Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 67

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-71316 🧪 Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients nuxt nuxt High 7.5 2026-08-05 21:14:31 Deep Dive
CVE-2026-71315 🧪 Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) nuxt nuxt High 8.2 2026-08-05 21:05:15 Deep Dive
CVE-2026-71314 🧪 Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering nuxt nuxt High 7.5 2026-08-05 20:58:51 Deep Dive
CVE-2026-71312 🧪 rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution rclone rclone High 8.0 2026-08-05 20:37:49 Deep Dive
CVE-2026-34966 🧪 Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass Gitea Gitea High 7.6 2026-08-05 20:28:58 Deep Dive
CVE-2026-71309 🧪 rclone: Incomplete path validation allows backend root escape in serve restic rclone rclone High 8.6 2026-08-05 20:13:31 Deep Dive
CVE-2026-18958 🧪 imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection imranrisal-dev Student-Management-System High 7.3 2026-08-05 20:00:10 Deep Dive
CVE-2026-55524 🧪 PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) MervinPraison PraisonAI High 7.5 2026-08-05 19:58:46 Deep Dive
CVE-2026-70617 🧪 Spacebar Server Missing Authorization via Group DM Recipient Endpoint Spacebar Server Spacebar Server High 8.1 2026-08-05 19:53:35 Deep Dive
CVE-2026-66298 🧪 JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts livebook-dev livebook High 8.6 2026-08-05 19:44:12 Deep Dive
CVE-2026-66881 🧪 Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download livebook-dev livebook High 7.0 2026-08-05 19:43:49 Deep Dive
CVE-2026-68746 🧪 Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access livebook-dev livebook High 7.7 2026-08-05 19:43:38 Deep Dive
CVE-2026-70615 🧪 boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation boringproxy boringproxy Critical 9.9 2026-08-05 19:34:13 Deep Dive
CVE-2026-18953 🧪 Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server AWS aws-transform-mcp-server High 8.6 2026-08-05 19:33:11 Deep Dive
CVE-2026-55523 🧪 PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets MervinPraison PraisonAI High 7.7 2026-08-05 19:26:22 Deep Dive
CVE-2026-69111 🧪 Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop milvus-io milvus High 7.5 2026-08-05 19:18:23 Deep Dive
CVE-2026-55522 🧪 PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code MervinPraison PraisonAI High 7.8 2026-08-05 19:01:43 Deep Dive
CVE-2026-48168 🧪 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name MervinPraison PraisonAI Critical 10.0 2026-08-05 18:29:39 Deep Dive
CVE-2026-70608 🧪 Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path electron electron High 7.2 2026-08-05 17:27:16 Deep Dive
CVE-2026-10716 🧪 Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation Directus Directus High 7.5 2026-08-05 16:50:49 Deep Dive