Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 7

Found 21067 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-75498 🧪 Webkul QloApps SQL injection Webkul QloApps High 7.2 2026-08-25 16:37:44 Deep Dive
CVE-2026-59184 🧪 OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write AcademySoftwareFoundation openexr High 7.1 2026-08-25 16:28:48 Deep Dive
CVE-2026-55557 🧪 browse-mcp: Arbitrary file write via unconfined download and state paths That1Drifter browse-mcp High 8.6 2026-08-25 16:28:07 Deep Dive
CVE-2026-55553 🧪 urllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage node-modules urllib High 7.5 2026-08-25 16:18:22 Deep Dive
CVE-2026-24169 🧪 NVIDIA Unified Fabric Manager Enterprise 命令注入漏洞 NVIDIA Unified Fabric Manager Enterprise - GA High 8.0 2026-08-25 16:17:43 Deep Dive
CVE-2026-24170 🧪 NVIDIA Unified Fabric Manager Enterprise 授权问题漏洞 NVIDIA Unified Fabric Manager Enterprise - GA High 8.8 2026-08-25 16:17:42 Deep Dive
CVE-2026-24263 🧪 NVIDIA DGX Spark 异常处理不当漏洞 NVIDIA DGX Spark High 8.2 2026-08-25 16:11:07 Deep Dive
CVE-2026-55640 🧪 Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) cbcoutinho nextcloud-mcp-server Critical 9.1 2026-08-25 16:03:28 Deep Dive
CVE-2026-55580 🧪 mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist sonirico mcp-shell High 8.6 2026-08-25 15:42:36 Deep Dive
CVE-2026-55581 🧪 mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable sonirico mcp-shell High 8.4 2026-08-25 15:40:11 Deep Dive
CVE-2026-55582 🧪 mcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias sonirico mcp-shell High 8.4 2026-08-25 15:37:43 Deep Dive
CVE-2026-55546 🧪 QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input QWED-AI qwed-mcp Critical 9.8 2026-08-25 15:25:35 Deep Dive
CVE-2026-55536 🧪 Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) MervinPraison PraisonAI Critical 9.1 2026-08-25 15:21:53 Deep Dive
CVE-2026-55532 🧪 PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server MervinPraison PraisonAI High 7.6 2026-08-25 15:17:53 Deep Dive
CVE-2026-79784 🧪 Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration gemelo-ai vocos High 8.8 2026-08-25 15:16:12 Deep Dive
CVE-2026-79774 🧪 Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy wintercms winter High 8.4 2026-08-25 15:16:06 Deep Dive
CVE-2026-79770 🧪 Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer sparklemotion nokogiri High 7.5 2026-08-25 15:16:03 Deep Dive
CVE-2026-79675 🧪 NLTK before 3.10.3 JVM Argument Injection via Per-Call Options nltk nltk Critical 9.8 2026-08-25 15:16:01 Deep Dive
CVE-2026-79674 🧪 NLTK 3.10.2 Path Traversal via corpus-reader constructors nltk nltk High 8.2 2026-08-25 15:16:00 Deep Dive
CVE-2026-55527 🧪 PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location MervinPraison PraisonAI High 7.1 2026-08-25 15:09:08 Deep Dive