Daily digest
Tuesday 28 July 2026
58 new CVEs this day, in line with the recent average. Severity skewed high: 5 critical and 34 high, 67% of the total. One arrived with exploitation evidence or public exploit code already attached. datamodel-code-generator was the most-affected vendor with 12.
New this day, ranked by depth score
The 12 that matter most of the 58 published.
CVE-2026-66748High· 8.8PoCCamaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…
CVE-2026-54658Critical· 9.8@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVE-2026-54588Critical· 9.6Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
CVE-2026-11841Critical· 9.4An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed throu…
CVE-2026-64863Critical· 9.1goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-62325Critical· 9.1goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
CVE-2026-55771High· 8.8Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
CVE-2026-54653High· 8.8`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
CVE-2026-54639High· 8.8Style Dictionary - Prototype Pollution in convertTokenData utility function
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-54650High· 8.6openhole exposes localhost to the internet in one command
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing…
CVE-2026-54609High· 8.6QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVE-2026-54603High· 8.6OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)
OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…
Most-changed records
Existing CVEs whose severity, score, KEV or exploitation status moved.
- CVE-2025-49619Skyvern has a Jinja runtime leakepss63
Most-affected vendors
By CVEs published in the period.