| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-67351 🧪 | Serendipity < 2.6.1 Authentication Bypass via Username Collision | s9y | Serendipity | High | 8.8 | 2026-07-30 13:57:52 | Deep Dive |
| CVE-2026-59309 🧪 | vCenter authentication-bypass vulnerability | VMware | Cloud Foundation | Critical | 9.8 | 2026-07-30 12:19:52 | Deep Dive |
| CVE-2026-59310 KEV 🧪 | vCenter directory-traversal vulnerability | VMware | Cloud Foundation | Critical | 9.8 | 2026-07-30 12:19:25 | Deep Dive |
| CVE-2026-18361 🧪 | DFIR-IRIS Stored XSS in Datastore Upload | dfir-iris | iris-web | High | 7.6 | 2026-07-30 09:42:26 | Deep Dive |
| CVE-2026-18360 🧪 | DFIR-IRIS Stored XSS in Custom Attributes | dfir-iris | iris-web | High | 7.6 | 2026-07-30 09:41:19 | Deep Dive |
| CVE-2026-16969 🧪 | DFIR-IRIS Stored XSS in Assets | dfir-iris | iris-web | High | 7.6 | 2026-07-30 09:40:14 | Deep Dive |
| CVE-2026-18353 🧪 | Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass | Eclipse Foundation | Eclipse CSI - PIA | High | 8.8 | 2026-07-30 07:23:04 | Deep Dive |
| CVE-2026-18015 🧪 | Google Chrome 安全漏洞 | Chrome | 超危 | - | 2026-07-30 00:26:09 | Deep Dive | |
| CVE-2026-17652 🧪 | Google Chrome 资源管理错误漏洞 | Chrome | 超危 | - | 2026-07-30 00:18:43 | Deep Dive | |
| CVE-2026-67595 🧪 | VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php | webreinvent | vaahcms | High | 8.1 | 2026-07-29 21:33:26 | Deep Dive |
| CVE-2026-67437 🧪 | OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) | OliveTin | OliveTin | High | 7.5 | 2026-07-29 20:43:05 | Deep Dive |
| CVE-2026-67432 🧪 | MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport | modelcontextprotocol | ruby-sdk | High | 7.5 | 2026-07-29 19:17:47 | Deep Dive |
| CVE-2026-67431 🧪 | MCP Ruby SDK: Ruby SSE Session Poisoning | modelcontextprotocol | ruby-sdk | High | 8.3 | 2026-07-29 19:15:32 | Deep Dive |
| CVE-2026-18022 🧪 | pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-bit systems | - | pgvector | High | 8.8 | 2026-07-29 18:55:55 | Deep Dive |
| CVE-2026-67429 🧪 | Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) | flytohub | flyto-core | Critical | 10.0 | 2026-07-29 18:50:43 | Deep Dive |
| CVE-2026-67428 🧪 | Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata) | flytohub | flyto-core | High | 8.5 | 2026-07-29 18:48:42 | Deep Dive |
| CVE-2026-67427 🧪 | Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted | flytohub | flyto-core | High | 8.6 | 2026-07-29 18:45:48 | Deep Dive |
| CVE-2026-67426 🧪 | Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration | flytohub | flyto-core | Critical | 9.3 | 2026-07-29 18:43:26 | Deep Dive |
| CVE-2026-67425 🧪 | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url | flytohub | flyto-core | High | 8.6 | 2026-07-29 18:35:02 | Deep Dive |
| CVE-2026-67424 🧪 | Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation | flytohub | flyto-core | High | 8.5 | 2026-07-29 18:32:01 | Deep Dive |