| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-12128 | Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter | dotonpaper | Pinpoint Booking System – Version 2 | Medium | 5.3 | 2026-08-15 02:26:18 | Deep Dive |
| CVE-2026-15303 | 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter | sixstorage | 6Storage Rentals | Critical | 9.8 | 2026-08-15 02:26:17 | Deep Dive |
| CVE-2026-8840 | Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action | wpdevart | Booking calendar, Appointment Booking System | Medium | 5.3 | 2026-08-15 02:26:17 | Deep Dive |
| CVE-2026-15965 | MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter | sadathimel | MaxUpload – Big File Uploads – Increase Maximum File Upload Size | High | 8.8 | 2026-08-15 02:26:16 | Deep Dive |
| CVE-2026-15312 | Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter | fassionstorage | Propovoice: All-in-One Client Management System | High | 8.8 | 2026-08-15 02:26:16 | Deep Dive |
| CVE-2026-15162 | Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection | minnpost | Object Sync for Salesforce | High | 7.5 | 2026-08-15 02:26:16 | Deep Dive |
| CVE-2026-16080 | Image Uploader for Welcart <= 1.4.6 - Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter | fishpie | Image Uploader for Welcart | Medium | 6.5 | 2026-08-15 02:26:15 | Deep Dive |
| CVE-2026-14484 | RapiSafe <= 1.0.4 - Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters | pietror91 | RapiSafe – Secure Multi File Upload for Contact Form 7 | Critical | 9.1 | 2026-08-15 02:26:15 | Deep Dive |
| CVE-2026-14433 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | High | 7.2 | 2026-08-15 02:26:15 | Deep Dive |
| CVE-2026-74250 | OpenStack Ironic<38.0.1自动检测部署接口缺陷 | OpenStack | Ironic | Medium | 6.3 | 2026-08-14 22:53:18 | Deep Dive |
| CVE-2026-74247 | Quay: ssrf via build archive_url in quay build api | Red Hat | Red Hat OpenShift Update Service | Medium | 4.2 | 2026-08-14 22:43:15 | Deep Dive |
| CVE-2026-74245 | Quay: unauthenticated exported logs download in quay | Red Hat | Red Hat OpenShift Update Service | Medium | 5.9 | 2026-08-14 22:43:11 | Deep Dive |
| CVE-2026-74244 | Quay: stripe webhook accepts forged events without signature verification in quay | Red Hat | Red Hat OpenShift Update Service | Medium | 5.9 | 2026-08-14 22:43:06 | Deep Dive |
| CVE-2026-74243 | Quay: unauthenticated secscan notification endpoint in quay when psk is unset | Red Hat | Red Hat OpenShift Update Service | Medium | 6.5 | 2026-08-14 22:43:06 | Deep Dive |
| CVE-2026-74242 | Quay: repository notification uuid idor in quay api | Red Hat | Red Hat OpenShift Update Service | Medium | 5.3 | 2026-08-14 22:43:04 | Deep Dive |
| CVE-2026-74241 | Quay: ldap referral filter injection in quay external ldap authentication | Red Hat | Red Hat OpenShift Update Service | Medium | 4.8 | 2026-08-14 22:43:02 | Deep Dive |
| CVE-2026-74240 | Quay: jwt claim validation bypasses in quay federated robot and sso authentication | Red Hat | Red Hat OpenShift Update Service | Medium | 5.4 | 2026-08-14 22:43:01 | Deep Dive |
| CVE-2026-63650 | OpenVPN 2.7.x身份认证漏洞 | OpenVPN | OpenVPN | Low | 2.0 | 2026-08-14 22:13:27 | Deep Dive |
| CVE-2026-63649 | OpenVPN多个版本存在配置文件绕过漏洞 | OpenVPN | OpenVPN | Medium | 4.1 | 2026-08-14 22:13:22 | Deep Dive |
| CVE-2026-69414 | Microsoft Defender Elevation of Privilege Vulnerability | Microsoft | Microsoft Malware Protection Engine | High | 7.8 | 2026-08-14 21:50:59 | Deep Dive |