| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-72817 | go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For | go-chi | chi | Medium | 6.5 | 2026-08-14 11:35:29 | Deep Dive |
| CVE-2026-72816 | go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware | go-chi | chi | Medium | 6.5 | 2026-08-14 11:35:28 | Deep Dive |
| CVE-2026-72814 | actix-web before 0.6.10 Information Disclosure via Files | actix | actix-web | Medium | 6.3 | 2026-08-14 11:35:27 | Deep Dive |
| CVE-2026-72815 | go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header | go-chi | chi | Medium | 6.9 | 2026-08-14 11:35:27 | Deep Dive |
| CVE-2026-72813 | actix-files before 0.6.10 Denial of Service via empty Range header | actix | actix-web | Medium | 6.9 | 2026-08-14 11:35:26 | Deep Dive |
| CVE-2026-72812 | SiYuan before v3.7.4 Missing Authorization via refreshBacklink | siyuan-note | siyuan | Medium | 6.5 | 2026-08-14 11:35:25 | Deep Dive |
| CVE-2026-72811 | SiYuan before v3.7.4 SQL Injection via backlink search | siyuan-note | siyuan | Critical | 10.0 | 2026-08-14 11:35:25 | Deep Dive |
| CVE-2026-72810 | SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket | siyuan-note | siyuan | High | 8.6 | 2026-08-14 11:35:24 | Deep Dive |
| CVE-2025-71405 | go-chi chi before v5.2.2 Open Redirect via RedirectSlashes | go-chi | chi | Medium | 5.1 | 2026-08-14 11:35:23 | Deep Dive |
| CVE-2026-19822🧪 | Tenda W20E QoS Edit editQos lstAdd stack-based overflow | Tenda | W20E | High | 8.8 | 2026-08-14 11:30:12 | Deep Dive |
| CVE-2026-19821🧪 | Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow | Tenda | AC12 | High | 8.8 | 2026-08-14 11:00:11 | Deep Dive |
| CVE-2026-19815🧪 | TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 08:30:10 | Deep Dive |
| CVE-2026-19814🧪 | TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 08:15:10 | Deep Dive |
| CVE-2026-19813🧪 | TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 08:00:11 | Deep Dive |
| CVE-2026-19794 | WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting | gamerz | WP-Stats | High | 7.2 | 2026-08-14 07:39:29 | Deep Dive |
| CVE-2026-19812🧪 | TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 07:30:10 | Deep Dive |
| CVE-2026-19811🧪 | TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow | TOTOLINK | A800R | High | 8.8 | 2026-08-14 06:15:11 | Deep Dive |
| CVE-2026-18039 | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment | Unknown | Essential Addons for Elementor | - | - | 2026-08-14 06:00:12 | Deep Dive |
| CVE-2026-15205 | Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup | Unknown | Paymob for WooCommerce | - | - | 2026-08-14 06:00:11 | Deep Dive |
| CVE-2026-16739 | Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery | Unknown | Epeken All Kurir for Woocommerce | - | - | 2026-08-14 06:00:11 | Deep Dive |