| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63221 🧪 | CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions | codeigniter4 | CodeIgniter4 | Critical | 9.4 | 2026-07-31 04:03:34 | Deep Dive |
| CVE-2026-55502 🧪 | Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials | cloudreve | cloudreve | High | 7.1 | 2026-07-31 03:35:59 | Deep Dive |
| CVE-2026-18157 🧪 | Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection | RedHatInsights | yggdrasil-worker-package-manager | High | 7.8 | 2026-07-31 02:38:28 | Deep Dive |
| CVE-2026-14541 🧪 | Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider | mcp-toolbox | High | 8.0 | 2026-07-31 01:48:39 | Deep Dive | |
| CVE-2026-14540 🧪 | Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox | mcp-toolbox | High | 8.0 | 2026-07-31 01:46:55 | Deep Dive | |
| CVE-2026-14537 🧪 | Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints | mcp-toolbox | High | 8.1 | 2026-07-31 01:38:19 | Deep Dive | |
| CVE-2026-66421 🧪 | OpenClaw Dashboard Stored XSS via lastMessage Session Field | tugcantopaloglu | openclaw-dashboard | Critical | 9.3 | 2026-07-30 22:16:59 | Deep Dive |
| CVE-2026-65423 🧪 | o6 Automation open62541 Integer Overflow or Wraparound | o6 Automation | open62541 | High | 8.8 | 2026-07-30 21:59:06 | Deep Dive |
| CVE-2026-63035 🧪 | o6 Automation open62541 Use After Free | o6 Automation | open62541 | High | 8.1 | 2026-07-30 21:56:04 | Deep Dive |
| CVE-2026-66420 🧪 | MeshCentral Cross-Site WebSocket Hijacking via Origin Validation Bypass on Self-Signed Certificate Deployments | Ylianst | MeshCentral | High | 8.8 | 2026-07-30 21:52:29 | Deep Dive |
| CVE-2026-63559 🧪 | o6 Automation open62541 Integer Overflow or Wraparound | o6 Automation | open62541 | High | 7.5 | 2026-07-30 21:47:21 | Deep Dive |
| CVE-2026-18064 🧪 | NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference | NASA | Core Flight System (cFS) Health & Safety (HS) Application | High | 7.5 | 2026-07-30 21:35:14 | Deep Dive |
| CVE-2026-62246 🧪 | Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation | clastix | kamaji | High | 8.5 | 2026-07-30 21:06:15 | Deep Dive |
| CVE-2026-66418 🧪 | OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field | tugcantopaloglu | openclaw-dashboard | Critical | 9.3 | 2026-07-30 20:55:25 | Deep Dive |
| CVE-2026-68503 🧪 | LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard | grisuno | LazyOwn | Critical | 9.8 | 2026-07-30 20:39:35 | Deep Dive |
| CVE-2026-68502 🧪 | LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE | grisuno | LazyOwn | Critical | 9.8 | 2026-07-30 20:38:05 | Deep Dive |
| CVE-2026-55768 🧪 | GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service | allinurl | goaccess | High | 8.7 | 2026-07-30 20:34:33 | Deep Dive |
| CVE-2026-54715 🧪 | GoAccess: Heap Out-of-Bounds Write in parse_browser() | allinurl | goaccess | High | 7.1 | 2026-07-30 20:23:37 | Deep Dive |
| CVE-2026-67207 🧪 | Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController | wolfcms | wolfcms | High | 8.8 | 2026-07-30 19:30:45 | Deep Dive |
| CVE-2026-67206 🧪 💣 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | wolfcms | High | 8.8 | 2026-07-30 19:27:46 | Deep Dive |