Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 88

Found 21070 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-55415 🧪 datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements koxudaxi datamodel-code-generator High 7.5 2026-07-28 21:37:56 Deep Dive
CVE-2026-54621 🧪 `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description koxudaxi datamodel-code-generator High 7.8 2026-07-28 21:35:28 Deep Dive
CVE-2026-54655 🧪 `datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator koxudaxi datamodel-code-generator High 7.8 2026-07-28 21:33:45 Deep Dive
CVE-2026-54691 🧪 datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects koxudaxi datamodel-code-generator High 8.2 2026-07-28 21:29:52 Deep Dive
CVE-2026-55390 🧪 Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate koxudaxi datamodel-code-generator High 7.5 2026-07-28 21:25:32 Deep Dive
CVE-2026-54654 🧪 `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field koxudaxi datamodel-code-generator High 7.8 2026-07-28 21:22:52 Deep Dive
CVE-2026-14512 🧪 IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information IBM WebSphere Application Server Critical 9.8 2026-07-28 20:50:09 Deep Dive
CVE-2026-6881 🧪 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance Ellucian Advance Web Critical 9.4 2026-07-28 20:03:12 Deep Dive
CVE-2026-57510 🧪 SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC superplanehq superplane High 8.8 2026-07-28 19:06:15 Deep Dive
CVE-2026-48060 🧪 Litestar: HTML Injection Through CSRF Token litestar-org litestar High 8.1 2026-07-28 19:02:40 Deep Dive
CVE-2026-49258 🧪 Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete) juev nebula-mesh High 8.8 2026-07-28 18:52:59 Deep Dive
CVE-2026-59932 🧪 PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion PHPOffice PhpSpreadsheet High 7.5 2026-07-28 17:59:17 Deep Dive
CVE-2026-47726 🧪 nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator juev nebula-mesh High 7.1 2026-07-28 17:58:27 Deep Dive
CVE-2026-59933 🧪 PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion PHPOffice PhpSpreadsheet High 7.5 2026-07-28 17:29:27 Deep Dive
CVE-2026-59931 🧪 PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist PHPOffice PhpSpreadsheet High 7.7 2026-07-28 17:27:27 Deep Dive
CVE-2026-54635 🧪 pytonapi has a Webhook Custom Path Authentication Bypass nessshon tonapi High 7.5 2026-07-28 17:09:08 Deep Dive
CVE-2026-16313 🧪 Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export Red Hat Red Hat Enterprise Linux 10 High 7.6 2026-07-28 16:47:06 Deep Dive
CVE-2026-54609 🧪 QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding Quiet-Terminal-Interactive QTINeon High 8.6 2026-07-28 16:36:38 Deep Dive
CVE-2026-67185 🧪 TinyWeb 0.0.8 Path Traversal via URL Path Component GeneralSandman TinyWeb High 7.5 2026-07-28 16:30:45 Deep Dive
CVE-2026-54603 🧪 OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host ruby-oauth oauth2 High 8.6 2026-07-28 16:29:04 Deep Dive