Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 35

Found 21069 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-75080 🧪 SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection SourceCodester Class and Exam Timetabling System High 7.3 2026-08-17 23:30:09 Deep Dive
CVE-2026-75079 🧪 SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection SourceCodester Class and Exam Timetabling System High 7.3 2026-08-17 23:15:11 Deep Dive
CVE-2026-71424 🧪 Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers onyx-dot-app onyx Critical 9.6 2026-08-17 21:28:33 Deep Dive
CVE-2026-45790 🧪 Dokploy: Invitation Role Escalation Allows Organization Takeover Dokploy dokploy High 8.0 2026-08-17 21:24:22 Deep Dive
CVE-2026-64849 KEV 📌 💣 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) EPSS 0.16 mlflow mlflow Critical 9.3 2026-08-17 21:16:11 Deep Dive
CVE-2026-56677 🧪 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint decolua 9router High 8.6 2026-08-17 21:14:06 Deep Dive
CVE-2026-71518 🧪 Typemill < 2.26.0 Authorization Bypass via Media File Download Route typemill typemill High 7.5 2026-08-17 21:05:11 Deep Dive
CVE-2026-75531 🧪 Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora pandora-analysis pandora High 7.0 2026-08-17 21:00:13 Deep Dive
CVE-2026-65832 🧪 Deskflow - Unauthenticated server-controlled out-of-bounds read in ServerProxy::setOptions / translateKey modifier-table indexing deskflow deskflow High 8.2 2026-08-17 20:59:09 Deep Dive
CVE-2026-63409 🧪 Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow client deskflow deskflow High 8.2 2026-08-17 20:57:19 Deep Dive
CVE-2026-47683 🧪 vm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike patriksimek vm2 High 8.7 2026-08-17 20:55:32 Deep Dive
CVE-2026-47686 🧪 vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE patriksimek vm2 Critical 9.9 2026-08-17 20:54:39 Deep Dive
CVE-2026-47698 🧪 vm2: Sandbox Breakout Using Dangerous Host Proto Mutators patriksimek vm2 Critical 9.8 2026-08-17 20:53:09 Deep Dive
CVE-2026-65822 🧪 ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter frappe erpnext High 7.6 2026-08-17 20:45:46 Deep Dive
CVE-2026-65974 🧪 ERPNext: Server-Side Template Injection leading to Remote Code Execution frappe erpnext Critical 9.9 2026-08-17 20:44:21 Deep Dive
CVE-2026-75482 🧪 SWE-agent Trajectory Inspector Path Traversal File Disclosure SWE-agent SWE-agent High 7.5 2026-08-17 20:36:07 Deep Dive
CVE-2026-75479 🧪 JimuReport Unauthenticated Report Listing and Share Token Disclosure jeecgboot jimureport High 7.5 2026-08-17 20:36:05 Deep Dive
CVE-2026-75111 🧪 Evidently UI Path Traversal via Dataset Materialization Filename evidentlyai evidently High 7.5 2026-08-17 20:36:05 Deep Dive
CVE-2026-75110 🧪 MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET MemTensor MemOS Critical 9.8 2026-08-17 20:36:04 Deep Dive
CVE-2026-75109 🧪 Determined Missing Authorization Check on Generic Task Endpoints determined-ai determined High 7.1 2026-08-17 20:36:03 Deep Dive