Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 85

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-67351 🧪 Serendipity < 2.6.1 Authentication Bypass via Username Collision s9y Serendipity High 8.8 2026-07-30 13:57:52 Deep Dive
CVE-2026-59309 🧪 vCenter authentication-bypass vulnerability VMware Cloud Foundation Critical 9.8 2026-07-30 12:19:52 Deep Dive
CVE-2026-59310 KEV 🧪 vCenter directory-traversal vulnerability VMware Cloud Foundation Critical 9.8 2026-07-30 12:19:25 Deep Dive
CVE-2026-18361 🧪 DFIR-IRIS Stored XSS in Datastore Upload dfir-iris iris-web High 7.6 2026-07-30 09:42:26 Deep Dive
CVE-2026-18360 🧪 DFIR-IRIS Stored XSS in Custom Attributes dfir-iris iris-web High 7.6 2026-07-30 09:41:19 Deep Dive
CVE-2026-16969 🧪 DFIR-IRIS Stored XSS in Assets dfir-iris iris-web High 7.6 2026-07-30 09:40:14 Deep Dive
CVE-2026-18353 🧪 Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass Eclipse Foundation Eclipse CSI - PIA High 8.8 2026-07-30 07:23:04 Deep Dive
CVE-2026-18015 🧪 Google Chrome 安全漏洞 Google Chrome 超危 - 2026-07-30 00:26:09 Deep Dive
CVE-2026-17652 🧪 Google Chrome 资源管理错误漏洞 Google Chrome 超危 - 2026-07-30 00:18:43 Deep Dive
CVE-2026-67595 🧪 VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php webreinvent vaahcms High 8.1 2026-07-29 21:33:26 Deep Dive
CVE-2026-67437 🧪 OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) OliveTin OliveTin High 7.5 2026-07-29 20:43:05 Deep Dive
CVE-2026-67432 🧪 MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport modelcontextprotocol ruby-sdk High 7.5 2026-07-29 19:17:47 Deep Dive
CVE-2026-67431 🧪 MCP Ruby SDK: Ruby SSE Session Poisoning modelcontextprotocol ruby-sdk High 8.3 2026-07-29 19:15:32 Deep Dive
CVE-2026-18022 🧪 pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-bit systems - pgvector High 8.8 2026-07-29 18:55:55 Deep Dive
CVE-2026-67429 🧪 Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) flytohub flyto-core Critical 10.0 2026-07-29 18:50:43 Deep Dive
CVE-2026-67428 🧪 Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata) flytohub flyto-core High 8.5 2026-07-29 18:48:42 Deep Dive
CVE-2026-67427 🧪 Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted flytohub flyto-core High 8.6 2026-07-29 18:45:48 Deep Dive
CVE-2026-67426 🧪 Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration flytohub flyto-core Critical 9.3 2026-07-29 18:43:26 Deep Dive
CVE-2026-67425 🧪 Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url flytohub flyto-core High 8.6 2026-07-29 18:35:02 Deep Dive
CVE-2026-67424 🧪 Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation flytohub flyto-core High 8.5 2026-07-29 18:32:01 Deep Dive