| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19556 | Google Chrome < 151.0.7922.137 V8堆释放后使用漏洞 | Chrome | - | - | 2026-08-11 21:23:53 | Deep Dive | |
| CVE-2026-19557 | Chrome <151.0.7922.137 Mac UAF导致沙箱逃逸 | Chrome | - | - | 2026-08-11 21:23:53 | Deep Dive | |
| CVE-2026-68067 | Mira Hormone Monitor, Mira Android App Weak Authentication | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | Critical | 9.8 | 2026-08-11 21:23:06 | Deep Dive |
| CVE-2026-66340 | Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | Medium | 5.3 | 2026-08-11 21:20:58 | Deep Dive |
| CVE-2026-64934 | Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | Medium | 4.3 | 2026-08-11 21:15:13 | Deep Dive |
| CVE-2026-48763 | TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath | baptisteArno | typebot.io | High | 8.2 | 2026-08-11 20:51:25 | Deep Dive |
| CVE-2026-66832 | Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings | Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | Medium | 6.5 | 2026-08-11 20:49:57 | Deep Dive |
| CVE-2026-19550 | Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes | Red Hat | Red Hat Enterprise Linux 10 | Medium | 4.3 | 2026-08-11 20:46:42 | Deep Dive |
| CVE-2026-14863 | FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection | FileRun | FileRun | High | 8.8 | 2026-08-11 20:41:36 | Deep Dive |
| CVE-2026-48762 | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler | baptisteArno | typebot.io | Medium | 5.4 | 2026-08-11 20:40:32 | Deep Dive |
| CVE-2026-48765 | TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding | baptisteArno | typebot.io | Critical | 9.9 | 2026-08-11 20:37:48 | Deep Dive |
| CVE-2026-71290 | Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) | Apache Software Foundation | Apache HttpComponents Client | - | - | 2026-08-11 20:33:57 | Deep Dive |
| CVE-2026-63177🧪 | Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC | cisagov | Malcolm | High | 7.1 | 2026-08-11 20:30:58 | Deep Dive |
| CVE-2026-63134 | Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation | cisagov | Malcolm | Medium | 5.4 | 2026-08-11 20:29:39 | Deep Dive |
| CVE-2026-15606 | Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token | shabti | Frontend Admin by DynamiApps | High | 8.8 | 2026-08-11 20:26:11 | Deep Dive |
| CVE-2026-63133 | Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) | cisagov | Malcolm | Medium | 6.5 | 2026-08-11 20:26:06 | Deep Dive |
| CVE-2026-19579 | Snipe-IT Checkout Request Cancellation IDOR | Grokability | Snipe-IT | Medium | 5.4 | 2026-08-11 20:25:02 | Deep Dive |
| CVE-2026-55676🧪 | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component | cisagov | Malcolm | High | 8.8 | 2026-08-11 20:24:51 | Deep Dive |
| CVE-2026-66150 | SonicWall Email Security代码注入漏洞 | SonicWall | Email Security | - | - | 2026-08-11 20:19:34 | Deep Dive |
| CVE-2026-66149 | SonicWall Email Security CLI代码注入漏洞 | SonicWall | Email Security | - | - | 2026-08-11 20:18:25 | Deep Dive |