| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-65896 🧪 | Grav API Plugin before 1.0.10 Path Traversal via move | getgrav | grav | High | 7.1 | 2026-07-23 11:42:17 | Deep Dive |
| CVE-2026-65897 🧪 | Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups | getgrav | grav | High | 8.8 | 2026-07-23 11:42:17 | Deep Dive |
| CVE-2026-65608 🧪 | Grav before 2.0.9 Remote Code Execution via FlexDirectory | getgrav | grav | High | 8.8 | 2026-07-23 11:42:16 | Deep Dive |
| CVE-2026-65895 🧪 | Grav API Plugin before 1.0.10 Broken Access Control | getgrav | grav | High | 8.5 | 2026-07-23 11:42:16 | Deep Dive |
| CVE-2026-65606 🧪 | SiYuan before v3.7.2 Cross-Site Scripting to RCE | siyuan-note | siyuan | Critical | 9.6 | 2026-07-23 11:42:14 | Deep Dive |
| CVE-2026-65605 🧪 | SiYuan before v3.7.2 Stored XSS to RCE via Attribute View | siyuan-note | siyuan | Critical | 9.6 | 2026-07-23 11:42:14 | Deep Dive |
| CVE-2026-64611 🧪 | Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel() | Red Hat | Red Hat Enterprise Linux 10 | High | 7.5 | 2026-07-23 10:46:50 | Deep Dive |
| CVE-2026-14282 🧪 | GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field | rtcamp | GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more | Critical | 9.8 | 2026-07-23 08:34:42 | Deep Dive |
| CVE-2026-16723 🧪 | Remote Code Execution in fastjson 1.2.68–1.2.83 | Alibaba | Fastjson | Critical | 9.0 | 2026-07-23 08:26:24 | Deep Dive |
| CVE-2026-16632 🧪 | boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation | boazsegev | facil.io | High | 7.3 | 2026-07-22 23:45:10 | Deep Dive |
| CVE-2026-64829 🧪 | Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow | q2a | question2answer | High | 7.4 | 2026-07-22 19:57:30 | Deep Dive |
| CVE-2026-14881 🧪 | Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow | MongoDB | MongoDB Compass | High | 7.8 | 2026-07-22 19:23:17 | Deep Dive |
| CVE-2026-65013 🧪 | Onlook tRPC Insecure Direct Object Reference via multiple procedures | onlook | repo | High | 8.8 | 2026-07-22 16:14:23 | Deep Dive |
| CVE-2026-48029 🧪 | libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow | strukturag | libheif | High | 7.1 | 2026-07-22 14:13:28 | Deep Dive |
| CVE-2026-2395 📌 | SQLi in Xpoda Türkiye Informatics Technology's No Code Platform | Xpoda Türkiye Informatics Technology Inc. | No Code Platform | Critical | 9.8 | 2026-07-22 14:02:08 | Deep Dive |
| CVE-2026-16232 KEV 📌 💣 | Authentication Bypass in the SmartConsole Login Process Using an Application Token EPSS 0.78 | checkpoint | Quantum Security Management | Critical | 9.3 | 2026-07-22 13:53:10 | Deep Dive |
| CVE-2026-13181 🧪 | RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX | Progress Software | Telerik UI for ASP.NET AJAX | High | 8.1 | 2026-07-22 13:33:18 | Deep Dive |
| CVE-2026-65603 🧪 | Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update | getgrav | grav | High | 8.8 | 2026-07-22 11:21:49 | Deep Dive |
| CVE-2026-65600 🧪 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | traefik | traefik | High | 7.8 | 2026-07-22 11:21:47 | Deep Dive |
| CVE-2026-2406 📌 | IDOR in Universe Software's Online Registration and Workflow Management System | Universe Software Computer Marketing Trade and Industry Inc. | Online Registration and Workflow Management System | Medium | 6.5 | 2026-07-22 08:51:21 | Deep Dive |