| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-56164 KEV | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Microsoft | Microsoft SharePoint Enterprise Server 2016 | Medium | 5.3 | 2026-07-14 17:05:12 | Deep Dive |
| CVE-2026-56291 KEV 🧪 💣 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 EPSS 0.15 | balbooa.com | balbooa.com Balbooa Forms extension for Joomla | Critical | 10.0 | 2026-07-09 09:53:58 | Deep Dive |
| CVE-2026-59822 KEV | LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | BerriAI | litellm | High | 8.8 | 2026-07-08 19:32:19 | Deep Dive |
| CVE-2026-53362 KEV | ipv6: account for fraggap on the paged allocation path | Linux | Linux | High | 7.8 | 2026-07-04 11:56:36 | Deep Dive |
| CVE-2026-48282 KEV 🧪 💣 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) EPSS 0.42 | Adobe | ColdFusion 2025 | Critical | 10.0 | 2026-06-30 15:11:57 | Deep Dive |
| CVE-2026-8452 KEV | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service | NetScaler | ADC | High | 8.8 | 2026-06-30 12:41:08 | Deep Dive |
| CVE-2026-56290 KEV 🧪 💣 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 EPSS 0.31 | joomlack.fr | JoomlaCK.fr Page Builder CK extension for Joomla | Critical | 10.0 | 2026-06-29 14:31:38 | Deep Dive |
| CVE-2026-49869 KEV 🧪 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` | kestra-io | kestra | Critical | 10.0 | 2026-06-26 20:58:20 | Deep Dive |
| CVE-2026-53266 KEV | netfilter: bridge: make ebt_snat ARP rewrite writable | Linux | Linux | High | 8.8 | 2026-06-25 08:39:53 | Deep Dive |
| CVE-2026-55255 KEV 🧪 | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow | langflow-ai | langflow | High | 8.4 | 2026-06-23 16:28:21 | Deep Dive |
| CVE-2026-48908 KEV 📌 | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 EPSS 0.89 | joomshaper.net | SP Page Builder extension for Joomla | Critical | 10.0 | 2026-06-20 11:57:01 | Deep Dive |
| CVE-2026-48939 KEV 📌 💣 | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 EPSS 0.20 | icagenda.com | iCagenda extension for Joomla | Critical | 10.0 | 2026-06-20 11:56:51 | Deep Dive |
| CVE-2026-12569 KEV | Remote Code Execution (RCE) vulnerability in Windchill PDMlink EPSS 0.46 | PTC | Windchill PDMLink | Critical | 9.3 | 2026-06-18 00:11:35 | Deep Dive |
| CVE-2026-7273 KEV | Zyxel GS1900-48HPv2 firmware 缓冲区错误漏洞 | Zyxel | GS1900-48HPv2 firmware | High | 8.8 | 2026-06-16 02:20:30 | Deep Dive |
| CVE-2026-20262 KEV | Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability EPSS 0.28 | Cisco | Cisco Catalyst SD-WAN Manager | Medium | 6.5 | 2026-06-15 16:21:10 | Deep Dive |
| CVE-2026-54420 KEV | LiteSpeed cPanel Plugin 后置链接漏洞 | LiteSpeed Technologies | cPanel Plugin | High | 8.5 | 2026-06-14 03:23:13 | Deep Dive |
| CVE-2026-48558 KEV 📌 💣 | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification | SimpleHelp | SimpleHelp | Critical | 10.0 | 2026-06-12 17:07:05 | Deep Dive |
| CVE-2026-35273 KEV 📌 💣 | Oracle PeopleSoft Enterprise PeopleTools 访问控制错误漏洞 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | Critical | 9.8 | 2026-06-11 02:25:15 | Deep Dive |
| CVE-2026-20253 KEV 🧪 💣 | Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise EPSS 0.97 | Splunk | Splunk Enterprise | Critical | 9.8 | 2026-06-10 17:16:21 | Deep Dive |
| CVE-2026-25089 KEV | Fortinet多款产品 操作系统命令注入漏洞 EPSS 0.76 | Fortinet | FortiSandbox | Critical | 9.8 | 2026-06-09 14:27:47 | Deep Dive |