| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-59248 🧪 | Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS | ninenines | cowlib | High | 8.7 | 2026-07-28 09:54:20 | Deep Dive |
| CVE-2026-17524 🧪 | Ouga zip-lib 路径遍历漏洞 | - | zip-lib | High | 7.5 | 2026-07-28 05:00:01 | Deep Dive |
| CVE-2026-65442 📌 💣 | WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability | Subtle Web Inc | FormCraft | High | 7.2 | 2026-07-27 22:44:05 | Deep Dive |
| CVE-2026-55685 🧪 | React Router: Unauthenticated Denial of Service via Inefficient Route Matching | remix-run | react-router | High | 8.7 | 2026-07-27 21:45:58 | Deep Dive |
| CVE-2026-53666 🧪 | React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration | remix-run | react-router | Medium | 6.1 | 2026-07-27 21:14:50 | Deep Dive |
| CVE-2026-66824 🧪 | Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding | lookyloo | lookyloo | Critical | 9.2 | 2026-07-27 19:58:28 | Deep Dive |
| CVE-2026-64649 🧪 | Next.js: Server-Side Request Forgery in Server Actions on Custom Servers | vercel | next.js | High | 8.3 | 2026-07-27 19:27:59 | Deep Dive |
| CVE-2026-16481 🧪 | Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page Tool | MCP Toolbox for Databases (googleapis/mcp-toolbox) | Medium | 6.0 | 2026-07-27 19:13:29 | Deep Dive | |
| CVE-2026-59239 🧪 | Stored XSS in Prospero Flow CRM email body allows administrator account takeover | Roskus | Prospero Flow CRM | High | 8.6 | 2026-07-27 17:56:09 | Deep Dive |
| CVE-2026-55579 🧪 | Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise | pheditor | pheditor | Critical | 9.8 | 2026-07-27 17:54:45 | Deep Dive |
| CVE-2026-55578 🧪 | Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection | pheditor | pheditor | High | 8.8 | 2026-07-27 17:54:29 | Deep Dive |
| CVE-2026-54540 🧪 | Authenticated terminal command whitelist bypass in Pheditor | pheditor | pheditor | High | 8.8 | 2026-07-27 17:53:54 | Deep Dive |
| CVE-2026-48030 🧪 💣 | Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) | pheditor | pheditor | Critical | 9.9 | 2026-07-27 17:53:34 | Deep Dive |
| CVE-2026-45623 🧪 | PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments | postcss | postcss | High | 7.5 | 2026-07-27 17:23:13 | Deep Dive |
| CVE-2026-66731 🧪 | facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS | boazsegev | facil.io | High | 7.5 | 2026-07-27 16:57:01 | Deep Dive |
| CVE-2026-66730 🧪 | facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser | boazsegev | facil.io | High | 7.5 | 2026-07-27 16:55:27 | Deep Dive |
| CVE-2026-66729 🧪 | facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser | boazsegev | facil.io | High | 7.5 | 2026-07-27 16:52:35 | Deep Dive |
| CVE-2026-63077 KEV 📌 💣 | JetBrains TeamCity 反序列化注入漏洞 | JetBrains | TeamCity | Critical | 9.8 | 2026-07-27 16:44:32 | Deep Dive |
| CVE-2026-66398 🧪 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API | thorsten | phpMyFAQ | Critical | 9.4 | 2026-07-27 15:43:48 | Deep Dive |
| CVE-2026-66397 🧪 | phpMyFAQ before 4.1.6 Path Traversal via category image deletion | thorsten | phpMyFAQ | High | 8.6 | 2026-07-27 15:43:47 | Deep Dive |