Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 68

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-70604 🧪 Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads electron electron High 7.4 2026-08-05 15:59:24 Deep Dive
CVE-2026-70601 🧪 Electron: Context isolation bypass via Function.prototype.bind hijack electron electron High 7.5 2026-08-05 15:45:31 Deep Dive
CVE-2026-39923 🧪 Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset Flarum Flarum Framework High 8.1 2026-08-05 14:38:36 Deep Dive
CVE-2026-67623 🧪 Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook mistralai mistral-vibe High 8.8 2026-08-05 13:27:27 Deep Dive
CVE-2026-71294 🧪 Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions Cotonti Cotonti High 7.6 2026-08-05 12:38:48 Deep Dive
CVE-2026-71292 🧪 Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter intelliants subrion High 7.2 2026-08-05 12:38:43 Deep Dive
CVE-2026-71291 🧪 Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering bolt core High 8.8 2026-08-05 12:38:41 Deep Dive
CVE-2026-71289 🧪 NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution via Exposed AMP Manager REST API NASA-AMMOS anms Critical 9.8 2026-08-05 12:26:35 Deep Dive
CVE-2026-71288 🧪 Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl Koha Community Koha High 8.8 2026-08-05 12:26:34 Deep Dive
CVE-2026-71287 🧪 Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Leading to Blind SQL Injection Cacti cacti High 8.8 2026-08-05 12:26:33 Deep Dive
CVE-2026-71285 🧪 Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages louislam uptime-kuma High 8.1 2026-08-05 12:26:31 Deep Dive
CVE-2026-71284 🧪 Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename fledge-iot fledge High 7.2 2026-08-05 12:26:30 Deep Dive
CVE-2026-71281 🧪 peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and CorDA Modules huggingface peft High 8.8 2026-08-05 12:26:27 Deep Dive
CVE-2026-71279 🧪 Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execution Koenkk zigbee2mqtt High 8.0 2026-08-05 12:26:26 Deep Dive
CVE-2026-71280 🧪 go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch go-shiori shiori High 8.5 2026-08-05 12:26:26 Deep Dive
CVE-2026-71278 🧪 rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-Rule Script Evaluation iot-ecology rust-iot-platform Critical 9.8 2026-08-05 12:26:25 Deep Dive
CVE-2026-71277 🧪 rust-iot-platform Authentication Bypass via Non-Validated Authorization Header iot-ecology rust-iot-platform Critical 9.1 2026-08-05 12:26:24 Deep Dive
CVE-2026-71276 🧪 Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter absmach magistrala High 7.1 2026-08-05 12:26:23 Deep Dive
CVE-2026-71274 🧪 OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels openshwprojects OpenBK7231T_App High 8.5 2026-08-05 12:26:21 Deep Dive
CVE-2026-71272 🧪 Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext() usememos memos High 8.5 2026-08-05 12:26:19 Deep Dive