Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 15

Found 21062 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-48050 🧪 Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS Basekick-Labs arc High 8.8 2026-08-21 22:40:13 Deep Dive
CVE-2026-53499 🧪 FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning NICMx FORT-validator High 7.2 2026-08-21 22:29:49 Deep Dive
CVE-2026-53525 🧪 WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication weechat weechat High 7.4 2026-08-21 22:19:21 Deep Dive
CVE-2026-53528 🧪 FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter perber leafwiki High 8.8 2026-08-21 21:26:58 Deep Dive
CVE-2026-53527 🧪 LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update perber leafwiki High 8.8 2026-08-21 21:25:16 Deep Dive
CVE-2026-49849 🧪 xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution 4xmen xshop Critical 9.1 2026-08-21 21:14:24 Deep Dive
CVE-2026-50538 🧪 libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write LibVNC libvncserver High 8.8 2026-08-21 21:03:58 Deep Dive
CVE-2026-77415 🧪 JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata-js jsonata Critical 9.3 2026-08-21 21:01:09 Deep Dive
CVE-2026-77414 🧪 JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata-js jsonata Critical 9.3 2026-08-21 20:51:44 Deep Dive
CVE-2026-77413 🧪 JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata-js jsonata Critical 9.3 2026-08-21 20:47:08 Deep Dive
CVE-2026-77354 🧪 kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decoding getkin kin-openapi High 8.7 2026-08-21 20:44:48 Deep Dive
CVE-2026-63135 🧪 YOURLS: Stored XSS in referrer statistics chart via crafted Referer header YOURLS YOURLS High 8.2 2026-08-21 20:40:08 Deep Dive
CVE-2026-61539 🧪 Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing xorbitsai inference Critical 10.0 2026-08-21 20:37:03 Deep Dive
CVE-2026-54457 🧪 TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint tensorzero tensorzero High 7.7 2026-08-21 20:34:04 Deep Dive
CVE-2026-64679 🧪 Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation runatlantis atlantis High 8.1 2026-08-21 20:29:55 Deep Dive
CVE-2026-59989 🧪 Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE) phalcon cphalcon Critical 9.2 2026-08-21 20:25:45 Deep Dive
CVE-2026-62283 🧪 Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check nezhahq nezha Critical 9.9 2026-08-21 20:21:29 Deep Dive
CVE-2026-77219 🧪 GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader GNU Emacs High 7.1 2026-08-21 20:20:45 Deep Dive
CVE-2026-62316 🧪 Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution microsoft UFO High 8.8 2026-08-21 20:17:21 Deep Dive
CVE-2026-63421 🧪 Keystone: `graphql.maxTake` bypass with negative `take` keystonejs keystone High 7.5 2026-08-21 20:15:16 Deep Dive