| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-47216 | Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint | typesense | typesense | 高危 | - | 2026-06-12 17:12:55 | Deep Dive |
| CVE-2026-47225 | Improper Search Cache Isolation for Scoped Search API Keys in Typesense | typesense | typesense | 中危 | - | 2026-06-12 17:12:41 | Deep Dive |
| CVE-2026-47965 | Acrobat Reader | Out-of-bounds Write (CWE-787) | Adobe | Acrobat Reader | High | 7.8 | 2026-06-12 17:08:31 | Deep Dive |
| CVE-2026-48558 | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification | SimpleHelp | SimpleHelp | Critical | 10.0 | 2026-06-12 17:07:05 | Deep Dive |
| CVE-2026-47223 | NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow | M2Team | NanaZip | Medium | 5.4 | 2026-06-12 17:06:15 | Deep Dive |
| CVE-2026-47224 | NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check | M2Team | NanaZip | Medium | 4.3 | 2026-06-12 16:57:14 | Deep Dive |
| CVE-2026-47222 | NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow | M2Team | NanaZip | Medium | 5.4 | 2026-06-12 16:56:48 | Deep Dive |
| CVE-2026-53982 | Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association | Cap-go | capgo | Medium | 6.5 | 2026-06-12 16:25:43 | Deep Dive |
| CVE-2026-6961 | CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync | Mattermost | Mattermost | High | 7.6 | 2026-06-12 15:56:17 | Deep Dive |
| CVE-2026-7387 | Mattermost group syncable endpoints allow privilege escalation via scheme_admin | Mattermost | Mattermost | High | 8.8 | 2026-06-12 15:54:10 | Deep Dive |
| CVE-2026-6046 | Plugin bot username conflict allows user account to be used as bot identity in Mattermost Server | Mattermost | Mattermost | Medium | 5.3 | 2026-06-12 15:52:34 | Deep Dive |
| CVE-2026-6689 | *Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings* | Mattermost | Mattermost | Medium | 4.3 | 2026-06-12 15:51:31 | Deep Dive |
| CVE-2026-7184 | Mattermost Remote Cluster PATCH API Leaks Authentication Tokens | Mattermost | Mattermost | Medium | 6.5 | 2026-06-12 15:49:47 | Deep Dive |
| CVE-2026-6739 | Mattermost: Delegated admins could patch protected default system roles | Mattermost | Mattermost | Medium | 6.7 | 2026-06-12 15:49:14 | Deep Dive |
| CVE-2026-3433 | Mattermost fails to scope role_updated websocket events to authorized team and channel members | Mattermost | Mattermost | Medium | 4.3 | 2026-06-12 15:46:55 | Deep Dive |
| CVE-2026-3840 | Path Traversal in kedro-org/kedro | kedro-org | kedro-org/kedro | 高危 | - | 2026-06-12 15:45:40 | Deep Dive |
| CVE-2026-53981🧪 | Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism | Cap-go | Cap-go | High | 7.6 | 2026-06-12 15:42:18 | Deep Dive |
| CVE-2026-45833 | ChromaDB 代码注入漏洞 | Chroma | ChromaDB | 超危 | - | 2026-06-12 15:16:33 | Deep Dive |
| CVE-2026-45832 | Chroma ChromaDB 授权问题漏洞 | Chroma | ChromaDB | 高危 | - | 2026-06-12 15:11:47 | Deep Dive |
| CVE-2026-45831 | ChromaDB 授权问题漏洞 | Chroma | ChromaDB | 高危 | - | 2026-06-12 15:03:59 | Deep Dive |