Casky.AI
BlogFree GuideAboutEnterpriseCommunityContributeCVE WatchCareers
Sign inGet Access
Get Access
Updated daily · NVD + CISA KEV

CVE Watch

Investigate real vulnerabilities with AI guidance. Every major CVE is MITRE-tagged, CVSS-scored, and paired with an Evidence Mode investigation — so you understand the threat, not just the patch number.

CVE-2026-127218.6 HIGHJul 31, 2026

Kirki WordPress Plugin SQL Injection via Unsanitized Request Input

322skills
CVE-2026-152588.1 HIGHJul 31, 2026

WooCommerce Product Feed Manager SQL Injection Flaw

322skills
CVE-2026-566708.2 HIGHJul 31, 2026

Stored XSS via SVG Upload in ComfyUI /view Endpoint

322skills
CVE-2026-566717.5 HIGHJul 31, 2026

Path Traversal in ComfyUI Model Preview Functionality

351skills
CVE-2026-566728.2 HIGHJul 31, 2026

Stored XSS in ComfyUI File Upload Handler

322skills
CVE-2026-566737.5 HIGHJul 31, 2026

Path Traversal in ComfyUI Image Loading Allows Arbitrary File Access

351skills
CVE-2026-632219.4 CRITICALJul 31, 2026

CodeIgniter Query Builder SQL Injection in deleteBatch()

322skills
CVE-2026-632227.5 HIGHJul 31, 2026

CodeIgniter Path Traversal in Unsanitized File Uploads

351skills
CVE-2026-632239.8 CRITICALJul 31, 2026

CodeIgniter Upload Validation Bypass Enables Code Execution

446skills
CVE-2026-133927.2 HIGHJul 31, 2026

Arbitrary PHP Code Execution via Unsafe Widget Definition Storage

322skills
CVE-2026-122518.1 HIGHJul 31, 2026

WordPress Ultimate Member Plugin Allows Unauthenticated Admin Registration

224skills
CVE-2026-148307.5 HIGHJul 31, 2026

WordPress FlxWoo Plugin Bypasses Payment Verification

283skills
CVE-2026-1845210 CRITICALJul 31, 2026

Hard-Coded API Key Enables Unauthenticated DMS+ Device Control

233skills
CVE-2026-126958.1 HIGHJul 31, 2026

WordPress 2FA Plugin Fails to Validate One-Time Passwords

283skills
CVE-2026-127207.5 HIGHJul 31, 2026

Unauthenticated PHP Object Injection in Kirki WordPress Plugin

446skills
CVE-2026-136098.8 HIGHJul 31, 2026

Double-Encoded Payload Bypass Enables Stored XSS in WordPress Admin Plugin

322skills
CVE-2026-143197.5 HIGHJul 31, 2026

GiveWP Plugin Exposes Donor Information via Unauthenticated API

284skills
CVE-2026-143337.5 HIGHJul 31, 2026

WordPress Plugin Stores Backups in Publicly Accessible Location

224skills
CVE-2026-144839.8 CRITICALJul 31, 2026

WordPress Real Estate Plugins Allow Unauthenticated Arbitrary File Upload

446skills
CVE-2026-149199.8 CRITICALJul 31, 2026

WordPress Plugin Allows Unauthenticated Email Interception

283skills
CVE-2026-149307.5 HIGHJul 31, 2026

Unauthenticated File Upload in JS Help Desk Plugin

283skills
CVE-2026-150487.5 HIGHJul 31, 2026

Geeky Bot Plugin Exposes User Data via Unprotected AJAX

284skills
CVE-2026-162368.8 HIGHJul 31, 2026

WordPress Plugin Allows Arbitrary File Upload via REST API

446skills
CVE-2026-653097.5 HIGHJul 31, 2026

Reversible Password Storage Enables Credential Recovery

301skills
CVE-2026-653107.5 HIGHJul 31, 2026

Unauthenticated Data Access in ANDRITZ HIPASE-250 Configuration

283skills
CVE-2026-653138.1 HIGHJul 31, 2026

Hard-Coded VNC Credentials in HIPASE Engineering Workstations

233skills
CVE-2026-100798.5 HIGHJul 31, 2026

Kubernetes Deployment Identity Spoofing in Red Hat ACS

446skills
CVE-2026-117707.5 HIGHJul 31, 2026

LDAP Filter Injection in 389 Directory Server Replication

0skills
CVE-2026-157227.5 HIGHJul 31, 2026

Stack Buffer Overflow in 389 Directory Server RUV Parsing

0skills
CVE-2026-125007.5 HIGHJul 30, 2026

WP Travel Engine Plugin Lacks AJAX Capability Verification

283skills

Investigate every CVE — not just patch it

Casky's multi-agent pipeline uses CVE context to generate a structured investigation plan before a single skill runs. Run your first investigation free — no simulation, your actual security work.

Start investigating CVEs free →
XInstagramLinkedIn
TikTok
TermsPrivacyLegal Disclaimer

© 2026 Casky.AI, Inc. · AI Security Investigation