| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63090 🧪 | ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly | proftpd | proftpd | High | 8.8 | 2026-07-20 14:22:04 | Deep Dive |
| CVE-2026-54910 🧪 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | gtsteffaniak | filebrowser | High | 7.7 | 2026-07-20 14:20:21 | Deep Dive |
| CVE-2026-45270 🧪 | CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule | ci4-cms-erp | ci4ms | High | 8.7 | 2026-07-20 14:12:13 | Deep Dive |
| CVE-2026-16248 🧪 | Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow | Tenda | AC10 | High | 8.8 | 2026-07-20 12:45:11 | Deep Dive |
| CVE-2026-64622 🧪 | Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox | Jovancoding | Network-AI | High | 7.5 | 2026-07-20 12:04:55 | Deep Dive |
| CVE-2026-64623 🧪 | Network-AI before 5.13.4 Cryptographic Signature Verification Bypass | Jovancoding | Network-AI | High | 8.6 | 2026-07-20 12:04:55 | Deep Dive |
| CVE-2026-64621 🧪 | FreeRDP before 3.28.0 Double-Free via selectedmonitors | FreeRDP | FreeRDP | High | 7.3 | 2026-07-20 12:04:54 | Deep Dive |
| CVE-2026-64620 🧪 | FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common | FreeRDP | FreeRDP | Critical | 9.8 | 2026-07-20 12:04:53 | Deep Dive |
| CVE-2026-63763 🧪 | SurrealDB before 2.5.0 Privilege Escalation via Future Fields | surrealdb | surrealdb | High | 7.5 | 2026-07-20 12:04:52 | Deep Dive |
| CVE-2026-63760 🧪 | SurrealDB before 3.1.0 Denial of Service via JSON Parser | surrealdb | surrealdb | High | 7.5 | 2026-07-20 12:04:50 | Deep Dive |
| CVE-2026-63757 🧪 | SurrealDB before 3.1.0 Session Hijacking via /rpc sessions | surrealdb | surrealdb | High | 8.8 | 2026-07-20 12:04:48 | Deep Dive |
| CVE-2026-63756 🧪 | SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition | surrealdb | surrealdb | High | 8.1 | 2026-07-20 12:04:47 | Deep Dive |
| CVE-2026-63747 🧪 | SurrealDB before 3.1.0 Denial of Service via malformed RPC use | surrealdb | surrealdb | High | 7.5 | 2026-07-20 12:04:40 | Deep Dive |
| CVE-2026-63739 🧪 | SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER | surrealdb | surrealdb | High | 7.7 | 2026-07-20 12:04:34 | Deep Dive |
| CVE-2026-63735 🧪 | SurrealDB before 3.2.0 Authentication Bypass via Custom API | surrealdb | surrealdb | High | 8.1 | 2026-07-20 12:04:31 | Deep Dive |
| CVE-2026-13147 📌 💣 | Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis | Unknown | Kirki | 超危 | - | 2026-07-20 06:00:05 | Deep Dive |
| CVE-2026-12898 📌 💣 | All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal | Unknown | All-in-One WP Migration and Backup | 中危 | - | 2026-07-20 06:00:04 | Deep Dive |
| CVE-2026-51027 🧪 | Frances Leese File Thingie 日志信息泄露漏洞 | - | - | Critical | 9.9 | 2026-07-20 00:00:00 | Deep Dive |
| CVE-2026-42566 🧪 | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure | meshtastic | firmware | High | 7.5 | 2026-07-19 23:16:05 | Deep Dive |
| CVE-2026-44359 🧪 | Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow | meshtastic | firmware | Critical | 10.0 | 2026-07-19 23:06:32 | Deep Dive |