CVE ID :CVE-2026-67595 Published : July 29, 2026, 10:16 p.m. | 2 hours, 21 minutes ago Description :VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible…
CVE-2026-13308 – Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
CVE ID :CVE-2026-13308 Published : July 29, 2026, 9:17 p.m. | 3 hours, 20 minutes ago Description :Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers…
CVE-2026-6267 – Insertion of Sensitive Information Into Sent Data in GitLab
CVE ID :CVE-2026-6267 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before…
CVE-2026-67436 – Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVE ID :CVE-2026-67436 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier,…
CVE-2026-67431 – MCP Ruby SDK: Ruby SSE Session Poisoning
CVE ID :CVE-2026-67431 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to…
CVE-2026-64863 – goshs –no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE ID :CVE-2026-64863 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go…
CVE-2026-62325 – goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVE ID :CVE-2026-62325 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the…
CVE-2026-54658 – @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVE ID :CVE-2026-54658 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape…
CVE-2026-54650 – openhole-server vulnerable to path traversal via URL-decoded request path
CVE ID :CVE-2026-54650 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded…
CVE-2026-54691 – datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects
CVE ID :CVE-2026-54691 Published : July 28, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts –url targets…