Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 19

Found 21067 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-55765 🧪 CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod cloudnative-pg cloudnative-pg High 8.5 2026-08-20 21:38:48 Deep Dive
CVE-2026-72860 🧪 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable decolua 9router High 8.5 2026-08-20 21:35:15 Deep Dive
CVE-2026-46355 🧪 BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser bigbluebutton bigbluebutton High 7.1 2026-08-20 21:34:41 Deep Dive
CVE-2026-46682 🧪 BigBlueButton: Blind SQL Injection AUTH (Moderator) bigbluebutton bigbluebutton High 8.5 2026-08-20 21:33:56 Deep Dive
CVE-2026-55893 🧪 Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode capstone-engine capstone High 7.3 2026-08-20 21:32:47 Deep Dive
CVE-2026-74836 🧪 HTTP/2 connection-window starvation pins Plug processes indefinitely in Bandit mtrudel bandit High 8.7 2026-08-20 21:11:19 Deep Dive
CVE-2026-69242 🧪 libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident write libvips libvips High 8.4 2026-08-20 21:02:58 Deep Dive
CVE-2026-71485 🧪 Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends centrifugal centrifugo Critical 9.1 2026-08-20 21:01:01 Deep Dive
CVE-2026-73040 🧪 Dockge Path Traversal via Unvalidated Stack Name Allows Arbitrary Compose and .env Disclosure and Arbitrary Directory Deletion louislam dockge High 8.8 2026-08-20 20:29:00 Deep Dive
CVE-2026-50190 🧪 Shaarli vulnerable to stored XSS via raw bookmark title in document <title> element on public permalink page shaarli Shaarli High 8.6 2026-08-20 18:49:49 Deep Dive
CVE-2026-66001 🧪 Frappe: Improper Authorization in OAuth2 Consent Endpoint frappe frappe High 8.5 2026-08-20 18:27:32 Deep Dive
CVE-2026-62315 🧪 Frappe: Mass assignment via set_value frappe frappe High 7.1 2026-08-20 18:25:01 Deep Dive
CVE-2026-72852 🧪 darknet Integer Overflow in Convolutional Layer Buffer Sizing Leads to Heap Buffer Overflow hank-ai darknet High 7.8 2026-08-20 18:19:24 Deep Dive
CVE-2026-77148 🧪 Comfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow Comfast CF-N1-S Critical 9.9 2026-08-20 18:15:09 Deep Dive
CVE-2026-2334 🧪 ) Missing Server-Side File Extension Validation in vsDesk vsDesk vsDesk Critical 9.4 2026-08-20 18:03:39 Deep Dive
CVE-2026-54623 🧪 django CMS: Plugin move endpoint allows cyclic reparenting (DoS) django-cms django-cms High 7.1 2026-08-20 18:02:46 Deep Dive
CVE-2026-63385 🧪 Libevent: HTTP header handling bugs create risk of access control bypass. libevent libevent Critical 9.2 2026-08-20 17:55:36 Deep Dive
CVE-2026-63387 🧪 Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response libevent libevent High 7.0 2026-08-20 17:53:42 Deep Dive
CVE-2026-63384 🧪 Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value. libevent libevent High 8.7 2026-08-20 17:53:08 Deep Dive
CVE-2026-63382 🧪 libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling libevent libevent Critical 9.2 2026-08-20 17:51:15 Deep Dive