Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 37

Found 21069 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-59902 🧪 Netty: Memory Exhaustion in SctpMessageCompletionHandler netty netty High 7.5 2026-08-17 17:48:56 Deep Dive
CVE-2026-54284 🧪 sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger andialbrecht sqlparse High 8.7 2026-08-17 17:43:48 Deep Dive
CVE-2026-59893 🧪 sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service) andialbrecht sqlparse High 7.5 2026-08-17 17:41:37 Deep Dive
CVE-2026-71979 🧪 INDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag Parsing indilib indi High 7.5 2026-08-17 17:40:38 Deep Dive
CVE-2026-71491 🧪 sqlparse: Quadratic O(n²) DoS in group_comments andialbrecht sqlparse High 8.7 2026-08-17 17:16:49 Deep Dive
CVE-2026-74253 🧪 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 regularlabs.com Sourcerer extension for Joomla Critical 10.0 2026-08-17 17:12:55 Deep Dive
CVE-2026-68519 🧪 Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925) nicolargo glances High 7.1 2026-08-17 17:10:26 Deep Dive
CVE-2026-62982 🧪 Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection nicolargo glances High 8.8 2026-08-17 17:07:49 Deep Dive
CVE-2026-68518 🧪 Glances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction nicolargo glances High 8.8 2026-08-17 16:18:29 Deep Dive
CVE-2026-61666 🧪 websocket-driver: Denial of service via malformed Host header faye websocket-driver-ruby High 8.9 2026-08-17 16:16:33 Deep Dive
CVE-2026-71479 🧪 New API: Integer overflow in quota billing yields negative charges (self-crediting) QuantumNous new-api Critical 9.1 2026-08-17 16:11:28 Deep Dive
CVE-2026-64866 🧪 New API: Admin can reset passkeys for same-level or higher-privileged users QuantumNous new-api Medium 5.1 2026-08-17 16:06:39 Deep Dive
CVE-2025-27772 🧪 Uptrain vulnerable to remote code execution via `/new_run` endpoint uptrain-ai uptrain High 7.4 2026-08-17 15:47:51 Deep Dive
CVE-2025-27771 🧪 Uptrain vulnerable to remote code execution via `/add_prompts` endpoint uptrain-ai uptrain High 7.4 2026-08-17 15:44:26 Deep Dive
CVE-2026-64868 🧪 New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging QuantumNous new-api High 7.5 2026-08-17 15:44:14 Deep Dive
CVE-2025-27770 🧪 UpTrain vulnerable to Remote code execution at `/create_project` uptrain-ai uptrain High 7.4 2026-08-17 15:43:21 Deep Dive
CVE-2025-27621 🧪 UpTrain has a Constant Default API Key uptrain-ai uptrain High 7.7 2026-08-17 15:42:31 Deep Dive
CVE-2026-64859 🧪 New API: User List API Leaks Root User Access Token Leading to Privilege Escalation QuantumNous new-api Critical 9.1 2026-08-17 15:42:19 Deep Dive
CVE-2026-73646 🧪 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure postcss postcss High 7.5 2026-08-17 15:35:14 Deep Dive
CVE-2026-71567 🧪 User-controlled variables inserted unescaped into shell scripts and Kubernetes manifests openshift-metal3 fakefish High 7.7 2026-08-17 14:39:10 Deep Dive