| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway OS Command Injection | Haiwell | Haiwell IoT Cloud HMI Gateway | Critical | 10.0 | 2026-08-14 18:20:49 | Deep Dive |
| CVE-2026-72970 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft | Microsoft Edge (Chromium-based) | High | 8.3 | 2026-08-14 18:06:03 | Deep Dive |
| CVE-2026-48528🧪 | Metacat has an unauthenticated SQL injection vulnerability | NCEAS | metacat | Critical | 9.8 | 2026-08-14 17:56:35 | Deep Dive |
| CVE-2026-12366 | Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal | zephyrproject | zephyr | High | 8.8 | 2026-08-14 17:52:07 | Deep Dive |
| CVE-2026-12365 | Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race | zephyrproject | zephyr | Medium | 5.8 | 2026-08-14 17:52:06 | Deep Dive |
| CVE-2026-12364 | Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service | zephyrproject | zephyr | High | 8.4 | 2026-08-14 17:52:05 | Deep Dive |
| CVE-2026-12363 | Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0 | zephyrproject | zephyr | Medium | 4.2 | 2026-08-14 17:52:04 | Deep Dive |
| CVE-2026-19682 | Command Injection | Tenable, Inc. | Security Center | Critical | 9.9 | 2026-08-14 17:51:56 | Deep Dive |
| CVE-2026-49263 | Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and parser desynchronization | capstone-engine | capstone | Low | 2.0 | 2026-08-14 17:49:37 | Deep Dive |
| CVE-2026-73850🧪 | Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function | emlog | emlog | High | 8.6 | 2026-08-14 17:46:26 | Deep Dive |
| CVE-2026-19681 | Command Injection | Tenable, Inc. | Security Center | Critical | 9.9 | 2026-08-14 17:45:38 | Deep Dive |
| CVE-2026-49282 | Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and process crashes | capstone-engine | capstone | Medium | 5.1 | 2026-08-14 17:44:45 | Deep Dive |
| CVE-2026-19680 | SQL Injection | Tenable, Inc. | Security Center | High | 7.1 | 2026-08-14 17:39:22 | Deep Dive |
| CVE-2026-73849🧪 | emlog allows unauthenticated reinstallation via `install.php?action=reinstall`. | emlog | emlog | Critical | 9.8 | 2026-08-14 17:37:20 | Deep Dive |
| CVE-2026-19679 | Improper Input Validation | Tenable, Inc. | Security Center | High | 8.8 | 2026-08-14 17:35:46 | Deep Dive |
| CVE-2026-73847 | Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover | emlog | emlog | Medium | 6.8 | 2026-08-14 17:33:03 | Deep Dive |
| CVE-2026-19847 | TOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 17:30:10 | Deep Dive |
| CVE-2026-19639 | Improper Access Control | Tenable, Inc. | Security Center | Medium | 4.3 | 2026-08-14 17:28:50 | Deep Dive |
| CVE-2026-19636 | Insuffucient Protections Lead to Brute Force | Tenable, Inc. | Security Center | Medium | 5.3 | 2026-08-14 17:24:22 | Deep Dive |
| CVE-2026-19846🧪 | TOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 17:15:09 | Deep Dive |