| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-68460 | f2fs: fix potential deadlock in f2fs_balance_fs() | Linux | Linux | - | - | 2026-08-15 05:51:20 | Deep Dive |
| CVE-2026-68458 | binder: cache secctx size before release zeroes it | Linux | Linux | - | - | 2026-08-15 05:51:19 | Deep Dive |
| CVE-2026-68457 | ksmbd: use opener credentials for FSCTL mutations | Linux | Linux | - | - | 2026-08-15 05:51:18 | Deep Dive |
| CVE-2026-68455 | liveupdate: validate session type before performing operation | Linux | Linux | - | - | 2026-08-15 05:51:17 | Deep Dive |
| CVE-2026-68456 | usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() | Linux | Linux | - | - | 2026-08-15 05:51:17 | Deep Dive |
| CVE-2026-16007 | Authenticated SQL Injection in AppFlowy | AppFlowy-IO | AppFlowy-Cloud | High | 7.1 | 2026-08-15 05:21:17 | Deep Dive |
| CVE-2026-16145 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scripting via 'action' Parameter | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | High | 7.2 | 2026-08-15 03:26:00 | Deep Dive |
| CVE-2026-13360 | Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter | wplegalpages | WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode | High | 7.2 | 2026-08-15 03:26:00 | Deep Dive |
| CVE-2026-15948 | Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter | themefic | Hydra Booking — Appointment Scheduling & Booking Calendar | Medium | 6.4 | 2026-08-15 03:25:59 | Deep Dive |
| CVE-2026-15453 | KiviCare <= 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | Medium | 6.5 | 2026-08-15 03:25:59 | Deep Dive |
| CVE-2026-16146 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | Medium | 4.9 | 2026-08-15 03:25:59 | Deep Dive |
| CVE-2026-16586 | Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' | contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | Medium | 6.5 | 2026-08-15 03:25:58 | Deep Dive |
| CVE-2026-16094 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection via 'key' Parameter | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | Medium | 4.9 | 2026-08-15 03:25:58 | Deep Dive |
| CVE-2026-15993 | Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | Medium | 5.3 | 2026-08-15 03:25:57 | Deep Dive |
| CVE-2026-18387 | Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | Medium | 6.5 | 2026-08-15 03:25:57 | Deep Dive |
| CVE-2026-17090 | Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2026-08-15 03:25:57 | Deep Dive |
| CVE-2026-15341 | User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters | rafasashi | User Session Synchronizer | Critical | 9.8 | 2026-08-15 02:26:18 | Deep Dive |
| CVE-2026-15001 | bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings | connectordev | bLoyal: Loyalty & Promotions by bLoyal | High | 8.8 | 2026-08-15 02:26:18 | Deep Dive |
| CVE-2026-12128 | Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter | dotonpaper | Pinpoint Booking System – Version 2 | Medium | 5.3 | 2026-08-15 02:26:18 | Deep Dive |
| CVE-2026-15303 | 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter | sixstorage | 6Storage Rentals | Critical | 9.8 | 2026-08-15 02:26:17 | Deep Dive |