| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73232🧪 | ffuf denial of service (OOM) via HTTP response decompression bomb | ffuf | ffuf | High | 7.5 | 2026-08-11 19:32:49 | Deep Dive |
| CVE-2026-73034 | DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header | eosphoros-ai | DB-GPT | Critical | 9.8 | 2026-08-11 19:31:49 | Deep Dive |
| CVE-2026-65655 | Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy | Temporal Technologies, Inc. | Temporal UI Server | Low | 2.3 | 2026-08-11 19:29:40 | Deep Dive |
| CVE-2026-73231🧪 | Faker: helpers.fake exploitable into arbritary code execution | faker-js | faker | High | 7.8 | 2026-08-11 19:28:45 | Deep Dive |
| CVE-2026-45618🧪 | LiquidJS is Vulnerable to Remote Code Execution | harttle | liquidjs | Critical | 10.0 | 2026-08-11 19:27:10 | Deep Dive |
| CVE-2026-71474 | Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | Medium | 6.3 | 2026-08-11 19:24:57 | Deep Dive |
| CVE-2026-48813🧪 | Flawfinder output manipulation via untrusted filenames and source text | david-a-wheeler | flawfinder | High | 8.7 | 2026-08-11 19:24:54 | Deep Dive |
| CVE-2026-71468 | Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | Medium | 5.3 | 2026-08-11 19:24:21 | Deep Dive |
| CVE-2026-71475 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | Medium | 5.0 | 2026-08-11 19:24:18 | Deep Dive |
| CVE-2026-71845 | Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault() | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | Medium | 6.3 | 2026-08-11 19:22:12 | Deep Dive |
| CVE-2026-71467 | Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | High | 7.5 | 2026-08-11 19:22:05 | Deep Dive |
| CVE-2026-73032🧪 | PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() | papersgpt | papersgpt-for-zotero | Critical | 9.6 | 2026-08-11 19:19:02 | Deep Dive |
| CVE-2026-70339 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft | Microsoft Edge (Chromium-based) | Medium | 5.4 | 2026-08-11 19:18:45 | Deep Dive |
| CVE-2026-48804🧪 | python-socketio: Binary attachment accumulation can cause denial of service | miguelgrinberg | python-socketio | High | 7.5 | 2026-08-11 19:17:54 | Deep Dive |
| CVE-2026-73230 | Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets | ente | ente | Medium | 5.9 | 2026-08-11 19:17:03 | Deep Dive |
| CVE-2026-73283 | OpenSSH 10.5前 restrict绕过隧道转发 | OpenBSD | OpenSSH | Low | 2.5 | 2026-08-11 19:15:24 | Deep Dive |
| CVE-2024-14042 | Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow | - | Open5GS | Medium | 6.3 | 2026-08-11 19:15:10 | Deep Dive |
| CVE-2026-73282 | OpenSSH 10.5前远程转发并发导致use-after-free | OpenBSD | OpenSSH | Medium | 4.8 | 2026-08-11 19:12:24 | Deep Dive |
| CVE-2026-73281 | OpenSSH<10.5:ssh-agent远程操作越权漏洞 | OpenBSD | OpenSSH | Low | 3.5 | 2026-08-11 19:10:33 | Deep Dive |
| CVE-2026-73031🧪 | telegram-search Stored XSS via v-html in MessageList.vue | GramSearch | telegram-search | High | 8.7 | 2026-08-11 19:02:51 | Deep Dive |