| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-1621 | Register Bypass in Universal Sotware's E-Municipality | Universal Software Inc. | E-Municipality | Medium | 5.3 | 2026-08-14 14:08:37 | Deep Dive |
| CVE-2026-19871🧪 | Use of hard-coded credentials in Prospero Flow CRM employee onboarding | Roskus | Prospero Flow CRM | Critical | 9.3 | 2026-08-14 14:00:56 | Deep Dive |
| CVE-2026-53472 | Migration-planner: credentialurl validator accepts javascript: urls | - | - | Medium | 6.3 | 2026-08-14 14:00:33 | Deep Dive |
| CVE-2026-19830 | TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources | TRENDnet | TEW-816DRM | Medium | 5.3 | 2026-08-14 14:00:12 | Deep Dive |
| CVE-2026-73633 | Apache Struts: Unbounded read of a JSON request body | Apache Software Foundation | Apache Struts | - | - | 2026-08-14 13:48:45 | Deep Dive |
| CVE-2026-19768 | ReDOS漏洞影响Devolutions PowerShell Universal 2026.2.3 | Devolutions | PowerShell Universal | - | - | 2026-08-14 13:48:04 | Deep Dive |
| CVE-2026-19829 | 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal | 648540858 | wvp-GB28181-pro | Medium | 4.3 | 2026-08-14 13:45:09 | Deep Dive |
| CVE-2026-19828 | 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal | 648540858 | wvp-GB28181-pro | Medium | 6.3 | 2026-08-14 13:30:10 | Deep Dive |
| CVE-2026-19827 | alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal | alldatacenter | alldata | Medium | 5.3 | 2026-08-14 13:15:09 | Deep Dive |
| CVE-2026-19826🧪 | alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization | alldatacenter | alldata | High | 7.3 | 2026-08-14 13:00:09 | Deep Dive |
| CVE-2026-19825🧪 | SourceCodester Simple Client Management System Master.php save_service sql injection | SourceCodester | Simple Client Management System | High | 7.3 | 2026-08-14 12:45:09 | Deep Dive |
| CVE-2026-19824🧪 | Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow | Tenda | W20E | High | 8.8 | 2026-08-14 12:30:10 | Deep Dive |
| CVE-2026-73673🧪 | Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication | Netis Systems Co., Ltd. | Netis NC63 Wireless AC1200 Router | High | 8.8 | 2026-08-14 12:21:06 | Deep Dive |
| CVE-2026-19823🧪 | Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow | Tenda | W20E | High | 8.8 | 2026-08-14 12:15:10 | Deep Dive |
| CVE-2026-19870🧪 | IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation | Roskus | Prospero Flow CRM | High | 8.6 | 2026-08-14 12:08:30 | Deep Dive |
| CVE-2026-73630 | SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess | siyuan-note | siyuan | Medium | 5.8 | 2026-08-14 11:35:46 | Deep Dive |
| CVE-2026-73051 | actix-http before 3.12.1 HTTP Request Smuggling via CL.TE | actix | actix-web | Medium | 6.3 | 2026-08-14 11:35:46 | Deep Dive |
| CVE-2026-73049 | SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks | siyuan-note | siyuan | Medium | 5.8 | 2026-08-14 11:35:45 | Deep Dive |
| CVE-2026-72859🧪 | Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL | budibase | server | High | 7.7 | 2026-08-14 11:35:44 | Deep Dive |
| CVE-2026-73048 | SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID | siyuan-note | siyuan | Medium | 5.8 | 2026-08-14 11:35:44 | Deep Dive |