Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 49

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-73601 🧪 Flowise before 3.1.3 Remote Code Execution via Custom MCP FlowiseAI Flowise Critical 9.0 2026-08-13 11:28:08 Deep Dive
CVE-2026-73487 🧪 Flowise before 3.1.3 Prompt Injection RCE via CSV Agent FlowiseAI Flowise Critical 9.0 2026-08-13 11:28:07 Deep Dive
CVE-2026-73486 🧪 Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV FlowiseAI Flowise Critical 9.0 2026-08-13 11:28:06 Deep Dive
CVE-2026-73485 🧪 Flowise before 3.1.3 Remote Code Execution via Airtable Agent FlowiseAI Flowise Critical 9.0 2026-08-13 11:28:05 Deep Dive
CVE-2026-73484 🧪 Flowise before 3.1.3 Sandbox Escape via Pandas Methods FlowiseAI Flowise High 8.6 2026-08-13 11:28:05 Deep Dive
CVE-2026-73483 🧪 Flowise before 3.1.3 Sandbox Escape via Puppeteer FlowiseAI Flowise Critical 9.4 2026-08-13 11:28:04 Deep Dive
CVE-2026-19484 🧪 @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary @fastify/busboy @fastify/busboy High 7.5 2026-08-13 08:50:47 Deep Dive
CVE-2026-19481 🧪 @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header @fastify/busboy @fastify/busboy High 7.5 2026-08-13 08:31:25 Deep Dive
CVE-2026-46382 🧪 Meeting Room Booking System has server-side request forgery in import functionality meeting-room-booking-system mrbs-code High 8.7 2026-08-12 23:39:51 Deep Dive
CVE-2026-49473 🧪 @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation cedar-policy authorization-for-expressjs High 8.8 2026-08-12 23:22:39 Deep Dive
CVE-2026-49819 🧪 UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd seriousm4x UpSnap Critical 9.8 2026-08-12 23:13:46 Deep Dive
CVE-2026-49481 🧪 UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd seriousm4x UpSnap Critical 9.6 2026-08-12 23:08:45 Deep Dive
CVE-2026-47717 🧪 💣 FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations frangoteam FUXA High 7.5 2026-08-12 22:18:04 Deep Dive
CVE-2026-73501 🧪 kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default getkin kin-openapi Critical 9.1 2026-08-12 21:23:41 Deep Dive
CVE-2026-73500 🧪 etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline etcd-io etcd High 8.7 2026-08-12 21:22:25 Deep Dive
CVE-2026-73499 🧪 etcd: Watch API authorization bypass via open-ended range requests etcd-io etcd High 7.1 2026-08-12 21:20:32 Deep Dive
CVE-2026-73498 🧪 MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment sooperset mcp-atlassian High 7.7 2026-08-12 21:17:25 Deep Dive
CVE-2026-73519 🧪 WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret wolfsoftwaresystemsltd WolfStack Critical 9.8 2026-08-12 21:15:33 Deep Dive
CVE-2026-73495 🧪 blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) http4s blaze High 7.4 2026-08-12 21:11:55 Deep Dive
CVE-2026-73493 🧪 http4s-blaze-server: Unbounded WebSocket message aggregation http4s blaze High 7.5 2026-08-12 21:08:35 Deep Dive