| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-66396 🧪 | SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL | siyuan-note | siyuan | High | 8.4 | 2026-07-27 15:43:47 | Deep Dive |
| CVE-2026-66395 🧪 | SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol | siyuan-note | siyuan | Critical | 9.6 | 2026-07-27 15:43:46 | Deep Dive |
| CVE-2026-66394 🧪 | SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass | siyuan-note | siyuan | High | 8.7 | 2026-07-27 15:43:45 | Deep Dive |
| CVE-2026-66050 🧪 | NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server | nitroshare | nitroshare-desktop | High | 7.5 | 2026-07-27 14:19:11 | Deep Dive |
| CVE-2026-61511 📌 💣 | vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php | vBulletin | vBulletin | Critical | 9.8 | 2026-07-27 12:39:16 | Deep Dive |
| CVE-2026-12394 📌 💣 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator | Unknown | MemberGlut | 超危 | - | 2026-07-27 06:00:02 | Deep Dive |
| CVE-2026-17497 🧪 | NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python | codexu | NoteGen | High | 8.3 | 2026-07-26 14:38:09 | Deep Dive |
| CVE-2026-17496 🧪 | NoteGen chat preview XSS via unsanitized AI/skill HTML rendering | codexu | NoteGen | High | 8.1 | 2026-07-26 14:33:03 | Deep Dive |
| CVE-2026-63720 🧪 | datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field | koxudaxi | datamodel-code-generator | High | 7.5 | 2026-07-26 03:51:19 | Deep Dive |
| CVE-2026-66013 🧪 | OpenRemote before 1.26.2 Authentication Bypass via Console Registration | openremote | openremote | Critical | 9.3 | 2026-07-25 10:45:57 | Deep Dive |
| CVE-2026-66012 🧪 | SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP | siyuan-note | siyuan | Critical | 10.0 | 2026-07-25 10:45:56 | Deep Dive |
| CVE-2026-66374 🧪 | nic Knot Resolver 输入验证错误漏洞 | nic | Knot Resolver | High | 8.1 | 2026-07-25 00:28:34 | Deep Dive |
| CVE-2026-66373 🧪 | Redis 资源管理错误漏洞 | Redis | Redis | High | 7.5 | 2026-07-25 00:08:36 | Deep Dive |
| CVE-2025-71408 🧪 | NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments | ntlk | ntlk | High | 7.8 | 2026-07-24 21:07:50 | Deep Dive |
| CVE-2026-48036 🧪 | Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts | kerberosmansour | hulumi | High | 8.4 | 2026-07-24 18:44:06 | Deep Dive |
| CVE-2026-48035 🧪 | Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened | kerberosmansour | hulumi | High | 7.1 | 2026-07-24 18:43:36 | Deep Dive |
| CVE-2026-48033 🧪 | Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name | kerberosmansour | hulumi | High | 8.4 | 2026-07-24 18:39:19 | Deep Dive |
| CVE-2026-48032 🧪 | Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers | kerberosmansour | hulumi | High | 8.3 | 2026-07-24 18:39:05 | Deep Dive |
| CVE-2026-48034 🧪 | HULUMI-H5 bypass via decoy sibling resources targeting a different bucket | kerberosmansour | hulumi | High | 8.5 | 2026-07-24 18:38:54 | Deep Dive |
| CVE-2026-48021 🧪 | epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau | med-united | epa4all | Critical | 9.1 | 2026-07-24 18:26:58 | Deep Dive |