| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-14290 | Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute | Unknown | Embed Google Photos album | - | - | 2026-08-14 06:00:11 | Deep Dive |
| CVE-2026-19617 | Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | Red Hat | Red Hat Enterprise Linux 10 | Medium | 5.5 | 2026-08-14 05:59:30 | Deep Dive |
| CVE-2026-12949 | Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter | Wishlist Member | Wishlist Member | Critical | 9.8 | 2026-08-14 05:30:44 | Deep Dive |
| CVE-2026-12743 | affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter | cservit | affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display | Medium | 4.9 | 2026-08-14 05:30:44 | Deep Dive |
| CVE-2026-16810 | Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterText' Parameter | bitpressadmin | Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder | Medium | 6.5 | 2026-08-14 05:30:43 | Deep Dive |
| CVE-2025-10308 | Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset | alian | Astro Booking Engine | Medium | 4.3 | 2026-08-14 04:26:21 | Deep Dive |
| CVE-2026-19792🧪 | Tenda G0 httpd web management interface module setPortMapping buffer overflow | Tenda | G0 | High | 8.8 | 2026-08-14 04:00:10 | Deep Dive |
| CVE-2026-19791🧪 | Tenda G0 httpd web management interface module addStaticRoute stack-based overflow | Tenda | G0 | High | 8.8 | 2026-08-14 03:45:08 | Deep Dive |
| CVE-2026-19790🧪 | Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow | Tenda | G0 | High | 8.8 | 2026-08-14 03:30:11 | Deep Dive |
| CVE-2026-19789🧪 | Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow | Tenda | AC1206 | High | 8.8 | 2026-08-14 03:15:10 | Deep Dive |
| CVE-2026-19788🧪 | Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow | Tenda | AC1206 | High | 8.8 | 2026-08-14 03:00:11 | Deep Dive |
| CVE-2026-19787 | SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection | SourceCodester | Air Cargo Management System | Medium | 4.7 | 2026-08-14 02:45:09 | Deep Dive |
| CVE-2026-19786 | francoisjacquet RosarioSIS Modules.php cross-site request forgery | francoisjacquet | RosarioSIS | Medium | 4.3 | 2026-08-14 02:30:11 | Deep Dive |
| CVE-2026-18109 | W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name | boldgrid | W3 Total Cache | High | 7.2 | 2026-08-14 02:25:46 | Deep Dive |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | francoisjacquet | RosarioSIS | Medium | 6.3 | 2026-08-14 02:15:11 | Deep Dive |
| CVE-2026-19784 | francoisjacquet RosarioSIS Referrals.php DBUpdate authorization | francoisjacquet | RosarioSIS | Medium | 4.3 | 2026-08-14 02:00:12 | Deep Dive |
| CVE-2026-19771🧪 | Baicells EG3661M LuCI Web luci os command injection | Baicells | EG3661M | High | 7.2 | 2026-08-14 01:45:08 | Deep Dive |
| CVE-2026-19770 | feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery | feedmob | fm-mcp-servers | Medium | 5.3 | 2026-08-14 01:30:10 | Deep Dive |
| CVE-2026-19767 | itsourcecode Hospital Management System viewdoctortimings.php sql injection | itsourcecode | Hospital Management System | Medium | 6.3 | 2026-08-14 01:15:13 | Deep Dive |
| CVE-2026-19765 | eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side request forgery | eyaushev | swagger-testcase-mcp | Medium | 6.3 | 2026-08-14 01:00:11 | Deep Dive |