CVE ID :CVE-2026-71987 Published : Aug. 8, 2026, 11:27 p.m. | 32 minutes ago Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows…
CVE-2026-71986 – MSI Radix AXE6600 v781521 Command Injection via dmz Function
CVE ID :CVE-2026-71986 Published : Aug. 8, 2026, 11:24 p.m. | 35 minutes ago Description :MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows…
CVE-2026-8798 – Native entropy source retries the CPU entropy instructions without limit
CVE ID :CVE-2026-8798 Published : Aug. 8, 2026, 1:16 a.m. | 39 minutes ago Description :In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms…
CVE-2026-13505 – Zeroisation of sensitive key material on garbage collection relies on finalization
CVE ID :CVE-2026-13505 Published : Aug. 8, 2026, 12:59 a.m. | 56 minutes ago Description :In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X…
CVE-2026-48120 – Kakoune has a Critical RCE via Autorestore Backup Filename Injection
CVE ID :CVE-2026-48120 Published : Aug. 7, 2026, 11:17 p.m. | 39 minutes ago Description :Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be…
CVE-2026-48026 – lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML
CVE ID :CVE-2026-48026 Published : Aug. 7, 2026, 11:17 p.m. | 39 minutes ago Description :lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of…
CVE-2026-46409 – OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
CVE ID :CVE-2026-46409 Published : Aug. 7, 2026, 11:17 p.m. | 39 minutes ago Description :OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior…
CVE-2026-48170 – scimPatch vulnerable to prototype pollution via unfiltered keys in patch
CVE ID :CVE-2026-48170 Published : Aug. 7, 2026, 10:16 p.m. | 1 hour, 39 minutes ago Description :`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a…
CVE-2026-48169 – PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
CVE ID :CVE-2026-48169 Published : Aug. 7, 2026, 10:16 p.m. | 1 hour, 39 minutes ago Description :PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two…
CVE-2026-70332 – Microsoft Office SharePoint Spoofing Vulnerability
CVE ID :CVE-2026-70332 Published : 2026年8月7日 00:16 | 1 小时,36 分钟 ago Description :Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Severity: 9.6 |…