| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-59247 🧪 | Insufficient verification of Hex package metadata in Gleam | gleam-lang | gleam | High | 7.6 | 2026-07-29 14:24:55 | Deep Dive |
| CVE-2026-54660 🧪 | swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` | acacode | swagger-typescript-api | High | 7.4 | 2026-07-29 14:21:34 | Deep Dive |
| CVE-2026-66723 🧪 | Missing authentication requirement in Remote Instances proxy API in MWDB Core | CERT.PL | MWDB Core | High | 7.0 | 2026-07-29 14:12:35 | Deep Dive |
| CVE-2026-55995 🧪 | Double-free in the iSNS attribute decoder in open-iscsi | open-iscsi | open-iscsi | High | 8.7 | 2026-07-29 13:43:22 | Deep Dive |
| CVE-2026-67215 🧪 | cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion | DaveGamble | cJSON | High | 7.5 | 2026-07-29 13:32:03 | Deep Dive |
| CVE-2026-44944 🧪 | iscsiuio control-socket authentication bypass in open-iscsi | open-iscsi | open-iscsi | High | 8.5 | 2026-07-29 13:04:51 | Deep Dive |
| CVE-2026-18072 🧪 💣 | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter | nico23 | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … | Critical | 9.8 | 2026-07-29 03:31:09 | Deep Dive |
| CVE-2026-56822 🧪 | Netty: TOCTOU in OcspServerCertificateValidator | netty | netty | High | 7.4 | 2026-07-28 23:17:17 | Deep Dive |
| CVE-2026-56821 🧪 | Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator | netty | netty | High | 7.4 | 2026-07-28 23:07:14 | Deep Dive |
| CVE-2026-54650 🧪 | openhole-server vulnerable to path traversal via URL-decoded request path | bablilayoub | openhole | High | 8.6 | 2026-07-28 22:20:37 | Deep Dive |
| CVE-2026-54658 🧪 | @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution | hypequery | hypequery | Critical | 9.8 | 2026-07-28 22:18:49 | Deep Dive |
| CVE-2026-47219 🧪 | find-my-way is Vulnerable to DDoS with HTTP2 | delvedor | find-my-way | High | 7.5 | 2026-07-28 22:14:31 | Deep Dive |
| CVE-2026-64863 🧪 | goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite | goshs-labs | goshs | Critical | 9.1 | 2026-07-28 22:02:16 | Deep Dive |
| CVE-2026-54719 🧪 | goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of CVE-2026-40189) | goshs-labs | goshs | High | 7.5 | 2026-07-28 21:58:50 | Deep Dive |
| CVE-2026-62325 🧪 | goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) | goshs-labs | goshs | Critical | 9.1 | 2026-07-28 21:52:06 | Deep Dive |
| CVE-2026-55389 🧪 | datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs` | koxudaxi | datamodel-code-generator | High | 7.5 | 2026-07-28 21:49:21 | Deep Dive |
| CVE-2026-54653 🧪 | `datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field | koxudaxi | datamodel-code-generator | High | 8.8 | 2026-07-28 21:48:05 | Deep Dive |
| CVE-2026-55391 🧪 | datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding | koxudaxi | datamodel-code-generator | High | 7.5 | 2026-07-28 21:45:39 | Deep Dive |
| CVE-2026-54656 🧪 | `datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data | koxudaxi | datamodel-code-generator | High | 7.8 | 2026-07-28 21:43:56 | Deep Dive |
| CVE-2026-54690 🧪 | datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default) | koxudaxi | datamodel-code-generator | High | 8.2 | 2026-07-28 21:42:07 | Deep Dive |