CVE ID :CVE-2026-8989 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through…
CVE-2026-8988 – Access to Bootloader
CVE ID :CVE-2026-8988 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the…
CVE-2026-8987 – Authenticated Heap Overflow
CVE ID :CVE-2026-8987 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled…
CVE-2026-8986 – Command Injection via Malicious OCPP Server
CVE ID :CVE-2026-8986 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics…
CVE-2026-63728 – Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
CVE ID :CVE-2026-63728 Published : July 21, 2026, 12:17 a.m. | 18 minutes ago Description :Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report…
CVE-2026-64625 – AVideo before 29.0 OS Command Injection via execAsync
CVE ID :CVE-2026-64625 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh…
CVE-2026-64624 – FreeRDP RDP File Parser Remote Code Execution via CLI Options
CVE ID :CVE-2026-64624 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing…
CVE-2026-57495 – AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator’s Claude Code session (bridge-wake)
CVE ID :CVE-2026-57495 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex…
CVE-2026-47255 – AgenticMail API/storage and outbound relay hardening
CVE ID :CVE-2026-47255 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core…
CVE-2026-44359 – Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
CVE ID :CVE-2026-44359 Published : July 20, 2026, 12:16 a.m. | 18 minutes ago Description :Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository’s main_matrix.yml workflow…