| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73509🧪 | OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal | OpenListTeam | OpenList | High | 7.6 | 2026-08-13 14:31:05 | Deep Dive |
| CVE-2026-73508 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names | netty | netty | Medium | 5.3 | 2026-08-13 14:27:20 | Deep Dive |
| CVE-2026-65936 | RS9116W/SiWx917 malformed packet with increased length field causes memory leak | silabs.com | WiseConnect | Medium | 5.3 | 2026-08-13 14:26:23 | Deep Dive |
| CVE-2026-28154 | WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability | snstheme | Samex - Clean, Minimal Shop WooCommerce WordPress Theme | High | 7.1 | 2026-08-13 14:25:55 | Deep Dive |
| CVE-2026-73507🧪 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion | netty | netty | High | 7.5 | 2026-08-13 14:25:34 | Deep Dive |
| CVE-2026-65935 | Bypassing passkey entry in legacy pairing | silabs.com | WiseConnect | High | 7.6 | 2026-08-13 14:24:08 | Deep Dive |
| CVE-2026-73506 | Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data | JanDeDobbeleer | oh-my-posh | Medium | 6.1 | 2026-08-13 14:23:02 | Deep Dive |
| CVE-2026-65934 | BT122 plaintext pause encryption request causes DOS | silabs.com | BT122 | High | 7.1 | 2026-08-13 14:23:00 | Deep Dive |
| CVE-2026-65933 | BT122 malformed packet with increased length field causes memory leak | silabs.com | BT122 | Medium | 5.3 | 2026-08-13 14:22:18 | Deep Dive |
| CVE-2026-73505🧪 | Oh My Posh: Arbitrary command execution via template injection in the path segment | JanDeDobbeleer | oh-my-posh | High | 7.8 | 2026-08-13 14:21:57 | Deep Dive |
| CVE-2026-65932 | BT122 stops advertising | silabs.com | BT122 | Medium | 5.3 | 2026-08-13 14:20:47 | Deep Dive |
| CVE-2026-19293 | SMP security request | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:18:05 | Deep Dive |
| CVE-2026-19292 | Bluetooth re-pairing with legitimate device can use lower security level | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:17:18 | Deep Dive |
| CVE-2026-19291 | Bluetooth re-pairing can use a lower security level than previous | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:16:28 | Deep Dive |
| CVE-2026-16101 | forced re-pairing with already bonded device | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:15:40 | Deep Dive |
| CVE-2026-19734🧪 | IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking | Roskus | Prospero Flow CRM | High | 8.6 | 2026-08-13 14:04:56 | Deep Dive |
| CVE-2026-68454 | KVM: s390: pci: Fix handling of AIF enable without AISB | Linux | Linux | High | 8.8 | 2026-08-13 13:59:57 | Deep Dive |
| CVE-2026-68453 | s390/zcrypt: Fix buffer over-read in cca_cipher2protkey | Linux | Linux | High | 7.1 | 2026-08-13 13:59:56 | Deep Dive |
| CVE-2026-68452 | s390/zcrypt: Validate length for CCA AES cipher key requests | Linux | Linux | High | 7.8 | 2026-08-13 13:59:55 | Deep Dive |
| CVE-2026-68451 | s390/zcrypt: Validate length for CCA ECC private key requests | Linux | Linux | High | 7.8 | 2026-08-13 13:59:54 | Deep Dive |