Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

Vulnerability List - Page 65

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-44577 Next.js: Denial of Service in the Image Optimization API vercelnext.js Medium 5.9 2026-05-13 17:00:03 Deep Dive
CVE-2026-44576 Next.js: Cache poisoning in React Server Component responses vercelnext.js Medium 5.4 2026-05-13 16:57:11 Deep Dive
CVE-2026-44574 Next.js: Middleware / Proxy bypass through dynamic route parameter injection vercelnext.js High 8.1 2026-05-13 16:56:06 Deep Dive
CVE-2026-44575 Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes vercelnext.js High 7.5 2026-05-13 16:54:39 Deep Dive
CVE-2026-44573 Next.js: Middleware / Proxy bypass in Pages Router applications using i18n vercelnext.js High 7.5 2026-05-13 16:48:16 Deep Dive
CVE-2026-2695 Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises) TeamViewerDEX (On-Premises) Medium 6.3 2026-05-13 16:09:09 Deep Dive
CVE-2026-44572 Next.js: Middleware / Proxy redirects can be cache-poisoned vercelnext.js Low 3.7 2026-05-13 15:57:16 Deep Dive
CVE-2025-32425 AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS Significant-GravitasAutoGPT--2026-05-13 15:55:03 Deep Dive
CVE-2026-45028 Astro: Server island encrypted parameters vulnerable to cross-component replay withastroastro--2026-05-13 15:50:50 Deep Dive
CVE-2026-45033 GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor githubcopilot-cli--2026-05-13 15:45:27 Deep Dive
CVE-2026-44470 Claude Desktop: Local Privilege Escalation via Directory Junction in CoworkVMService anthropicsclaude-code--2026-05-13 15:41:48 Deep Dive
CVE-2026-44467 Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions anthropicsclaude-code--2026-05-13 15:40:42 Deep Dive
CVE-2026-44479 Vercel: Non-interactive mode includes CLI arguments in suggested command output vercelvercel Medium 5.5 2026-05-13 15:36:37 Deep Dive
CVE-2026-44664 fast-xml-builder: Comment Value bypass regex NaturalIntelligencefast-xml-builder Medium 6.1 2026-05-13 15:27:35 Deep Dive
CVE-2026-44665 fast-xml-builder: Attribute values with unwanted quotes can bypass malicious or unwanted attributes NaturalIntelligencefast-xml-builder Medium 6.1 2026-05-13 15:24:55 Deep Dive
CVE-2026-44431 urllib3: Sensitive headers forwarded across origins in proxied low-level redirects urllib3urllib3--2026-05-13 15:20:25 Deep Dive
CVE-2026-44432 urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API urllib3urllib3--2026-05-13 15:17:13 Deep Dive
CVE-2026-42266 jupyterlab: Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request. jupyterlabjupyterlab High 8.8 2026-05-13 15:08:50 Deep Dive
CVE-2026-43489 liveupdate: luo_file: remember retrieve() status LinuxLinux--2026-05-13 15:08:34 Deep Dive
CVE-2026-43487 ata: libata-core: Disable LPM on ST1000DM010-2EP102 LinuxLinux--2026-05-13 15:08:33 Deep Dive