Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 82

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-54737 🧪 @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging phun-ky defaults-deep High 7.3 2026-07-31 17:48:43 Deep Dive
CVE-2026-54725 🧪 vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API bank-vaults vault-secrets-webhook Critical 9.6 2026-07-31 17:45:10 Deep Dive
CVE-2026-55100 🧪 hashi-vault-js has a path traversal and query parameter injection kyndryl-open-source hashi-vault-js High 8.7 2026-07-31 17:03:42 Deep Dive
CVE-2026-54729 🧪 dssrf: any users using 1.1.1.1 DNS is impacted by SSRF HackingRepo dssrf-js High 8.7 2026-07-31 16:58:57 Deep Dive
CVE-2026-52856 🧪 Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service pterodactyl wings High 7.5 2026-07-31 16:20:31 Deep Dive
CVE-2026-52855 🧪 Wings exposes node configuration secrets through egg configuration-file templating pterodactyl wings Critical 9.9 2026-07-31 16:16:42 Deep Dive
CVE-2026-17566 🧪 pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780) pgadmin.org pgAdmin 4 Critical 9.9 2026-07-31 16:00:23 Deep Dive
CVE-2026-17351 🧪 pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) pgadmin.org pgAdmin 4 Critical 9.0 2026-07-31 16:00:19 Deep Dive
CVE-2026-17349 🧪 pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner pgadmin.org pgAdmin 4 Critical 9.6 2026-07-31 15:59:48 Deep Dive
CVE-2026-17347 🧪 pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution pgadmin.org pgAdmin 4 High 7.5 2026-07-31 15:59:17 Deep Dive
CVE-2026-17346 🧪 pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044) pgadmin.org pgAdmin 4 High 8.8 2026-07-31 15:59:13 Deep Dive
CVE-2026-18446 🧪 fast-uri vulnerable to host confusion via backslash authority introducer fast-uri fast-uri High 7.5 2026-07-31 14:37:02 Deep Dive
CVE-2026-11770 🧪 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check Red Hat Red Hat Directory Server 11.7 E4S for RHEL 8 High 7.5 2026-07-31 09:18:58 Deep Dive
CVE-2026-14483 📌 💣 Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command realtyna Realtyna Organic IDX plugin + WPL Real Estate Critical 9.8 2026-07-31 05:35:23 Deep Dive
CVE-2026-56673 🧪 ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration Comfy-Org ComfyUI High 7.5 2026-07-31 04:46:21 Deep Dive
CVE-2026-56672 🧪 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization Comfy-Org ComfyUI High 8.2 2026-07-31 04:27:19 Deep Dive
CVE-2026-56671 🧪 ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read Comfy-Org ComfyUI High 7.5 2026-07-31 04:21:54 Deep Dive
CVE-2026-56670 🧪 ComfyUI: Stored XSS via SVG file upload on the /view endpoint Comfy-Org ComfyUI High 8.2 2026-07-31 04:17:44 Deep Dive
CVE-2026-63223 🧪 CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules codeigniter4 CodeIgniter4 Critical 9.8 2026-07-31 04:10:28 Deep Dive
CVE-2026-63222 🧪 CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames codeigniter4 CodeIgniter4 High 7.5 2026-07-31 04:06:19 Deep Dive