| # | Advisory | CVE | Product | Published |
|---|---|---|---|---|
| 1 | Session id path traversal in spiral/session leading to arbitrary file write | GHSA-c84m-p8px-4wpx | SpiralVendorSpiral | 2026-07-17 |
| 2 | █████ | █████ | higressVendorAlibaba | - |
| 3 | █████ | █████ | go-zeroVendorgo-zero | - |
| 4 | █████ | █████ | go-zeroVendorgo-zero | - |
| 5 | unauthenticated remote admin via reverse-proxy + localhost-trust | CVE-2026 | GPUStackVendorGPUStack | 2026-06-14 |
| 6 | SSRF via `framework_config.pricing_url` in `/api/config` enables internal network reconnaissance and service banner disclosure | CVE-2026-11574 | BifrostVendorMaxim | 2026-06-05 |
| 7 | █████ | █████ | LighthouseVendorLighthouse | - |
| 8 | Arbitrary file read in CDI importer via attacker-controlled qcow2 backing file | █████ | █████ | - |
| 9 | phpMyFAQ vulnerable to stored XSS on attachments filename | CVE-2024-24574 | phpMyFAQVendorphpMyFAQ | 2024-02-06 |
| 10 | █████ | █████ | SpiralVendorSpiral | - |