| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-63048 🧪 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 | joomlack.fr | Page Builder CK extension for Joomla | Critical | 9.4 | 2026-07-22 07:15:26 | Deep Dive |
| CVE-2026-56820 🧪 | Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks | netty | netty | High | 7.4 | 2026-07-21 22:26:17 | Deep Dive |
| CVE-2026-56819 🧪 | Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) | netty | netty | High | 7.5 | 2026-07-21 22:11:17 | Deep Dive |
| CVE-2026-56816 🧪 | Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types | netty | netty | High | 7.5 | 2026-07-21 21:56:36 | Deep Dive |
| CVE-2026-65319 🧪 | Feedbin Unauthenticated Entry Content Disclosure via GET /api/v2/entries/:id/text | Feedbin | Feedbin | High | 7.5 | 2026-07-21 21:40:54 | Deep Dive |
| CVE-2026-61211 🧪 | Oracle Database Server 安全漏洞 | Oracle Corporation | Oracle Database Server | Critical | 9.9 | 2026-07-21 21:38:46 | Deep Dive |
| CVE-2026-65318 🧪 | Verba (goldenverba) Unauthenticated Server-Side Request Forgery via WebSocket Import Endpoint HTMLReader | Weaviate | Verba | High | 8.6 | 2026-07-21 21:36:24 | Deep Dive |
| CVE-2026-47731 🧪 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker) | NASA-AMMOS | AIT-Core | Critical | 9.1 | 2026-07-21 21:36:23 | Deep Dive |
| CVE-2026-43947 🧪 | FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass | frangoteam | FUXA | High | 8.9 | 2026-07-21 21:33:10 | Deep Dive |
| CVE-2026-65317 🧪 | Verba (goldenverba) Server-Side Request Forgery via /api/connect and Same-Origin Middleware Bypass | Weaviate | Verba | High | 8.6 | 2026-07-21 21:31:02 | Deep Dive |
| CVE-2026-16484 🧪 | SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection | SourceCodester | Class and Exam Timetabling System | High | 7.3 | 2026-07-21 21:30:09 | Deep Dive |
| CVE-2026-55851 🧪 | Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion | netty | netty | High | 8.7 | 2026-07-21 21:22:35 | Deep Dive |
| CVE-2026-65315 🧪 | Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser | Ollama | Ollama | High | 7.5 | 2026-07-21 21:18:25 | Deep Dive |
| CVE-2026-47247 🧪 | libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation | strukturag | libheif | High | 7.5 | 2026-07-21 21:17:00 | Deep Dive |
| CVE-2026-65057 🧪 | Keep Unauthenticated Server-Side Request Forgery via POST /providers/healthcheck | keephq | keep | Critical | 9.3 | 2026-07-21 20:56:10 | Deep Dive |
| CVE-2026-47697 🧪 | Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data | Shelf-nu | shelf.nu | High | 7.1 | 2026-07-21 20:53:19 | Deep Dive |
| CVE-2026-47695 🧪 | CC-Tweaked has an SSRF Protection Bypass with NAT64 | cc-tweaked | CC-Tweaked | High | 7.1 | 2026-07-21 20:51:08 | Deep Dive |
| CVE-2026-47237 🧪 | Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Authorization Token Stealing | kubeflow | community-distribution | High | 8.0 | 2026-07-21 20:49:18 | Deep Dive |
| CVE-2026-65056 🧪 | mcp-webresearch Server-Side Request Forgery in visit_page Due to Missing Internal-IP Filtering | mzxrai | mcp-webresearch | High | 8.2 | 2026-07-21 20:48:51 | Deep Dive |
| CVE-2026-47690 🧪 | MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow | meltano | hub | High | 7.5 | 2026-07-21 20:46:26 | Deep Dive |