| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-54342 🧪 | TLS Certificate Verification Disabled on CXF Transport Clients in epa4all | med-united | epa4all | High | 8.1 | 2026-07-24 18:26:35 | Deep Dive |
| CVE-2026-66035 🧪 | libssh2 Heap Buffer Overflow via ETM Cipher Negotiation | libssh2 | libssh2 | High | 7.5 | 2026-07-24 16:45:24 | Deep Dive |
| CVE-2026-66034 🧪 | libssh2 Heap Out-of-Bounds Read via publickey subsystem | libssh2 | libssh2 | High | 7.5 | 2026-07-24 16:42:19 | Deep Dive |
| CVE-2026-66033 🧪 | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation | libssh2 | libssh2 | High | 7.5 | 2026-07-24 16:35:29 | Deep Dive |
| CVE-2026-66032 🧪 | libssh2 Double-Free Heap Corruption via sftp_open() | libssh2 | libssh2 | High | 8.8 | 2026-07-24 16:32:40 | Deep Dive |
| CVE-2026-65623 🧪 | Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit | mtrudel | bandit | High | 8.7 | 2026-07-24 16:32:25 | Deep Dive |
| CVE-2026-65710 🧪 | sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption | nuxsmin | sysPass | High | 7.1 | 2026-07-24 16:00:51 | Deep Dive |
| CVE-2026-65709 🧪 | sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API | nuxsmin | sysPass | High | 8.3 | 2026-07-24 15:59:27 | Deep Dive |
| CVE-2026-65708 🧪 | sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController | nuxsmin | sysPass | High | 8.1 | 2026-07-24 15:57:26 | Deep Dive |
| CVE-2026-66027 🧪 | Suna < 0.9.102 Broken Access Control via Message Queue API | kortix-ai | suna | High | 8.3 | 2026-07-24 15:27:05 | Deep Dive |
| CVE-2026-15704 🧪 | CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components | Eclipse Foundation | Eclipse BaSyx Go Components | Critical | 9.8 | 2026-07-24 07:41:43 | Deep Dive |
| CVE-2026-16765 🧪 | CodeAstro Online Classroom loginlinkadmin.php sql injection | CodeAstro | Online Classroom | High | 7.3 | 2026-07-23 21:45:10 | Deep Dive |
| CVE-2026-65694 📌 💣 | Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController | microweber | microweber | High | 7.5 | 2026-07-23 21:20:29 | Deep Dive |
| CVE-2026-65604 🧪 | Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass | zalando | skipper | High | 8.2 | 2026-07-23 21:16:48 | Deep Dive |
| CVE-2026-63732 🧪 | 9router before 0.4.60 Remote Code Execution via default password | decolua | 9router | Critical | 9.9 | 2026-07-23 21:16:46 | Deep Dive |
| CVE-2026-63313 🧪 | 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch | decolua | 9router | High | 7.7 | 2026-07-23 21:16:46 | Deep Dive |
| CVE-2026-47724 🧪 | nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation | juev | nebula-mesh | Critical | 9.9 | 2026-07-23 20:20:59 | Deep Dive |
| CVE-2026-47723 🧪 | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) | juev | nebula-mesh | High | 7.1 | 2026-07-23 20:17:26 | Deep Dive |
| CVE-2026-16796 🧪 | Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() | AWS | bedrock-agentcore 1.18.1 | High | 7.3 | 2026-07-23 20:06:33 | Deep Dive |
| CVE-2026-47722 🧪 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | juev | nebula-mesh | High | 8.7 | 2026-07-23 19:19:42 | Deep Dive |