| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-53593 🧪 | FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471 | freescout-help-desk | freescout | High | 8.8 | 2026-07-20 19:52:33 | Deep Dive |
| CVE-2026-53591 🧪 | FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails | freescout-help-desk | freescout | High | 8.6 | 2026-07-20 19:47:18 | Deep Dive |
| CVE-2026-44231 🧪 | RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint | bestpractical | rt | Critical | 9.1 | 2026-07-20 19:20:44 | Deep Dive |
| CVE-2026-63766 🧪 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | RVC-Boss | GPT-SoVITS | Critical | 9.8 | 2026-07-20 19:18:10 | Deep Dive |
| CVE-2026-63767 🧪 | ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ | kvcache-ai | ktransformers | Critical | 9.8 | 2026-07-20 19:13:43 | Deep Dive |
| CVE-2026-63769 🧪 | Huginn < 2026.09.09 SSRF via ScenarioImport fetch_url Method | huginn | huginn | High | 7.7 | 2026-07-20 19:05:41 | Deep Dive |
| CVE-2026-63770 🧪 | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass | glanceapp | glance | High | 7.5 | 2026-07-20 19:02:37 | Deep Dive |
| CVE-2026-63771 🧪 | Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header | vrana | adminer | High | 7.1 | 2026-07-20 18:57:16 | Deep Dive |
| CVE-2026-64619 🧪 | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers | vastsa | FileCodeBox | High | 7.5 | 2026-07-20 18:50:12 | Deep Dive |
| CVE-2026-63731 🧪 | HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint | hyperdxio | hyperdx | High | 7.7 | 2026-07-20 18:45:14 | Deep Dive |
| CVE-2026-63108 🧪 | Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing | RooCodeInc | Roo-Code | High | 8.8 | 2026-07-20 18:24:15 | Deep Dive |
| CVE-2026-63107 🧪 | LimeSurvey SSRF via REST API Survey Template Host Header | LimeSurvey | LimeSurvey | High | 7.7 | 2026-07-20 18:14:02 | Deep Dive |
| CVE-2026-64612 🧪 | Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png | Red Hat | Red Hat Enterprise Linux 10 | High | 7.5 | 2026-07-20 17:33:02 | Deep Dive |
| CVE-2026-48812 🧪 | FreeScout Allows Unauthenticated Access to Legacy Attachment Files | freescout-help-desk | freescout | High | 7.5 | 2026-07-20 17:32:46 | Deep Dive |
| CVE-2026-55626 🧪 | xrdp: No authentication required with Xvnc backend on RHEL 9 | neutrinolabs | xrdp | High | 8.0 | 2026-07-20 17:11:44 | Deep Dive |
| CVE-2026-39878 🧪 | Chamilo stored XSS via user registration leads to admin account takeover | chamilo | chamilo-lms | Critical | 9.3 | 2026-07-20 17:08:21 | Deep Dive |
| CVE-2026-46555 🧪 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | verygoodplugins | whatsapp-mcp | High | 7.7 | 2026-07-20 17:06:22 | Deep Dive |
| CVE-2026-58484 🧪 | Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning | Jovancoding | Network-AI | High | 7.1 | 2026-07-20 17:00:56 | Deep Dive |
| CVE-2026-54538 🧪 | xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER | neutrinolabs | xrdp | High | 7.5 | 2026-07-20 16:57:33 | Deep Dive |
| CVE-2026-39879 🧪 | SQL injection in syslog-ng SQL destionation driver | syslog-ng | syslog-ng | High | 7.1 | 2026-07-20 16:57:32 | Deep Dive |