4 | 2026-08-12 11:17:17 | Deep Dive |
| CVE-2026-68868 | Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables | Apache Software Foundation | Apache Airflow Google provider | - | - | 2026-08-12 10:27:56 | Deep Dive |
| CVE-2026-67284 | Joomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Cloud < 2.0.2 | tabaoca.org | Cotton Cloud extension for Joomla | Medium | 5.3 | 2026-08-12 09:58:46 | Deep Dive |
| CVE-2026-18652 | Velociraptor STACK Type Download Path Bypasses Denied Prefix Check | Rapid7 | Velociraptor | Medium | 4.9 | 2026-08-12 09:56:10 | Deep Dive |