| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19292 | Bluetooth re-pairing with legitimate device can use lower security level | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:17:18 | Deep Dive |
| CVE-2026-19291 | Bluetooth re-pairing can use a lower security level than previous | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:16:28 | Deep Dive |
| CVE-2026-16101 | forced re-pairing with already bonded device | silabs.com | WiseConnect | High | 8.8 | 2026-08-13 14:15:40 | Deep Dive |
| CVE-2026-19734🧪 | IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking | Roskus | Prospero Flow CRM | High | 8.6 | 2026-08-13 14:04:56 | Deep Dive |
| CVE-2026-68454 | KVM: s390: pci: Fix handling of AIF enable without AISB | Linux | Linux | High | 8.8 | 2026-08-13 13:59:57 | Deep Dive |
| CVE-2026-68453 | s390/zcrypt: Fix buffer over-read in cca_cipher2protkey | Linux | Linux | High | 7.1 | 2026-08-13 13:59:56 | Deep Dive |
| CVE-2026-68452 | s390/zcrypt: Validate length for CCA AES cipher key requests | Linux | Linux | High | 7.8 | 2026-08-13 13:59:55 | Deep Dive |
| CVE-2026-68451 | s390/zcrypt: Validate length for CCA ECC private key requests | Linux | Linux | High | 7.8 | 2026-08-13 13:59:54 | Deep Dive |
| CVE-2026-14456 | Unbounded Memory Growth in QUIC Server Incoming Channel Queue | OpenSSL | OpenSSL | - | - | 2026-08-13 13:55:52 | Deep Dive |
| CVE-2026-66256 | Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API) | Apache Software Foundation | Apache Shindig Common | - | - | 2026-08-13 13:53:35 | Deep Dive |
| CVE-2026-28002 | WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability | Arraytics | Booktics | High | 8.5 | 2026-08-13 13:42:09 | Deep Dive |
| CVE-2026-73403 | WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability | wpeverest | User Registration | Medium | 5.3 | 2026-08-13 13:37:26 | Deep Dive |
| CVE-2026-73401 | WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability | InstaWP | InstaWP Connect | Medium | 5.3 | 2026-08-13 13:37:25 | Deep Dive |
| CVE-2026-73353 | WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulnerability | revolutbusiness | Revolut Gateway for WooCommerce | Medium | 5.3 | 2026-08-13 13:37:24 | Deep Dive |
| CVE-2026-73357 | WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability | Nexcess | GiveWP | Medium | 6.5 | 2026-08-13 13:37:24 | Deep Dive |
| CVE-2026-73349 | WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability | Nexcess | GiveWP | Medium | 5.3 | 2026-08-13 13:37:23 | Deep Dive |
| CVE-2026-73346 | WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability | Mailchimp | MailChimp For WooCommerce | High | 7.6 | 2026-08-13 13:37:23 | Deep Dive |
| CVE-2026-73344 | WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability | Passionate Programmer Peter | WP Data Access | Medium | 5.9 | 2026-08-13 13:37:22 | Deep Dive |
| CVE-2026-73340 | WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability | fifu.app | Featured Image from URL | Medium | 6.5 | 2026-08-13 13:37:21 | Deep Dive |
| CVE-2026-66704 | WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability | Jegstudio | Gutenverse Companion | High | 7.2 | 2026-08-13 13:37:20 | Deep Dive |