🔓 CVEs & KEV
- CVE-2026-77946 — CVSS 9.3 — TRENDnet TEW-821DAP Critical Stack-Based Buffer Overflow
- CVE-2026-62243 — CVSS 8.7 — Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass
- CVE-2026-59808 — CVSS 8.7 — AVideo Authentication Bypass via Unkeyed Video Hash Disclosure
- CVE-2026-59256 — CVSS 8.7 — WWBN AVideo Unbound Token Authorization Bypass via Gallery
- CVE-2026-34741 — CVSS 8.6 — Combodo iTop Unauthenticated RCE via Authentication Bypass
- CVE-2026-57998 — CVSS 8.5 — better-npm-audit OS Command Injection via registry flag
- CVE-2026-60084 — CVSS 8.4 — SiYuan before v3.7.4 Arbitrary File Deletion via removeTemplate
- CVE-2026-58003 — CVSS 7.1 — WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php
- CVE-2026-58002 — CVSS 7.1 — WWBN AVideo Authorization Bypass via Users_affiliations add.json.php
- CVE-2026-62382 — CVSS 6.9 — PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison
- CVE-2026-62381 — CVSS 6.9 — luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow
- CVE-2026-60083 — CVSS 6.9 — SiYuan before v3.8.0 Incomplete Path Blocklist via MCP file tool
- CVE-2026-59809 — CVSS 6.9 — SiYuan before v3.8.0 Secret Exfiltration via http_request URL
- CVE-2026-58001 — CVSS 6.9 — WWBN AVideo Cross-Site Request Forgery via videoEditLight.php
- CVE-2026-56380 — CVSS 6.9 — AVideo feed/index.php Exposure of Channel Owner Email Address
- CVE-2026-62380 — CVSS 6.3 — Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection