| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-55415 🧪 | datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements | koxudaxi | datamodel-code-generator | High | 7.5 | 2026-07-28 21:37:56 | Deep Dive |
| CVE-2026-54621 🧪 | `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description | koxudaxi | datamodel-code-generator | High | 7.8 | 2026-07-28 21:35:28 | Deep Dive |
| CVE-2026-54655 🧪 | `datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator | koxudaxi | datamodel-code-generator | High | 7.8 | 2026-07-28 21:33:45 | Deep Dive |
| CVE-2026-54691 🧪 | datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects | koxudaxi | datamodel-code-generator | High | 8.2 | 2026-07-28 21:29:52 | Deep Dive |
| CVE-2026-55390 🧪 | Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate | koxudaxi | datamodel-code-generator | High | 7.5 | 2026-07-28 21:25:32 | Deep Dive |
| CVE-2026-54654 🧪 | `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field | koxudaxi | datamodel-code-generator | High | 7.8 | 2026-07-28 21:22:52 | Deep Dive |
| CVE-2026-14512 🧪 | IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information | IBM | WebSphere Application Server | Critical | 9.8 | 2026-07-28 20:50:09 | Deep Dive |
| CVE-2026-6881 🧪 | Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance | Ellucian | Advance Web | Critical | 9.4 | 2026-07-28 20:03:12 | Deep Dive |
| CVE-2026-57510 🧪 | SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC | superplanehq | superplane | High | 8.8 | 2026-07-28 19:06:15 | Deep Dive |
| CVE-2026-48060 🧪 | Litestar: HTML Injection Through CSRF Token | litestar-org | litestar | High | 8.1 | 2026-07-28 19:02:40 | Deep Dive |
| CVE-2026-49258 🧪 | Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) | juev | nebula-mesh | High | 8.8 | 2026-07-28 18:52:59 | Deep Dive |
| CVE-2026-59932 🧪 | PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion | PHPOffice | PhpSpreadsheet | High | 7.5 | 2026-07-28 17:59:17 | Deep Dive |
| CVE-2026-47726 🧪 | nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator | juev | nebula-mesh | High | 7.1 | 2026-07-28 17:58:27 | Deep Dive |
| CVE-2026-59933 🧪 | PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion | PHPOffice | PhpSpreadsheet | High | 7.5 | 2026-07-28 17:29:27 | Deep Dive |
| CVE-2026-59931 🧪 | PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist | PHPOffice | PhpSpreadsheet | High | 7.7 | 2026-07-28 17:27:27 | Deep Dive |
| CVE-2026-54635 🧪 | pytonapi has a Webhook Custom Path Authentication Bypass | nessshon | tonapi | High | 7.5 | 2026-07-28 17:09:08 | Deep Dive |
| CVE-2026-16313 🧪 | Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export | Red Hat | Red Hat Enterprise Linux 10 | High | 7.6 | 2026-07-28 16:47:06 | Deep Dive |
| CVE-2026-54609 🧪 | QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding | Quiet-Terminal-Interactive | QTINeon | High | 8.6 | 2026-07-28 16:36:38 | Deep Dive |
| CVE-2026-67185 🧪 | TinyWeb 0.0.8 Path Traversal via URL Path Component | GeneralSandman | TinyWeb | High | 7.5 | 2026-07-28 16:30:45 | Deep Dive |
| CVE-2026-54603 🧪 | OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host | ruby-oauth | oauth2 | High | 8.6 | 2026-07-28 16:29:04 | Deep Dive |