| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-18699 | Improper Input Validation in MongoDB Query Planner Leads to Denial of Service | MongoDB | MongoDB Server | Medium | 6.5 | 2026-08-11 18:46:36 | Deep Dive |
| CVE-2026-18691 | Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure | MongoDB | MongoDB Server | High | 8.8 | 2026-08-11 18:46:03 | Deep Dive |
| CVE-2026-73227🧪 | electerm's RDP clipboard file download may parse unsafe file name | electerm | electerm | High | 8.1 | 2026-08-11 18:45:22 | Deep Dive |
| CVE-2026-73226🧪 | Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist | electerm | electerm | High | 8.8 | 2026-08-11 18:44:02 | Deep Dive |
| CVE-2026-18702 | Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings | MongoDB | MongoDB Server | Medium | 6.4 | 2026-08-11 18:43:59 | Deep Dive |
| CVE-2026-18694 | Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure | MongoDB | MongoDB Server | High | 7.1 | 2026-08-11 18:42:43 | Deep Dive |
| CVE-2026-73225🧪 | electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename | electerm | electerm | High | 8.1 | 2026-08-11 18:42:16 | Deep Dive |
| CVE-2026-18708 | Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes | MongoDB | MongoDB Server | Medium | 6.4 | 2026-08-11 18:41:10 | Deep Dive |
| CVE-2026-18696 | Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections | MongoDB | MongoDB Server | Medium | 6.5 | 2026-08-11 18:40:35 | Deep Dive |
| CVE-2026-18700 | Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service | MongoDB | MongoDB Server | Medium | 6.5 | 2026-08-11 18:40:07 | Deep Dive |
| CVE-2026-18701 | Type Confusion in MongoDB Query Subsystem Leads to Denial of Service | MongoDB | MongoDB Server | Medium | 6.5 | 2026-08-11 18:39:35 | Deep Dive |
| CVE-2026-73224🧪 | Electerm check folder size function may get attacked by unsafe folder name | electerm | electerm | High | 8.8 | 2026-08-11 18:39:21 | Deep Dive |
| CVE-2026-18697 | Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos | MongoDB | MongoDB Server | High | 7.5 | 2026-08-11 18:39:04 | Deep Dive |
| CVE-2026-18693 | Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure | MongoDB | MongoDB Server | High | 7.6 | 2026-08-11 18:38:31 | Deep Dive |
| CVE-2026-18705 | Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data | MongoDB | MongoDB Server | Medium | 6.5 | 2026-08-11 18:37:54 | Deep Dive |
| CVE-2026-73223🧪 | electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename | electerm | electerm | High | 8.1 | 2026-08-11 18:37:41 | Deep Dive |
| CVE-2026-18704 | Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations | MongoDB | MongoDB Server | Medium | 6.5 | 2026-08-11 18:37:24 | Deep Dive |
| CVE-2026-18692 | Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution | MongoDB | MongoDB Server | High | 8.8 | 2026-08-11 18:36:54 | Deep Dive |
| CVE-2026-18688 | Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure | MongoDB | MongoDB Server | High | 7.1 | 2026-08-11 18:36:21 | Deep Dive |
| CVE-2026-69119🧪 | Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id} | Taubyte | tau | High | 8.3 | 2026-08-11 18:36:12 | Deep Dive |