| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67208 🧪 💣 | Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console | somta | Juggle | Critical | 9.8 | 2026-07-30 19:17:42 | Deep Dive |
| CVE-2026-67594 🧪 | Spikster Missing Authentication via API Route Group | yolanmees | Spikster | Critical | 9.8 | 2026-07-30 19:14:28 | Deep Dive |
| CVE-2026-18140 🧪 | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers | AWS | aws-smithy-json | High | 7.5 | 2026-07-30 18:34:04 | Deep Dive |
| CVE-2026-66066 🧪 💣 | Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing | rails | rails | Critical | 9.5 | 2026-07-30 18:32:11 | Deep Dive |
| CVE-2026-18245 🧪 | Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react | AWS | Amplify Codegen UI | Critical | 9.0 | 2026-07-30 18:13:07 | Deep Dive |
| CVE-2026-15969 🧪 | CVE-2026-15969 | SGLang | SGLang | 超危 | - | 2026-07-30 18:09:21 | Deep Dive |
| CVE-2026-15974 🧪 | CVE-2026-15974 | SGLang | SGLang | 高危 | - | 2026-07-30 18:07:35 | Deep Dive |
| CVE-2026-66416 🧪 | Leantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middleware | Leantime | Leantime | High | 8.8 | 2026-07-30 17:00:10 | Deep Dive |
| CVE-2026-61536 🧪 | Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path in CompletionExtension allows RCE | masci | banks | High | 7.5 | 2026-07-30 16:50:02 | Deep Dive |
| CVE-2026-66415 🧪 | Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import() | Leantime | Leantime | High | 8.5 | 2026-07-30 16:49:55 | Deep Dive |
| CVE-2026-54722 🧪 | dssrf: there a critical security bug with remove_at_symbol_in_string | HackingRepo | dssrf-js | High | 8.7 | 2026-07-30 16:27:13 | Deep Dive |
| CVE-2026-62663 🧪 | Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/video/document) | masci | banks | High | 7.5 | 2026-07-30 16:16:34 | Deep Dive |
| CVE-2026-57862 🧪 | Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation | Kanboard | Kanboard | High | 8.5 | 2026-07-30 15:26:23 | Deep Dive |
| CVE-2026-6540 🧪 | L7 policy bypass via unnormalized HTTP path matching | Tigera | Calico | High | 7.9 | 2026-07-30 14:45:04 | Deep Dive |
| CVE-2026-67349 🧪 | OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass | opencost | opencost | High | 7.5 | 2026-07-30 14:40:48 | Deep Dive |
| CVE-2026-67348 🧪 | Julep Insecure Direct Object Reference via GET /executions/{execution_id} | julep-ai | julep | High | 8.1 | 2026-07-30 14:40:27 | Deep Dive |
| CVE-2026-67346 🧪 | Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass | kyegomez | swarms | High | 8.6 | 2026-07-30 14:39:43 | Deep Dive |
| CVE-2026-67345 🧪 | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft | dromara | MaxKey | High | 8.1 | 2026-07-30 14:39:14 | Deep Dive |
| CVE-2026-53431 🧪 | Boruta accepts expired JWT client assertions due to missing exp claim validation | malach-it | boruta | Critical | 9.1 | 2026-07-30 14:17:28 | Deep Dive |
| CVE-2026-65635 🧪 | Boruta dynamic client registration allows creation of over-privileged OAuth clients | malach-it | boruta | High | 8.3 | 2026-07-30 14:17:03 | Deep Dive |