| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67297 🧪 | FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67305 🧪 | FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr | FreeRDP | FreeRDP | Critical | 9.4 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67342 🧪 | ArcadeDB before 26.7.2 Authorization Bypass via Database Handlers | ArcadeData | arcadedb | Critical | 9.8 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67304 🧪 | FreeRDP before 3.29.0 NULL Dereference via smartcard cleanup | FreeRDP | FreeRDP | High | 7.5 | 2026-08-01 12:22:17 | Deep Dive |
| CVE-2026-67352 🧪 | luci-app-https-dns-proxy Stored XSS via resolver_url | openwrt | luci | High | 7.6 | 2026-08-01 12:22:16 | Deep Dive |
| CVE-2026-68771 🧪 | ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization | Comfy-Org | ComfyUI | Critical | 9.8 | 2026-07-31 21:16:10 | Deep Dive |
| CVE-2026-65981 🧪 | Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover | coturn | coturn | High | 7.1 | 2026-07-31 21:00:03 | Deep Dive |
| CVE-2026-68770 🧪 | sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False | Hugging Face | sentence-transformers | Critical | 9.8 | 2026-07-31 20:56:07 | Deep Dive |
| CVE-2026-62959 🧪 | Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`) | coturn | coturn | High | 8.2 | 2026-07-31 19:57:06 | Deep Dive |
| CVE-2026-53599 🧪 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers | redaxo | core | High | 7.5 | 2026-07-31 19:43:16 | Deep Dive |
| CVE-2026-62999 🧪 | Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass) | copier-org | copier | High | 7.5 | 2026-07-31 19:41:55 | Deep Dive |
| CVE-2026-53510 🧪 | Savon::Model evaluates WSDL operation names as Ruby source | savonrb | savon | High | 8.1 | 2026-07-31 19:38:33 | Deep Dive |
| CVE-2026-18394 🧪 | Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration | AWS | Strands Agents Tools | High | 7.4 | 2026-07-31 19:34:15 | Deep Dive |
| CVE-2026-53502 🧪 | Thumbor has path traversal via post-validation URL decoding bypass in file_loader | thumbor | thumbor | High | 8.7 | 2026-07-31 19:03:17 | Deep Dive |
| CVE-2026-53505 🧪 | Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS | thumbor | thumbor | High | 7.5 | 2026-07-31 19:00:23 | Deep Dive |
| CVE-2026-53504 🧪 | Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter | thumbor | thumbor | High | 7.5 | 2026-07-31 18:57:19 | Deep Dive |
| CVE-2026-53503 🧪 | Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS | thumbor | thumbor | High | 7.5 | 2026-07-31 18:54:21 | Deep Dive |
| CVE-2026-53501 🧪 | Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature | thumbor | thumbor | High | 8.2 | 2026-07-31 18:42:42 | Deep Dive |
| CVE-2026-53500 🧪 | Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot | thumbor | thumbor | High | 8.2 | 2026-07-31 18:35:54 | Deep Dive |
| CVE-2026-18481 🧪 | Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft | AWS | AWS Ops Wheel | High | 7.3 | 2026-07-31 18:12:23 | Deep Dive |