| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-73845 | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) | ondata | ckan-mcp-server | Medium | 5.3 | 2026-08-14 16:45:07 | Deep Dive |
| CVE-2026-73844 | CKAN MCP Server: Information disclosure via verbose error reflection | ondata | ckan-mcp-server | Low | 3.7 | 2026-08-14 16:41:43 | Deep Dive |
| CVE-2026-47192 | kas's late signature validation may allow unnoticed repository manipulations | siemens | kas | Low | 2.1 | 2026-08-14 16:41:28 | Deep Dive |
| CVE-2026-46603 | Excessive memory allocation during VP8L decoding in golang.org/x/image | golang.org/x/image | golang.org/x/image/vp8l | - | - | 2026-08-14 16:38:17 | Deep Dive |
| CVE-2026-47191 | kas checks out SHA-like git branches as valid commits | siemens | kas | Low | 2.1 | 2026-08-14 16:35:48 | Deep Dive |
| CVE-2026-19841 | TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission | TRENDNET | TEW-813DRU | Low | 3.1 | 2026-08-14 16:30:07 | Deep Dive |
| CVE-2026-49989 | CrateDB's Blob HTTP handler bypasses authorization | crate | crate | High | 7.1 | 2026-08-14 16:29:17 | Deep Dive |
| CVE-2026-49826 | Concourse login flow has an open redirect issue | concourse | concourse | None | 0.0 | 2026-08-14 16:25:56 | Deep Dive |
| CVE-2026-49986🧪 | Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` | cdeust | Cortex | High | 7.1 | 2026-08-14 16:21:39 | Deep Dive |
| CVE-2026-47766 | crun follows rootfs /dev symlink while creating default devices | containers | crun | Medium | 5.1 | 2026-08-14 16:16:38 | Deep Dive |
| CVE-2026-19839 | SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload | SourceCodester | Simple Doctors Appointment System | Medium | 4.7 | 2026-08-14 16:15:08 | Deep Dive |
| CVE-2026-46380 | compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem | oscal-compass | compliance-trestle | Medium | 6.7 | 2026-08-14 16:10:14 | Deep Dive |
| CVE-2026-46439🧪 | compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) | oscal-compass | compliance-trestle | High | 7.8 | 2026-08-14 16:08:09 | Deep Dive |
| CVE-2026-19838 | Webkul Bagisto Backend Reporting Endpoint sales authorization | Webkul | Bagisto | Medium | 4.3 | 2026-08-14 16:00:07 | Deep Dive |
| CVE-2026-19837 | Webkul Bagisto Customer Search search information disclosure | Webkul | Bagisto | Low | 2.7 | 2026-08-14 15:45:06 | Deep Dive |
| CVE-2026-63700 | Dell Wyse Management Suite 权限提升漏洞 | Dell | Wyse Management Suite (WMS) | High | 7.8 | 2026-08-14 15:41:24 | Deep Dive |
| CVE-2026-66271 | Dell Wyse Management Suite < 2605.0.2 远程代码执行漏洞 | Dell | Wyse Management Suite (WMS) | High | 7.2 | 2026-08-14 15:39:10 | Deep Dive |
| CVE-2026-66270 | Dell Wyse Management Suite <2605.0.2 任意文件上传致RCE | Dell | Wyse Management Suite (WMS) | High | 7.2 | 2026-08-14 15:36:57 | Deep Dive |
| CVE-2026-66272 | Dell Wyse Management Suite 早期版本存在关键功能缺身份验证漏洞致信息泄露 | Dell | Wyse Management Suite (WMS) | Medium | 5.3 | 2026-08-14 15:34:28 | Deep Dive |
| CVE-2026-19884🧪 | CVE-2026-19884 | Eclipse Foundation | Eclipse Theia | High | 8.4 | 2026-08-14 15:32:39 | Deep Dive |