| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-44907 🧪 | react-server-dom-turbopack 反序列化漏洞 | Meta | react-server-dom-turbopack | High | 7.5 | 2026-07-21 16:03:32 | Deep Dive |
| CVE-2026-47398 🧪 | PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334 | MervinPraison | PraisonAI | High | 8.1 | 2026-07-21 16:01:22 | Deep Dive |
| CVE-2026-47397 🧪 | PraisonAI has an Arbitrary File Write in Python API | MervinPraison | PraisonAI | High | 7.1 | 2026-07-21 15:57:26 | Deep Dive |
| CVE-2026-47396 🧪 | PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset | MervinPraison | PraisonAI | Critical | 9.8 | 2026-07-21 15:55:23 | Deep Dive |
| CVE-2026-47393 🧪 | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default | MervinPraison | PraisonAI | Critical | 9.8 | 2026-07-21 15:39:28 | Deep Dive |
| CVE-2026-47392 🧪 | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) | MervinPraison | PraisonAI | Critical | 9.9 | 2026-07-21 15:27:17 | Deep Dive |
| CVE-2026-47391 🧪 | PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution | MervinPraison | PraisonAI | Critical | 9.8 | 2026-07-21 15:21:23 | Deep Dive |
| CVE-2026-16445 🧪 | Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module | Red Hat | Red Hat Enterprise Linux 8 | High | 7.5 | 2026-07-21 12:51:09 | Deep Dive |
| CVE-2026-65008 🧪 💣 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | getgrav | grav | Critical | 9.8 | 2026-07-21 11:39:57 | Deep Dive |
| CVE-2026-65007 🧪 | Grav before 1.0.8 Missing Authorization on API Key Generation | getgrav | grav | Critical | 9.6 | 2026-07-21 11:39:56 | Deep Dive |
| CVE-2026-55833 🧪 | Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation | netty | netty | High | 7.5 | 2026-07-20 23:18:08 | Deep Dive |
| CVE-2026-55831 🧪 | Netty SPDY SETTINGS frame count materializes unbounded settings map | netty | netty | High | 7.5 | 2026-07-20 23:00:32 | Deep Dive |
| CVE-2026-47255 🧪 | AgenticMail API/storage and outbound relay hardening | agenticmail | @agenticmail/api | High | 8.2 | 2026-07-20 21:56:40 | Deep Dive |
| CVE-2026-64624 🧪 | FreeRDP RDP File Parser Remote Code Execution via CLI Options | FreeRDP | FreeRDP | High | 7.8 | 2026-07-20 21:50:54 | Deep Dive |
| CVE-2026-55550 🧪 | NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product Catalog | pdovhomilja | nextcrm-app | High | 7.1 | 2026-07-20 21:02:17 | Deep Dive |
| CVE-2026-55544 🧪 | NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering | pdovhomilja | nextcrm-app | High | 7.6 | 2026-07-20 20:57:20 | Deep Dive |
| CVE-2026-47130 🧪 | NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering | pdovhomilja | nextcrm-app | High | 7.1 | 2026-07-20 20:49:39 | Deep Dive |
| CVE-2026-47129 🧪 | NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts | pdovhomilja | nextcrm-app | High | 8.1 | 2026-07-20 20:34:56 | Deep Dive |
| CVE-2026-47198 🧪 | Paymenter: URL parameter injection bypasses paid plan limits at checkout | Paymenter | Paymenter | High | 8.5 | 2026-07-20 20:18:21 | Deep Dive |
| CVE-2026-53595 🧪 💣 | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL | freescout-help-desk | freescout | Critical | 9.4 | 2026-07-20 20:14:59 | Deep Dive |