| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-44178 🧪 | xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow | neutrinolabs | xrdp | High | 8.8 | 2026-07-20 16:54:31 | Deep Dive |
| CVE-2026-41521 🧪 | xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass | neutrinolabs | xrdp | High | 8.2 | 2026-07-20 16:41:44 | Deep Dive |
| CVE-2026-46701 🧪 | Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret | Jovancoding | Network-AI | High | 7.6 | 2026-07-20 16:33:44 | Deep Dive |
| CVE-2026-41252 🧪 | xrdp: lib_palette_update Heap Buffer Overflow & RCE | neutrinolabs | xrdp | Critical | 9.8 | 2026-07-20 16:29:53 | Deep Dive |
| CVE-2026-35048 🧪 | Piwigo RCE via PHP Code Injection into Config File in Installer | Piwigo | Piwigo | Critical | 9.8 | 2026-07-20 16:27:10 | Deep Dive |
| CVE-2026-54051 🧪 | Network-AI has an an OS Command Injection issue | Jovancoding | Network-AI | Critical | 9.9 | 2026-07-20 16:24:21 | Deep Dive |
| CVE-2026-35590 🧪 | Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata | libvips | libvips | 中危 | - | 2026-07-20 16:23:34 | Deep Dive |
| CVE-2026-33328 🧪 | Possible integer overflow on 32-bit systems when reading GIF images | libvips | libvips | 中危 | - | 2026-07-20 16:22:22 | Deep Dive |
| CVE-2026-32825 🧪 | dataCycle No Brute-Force Protection On Web And API Login Endpoints | datacycle-engine | dataCycle-CORE | High | 7.3 | 2026-07-20 16:15:37 | Deep Dive |
| CVE-2026-32824 🧪 | dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redirect Targets | datacycle-engine | dataCycle-CORE | High | 7.3 | 2026-07-20 16:14:03 | Deep Dive |
| CVE-2026-32821 🧪 | API Collection Impersonation Via user_email And Missing Object- Level Authorization | datacycle-engine | dataCycle-CORE | High | 8.1 | 2026-07-20 16:11:29 | Deep Dive |
| CVE-2026-32806 🧪 | dataCycle Authorization Bypass Via /remote_render | datacycle-engine | dataCycle-CORE | High | 7.5 | 2026-07-20 16:10:18 | Deep Dive |
| CVE-2026-32820 🧪 | dataCycle Public Markdown Path Traversal Via /docs/*path | datacycle-engine | dataCycle-CORE | High | 7.5 | 2026-07-20 16:09:06 | Deep Dive |
| CVE-2026-63429 🧪 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context | heyform | heyform | High | 8.6 | 2026-07-20 15:54:22 | Deep Dive |
| CVE-2026-35198 🧪 | HeyForm vulnerable to stored XSS via form field titles | heyform | heyform | Critical | 9.0 | 2026-07-20 15:47:21 | Deep Dive |
| CVE-2026-32807 🧪 | dataCycle Public DataLink Text File Download Ignores Validity And Authorization | datacycle-engine | dataCycle-CORE | High | 7.5 | 2026-07-20 15:31:31 | Deep Dive |
| CVE-2026-28220 🧪 | Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node | wazuh | wazuh | High | 8.4 | 2026-07-20 15:26:13 | Deep Dive |
| CVE-2026-45713 🧪 | Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes | axllent | mailpit | High | 7.5 | 2026-07-20 15:01:01 | Deep Dive |
| CVE-2026-25039 🧪 | The application evaluate UNC path in workspace name | Scille | parsec-cloud | High | 8.8 | 2026-07-20 14:53:14 | Deep Dive |
| CVE-2026-46412 🧪 | Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm | BeProduct | beproduct-org-nestjs-auth | Critical | 10.0 | 2026-07-20 14:31:53 | Deep Dive |