| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-47669 🧪 | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE | dbgate | dbgate | Critical | 9.3 | 2026-07-23 19:13:15 | Deep Dive |
| CVE-2026-47670 🧪 💣 | DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection | dbgate | dbgate | Critical | 9.4 | 2026-07-23 19:12:01 | Deep Dive |
| CVE-2026-25800 🧪 | quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly | quinn-rs | quinn | High | 7.5 | 2026-07-23 19:09:19 | Deep Dive |
| CVE-2026-16756 🧪 | Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service | AWS | aws-smithy-http-server | High | 7.5 | 2026-07-23 18:32:54 | Deep Dive |
| CVE-2026-63765 🧪 | Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation | chatwoot | chatwoot | High | 8.2 | 2026-07-23 17:52:11 | Deep Dive |
| CVE-2026-65919 📌 💣 | Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload | meshery | meshery | High | 7.5 | 2026-07-23 17:39:28 | Deep Dive |
| CVE-2026-65918 🧪 | PyTorch torchvision GIF Decoder Out-of-bounds Heap Read | pytorch | vision | High | 7.1 | 2026-07-23 17:36:43 | Deep Dive |
| CVE-2026-47668 📌 💣 | DbGate: Unauthenticated Remote Code Execution via JSON Script Runner | dbgate | dbgate | Critical | 10.0 | 2026-07-23 17:34:52 | Deep Dive |
| CVE-2026-47743 🧪 | Shopper: Multiple data integrity and disclosure issues in admin Livewire components | shopperlabs | shopper | High | 8.7 | 2026-07-23 17:20:26 | Deep Dive |
| CVE-2026-65702 🧪 | Vanna 2.0.2 Path Traversal via FileSystemConversationStore | vanna-ai | vanna | High | 8.6 | 2026-07-23 17:09:38 | Deep Dive |
| CVE-2026-65701 🧪 | SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route | svc-develop-team | so-vits-svc | Critical | 9.1 | 2026-07-23 17:05:48 | Deep Dive |
| CVE-2026-65700 🧪 | h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API | h2oai | h2ogpt | Critical | 9.8 | 2026-07-23 17:02:24 | Deep Dive |
| CVE-2026-47752 🧪 | Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution | Quenary | tugtainer | Critical | 9.9 | 2026-07-23 16:57:55 | Deep Dive |
| CVE-2026-65761 📌 💣 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 | joomshaper.com | Easy Store extension for Joomla | Critical | 9.3 | 2026-07-23 16:38:59 | Deep Dive |
| CVE-2026-44909 🧪 | Facebook proxygen 资源管理错误漏洞 | proxygen | High | 7.5 | 2026-07-23 16:27:02 | Deep Dive | |
| CVE-2026-65917 🧪 | CyberPanel IncBackups IDOR via Sequential Backup ID | usmannasir | cyberpanel | High | 8.8 | 2026-07-23 15:59:49 | Deep Dive |
| CVE-2026-65916 🧪 | CyberPanel Missing Authorization in cancelBackupCreation Handler | usmannasir | cyberpanel | High | 8.1 | 2026-07-23 15:53:06 | Deep Dive |
| CVE-2026-16584 🧪 | AWS API MCP Server Security Policy Bypass via Startup Failure | AWS | aws-api-mcp-server | High | 7.0 | 2026-07-23 15:34:11 | Deep Dive |
| CVE-2026-65898 🧪 | DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig | cure53 | DOMPurify | High | 7.2 | 2026-07-23 13:16:18 | Deep Dive |
| CVE-2026-14257 🧪 | brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash | juliangruber | brace-expansion | High | 7.5 | 2026-07-23 12:54:23 | Deep Dive |