| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-54737 🧪 | @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging | phun-ky | defaults-deep | High | 7.3 | 2026-07-31 17:48:43 | Deep Dive |
| CVE-2026-54725 🧪 | vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API | bank-vaults | vault-secrets-webhook | Critical | 9.6 | 2026-07-31 17:45:10 | Deep Dive |
| CVE-2026-55100 🧪 | hashi-vault-js has a path traversal and query parameter injection | kyndryl-open-source | hashi-vault-js | High | 8.7 | 2026-07-31 17:03:42 | Deep Dive |
| CVE-2026-54729 🧪 | dssrf: any users using 1.1.1.1 DNS is impacted by SSRF | HackingRepo | dssrf-js | High | 8.7 | 2026-07-31 16:58:57 | Deep Dive |
| CVE-2026-52856 🧪 | Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service | pterodactyl | wings | High | 7.5 | 2026-07-31 16:20:31 | Deep Dive |
| CVE-2026-52855 🧪 | Wings exposes node configuration secrets through egg configuration-file templating | pterodactyl | wings | Critical | 9.9 | 2026-07-31 16:16:42 | Deep Dive |
| CVE-2026-17566 🧪 | pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) | pgadmin.org | pgAdmin 4 | Critical | 9.9 | 2026-07-31 16:00:23 | Deep Dive |
| CVE-2026-17351 🧪 | pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) | pgadmin.org | pgAdmin 4 | Critical | 9.0 | 2026-07-31 16:00:19 | Deep Dive |
| CVE-2026-17349 🧪 | pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner | pgadmin.org | pgAdmin 4 | Critical | 9.6 | 2026-07-31 15:59:48 | Deep Dive |
| CVE-2026-17347 🧪 | pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution | pgadmin.org | pgAdmin 4 | High | 7.5 | 2026-07-31 15:59:17 | Deep Dive |
| CVE-2026-17346 🧪 | pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044) | pgadmin.org | pgAdmin 4 | High | 8.8 | 2026-07-31 15:59:13 | Deep Dive |
| CVE-2026-18446 🧪 | fast-uri vulnerable to host confusion via backslash authority introducer | fast-uri | fast-uri | High | 7.5 | 2026-07-31 14:37:02 | Deep Dive |
| CVE-2026-11770 🧪 | 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | High | 7.5 | 2026-07-31 09:18:58 | Deep Dive |
| CVE-2026-14483 📌 💣 | Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command | realtyna | Realtyna Organic IDX plugin + WPL Real Estate | Critical | 9.8 | 2026-07-31 05:35:23 | Deep Dive |
| CVE-2026-56673 🧪 | ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration | Comfy-Org | ComfyUI | High | 7.5 | 2026-07-31 04:46:21 | Deep Dive |
| CVE-2026-56672 🧪 | ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization | Comfy-Org | ComfyUI | High | 8.2 | 2026-07-31 04:27:19 | Deep Dive |
| CVE-2026-56671 🧪 | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read | Comfy-Org | ComfyUI | High | 7.5 | 2026-07-31 04:21:54 | Deep Dive |
| CVE-2026-56670 🧪 | ComfyUI: Stored XSS via SVG file upload on the /view endpoint | Comfy-Org | ComfyUI | High | 8.2 | 2026-07-31 04:17:44 | Deep Dive |
| CVE-2026-63223 🧪 | CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules | codeigniter4 | CodeIgniter4 | Critical | 9.8 | 2026-07-31 04:10:28 | Deep Dive |
| CVE-2026-63222 🧪 | CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames | codeigniter4 | CodeIgniter4 | High | 7.5 | 2026-07-31 04:06:19 | Deep Dive |