Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 17

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-104416 Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API TryGhost Ghost High 7.5 2026-10-02 11:37:59 Deep Dive
CVE-2026-104414 Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses TryGhost Ghost High 8.1 2026-10-02 11:37:58 Deep Dive
CVE-2026-104415 Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API TryGhost Ghost Low 3.1 2026-10-02 11:37:58 Deep Dive
CVE-2026-104413 Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images TryGhost Ghost High 7.3 2026-10-02 11:37:57 Deep Dive
CVE-2026-104412 Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment TryGhost Ghost Medium 4.3 2026-10-02 11:37:56 Deep Dive
CVE-2026-104411 Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads TryGhost Ghost High 7.3 2026-10-02 11:37:56 Deep Dive
CVE-2026-104410 SiYuan before 3.8.5 Information Disclosure via /api/export/preview siyuan-note siyuan High 7.5 2026-10-02 11:37:55 Deep Dive
CVE-2026-103762 SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints siyuan-note siyuan Medium 5.3 2026-10-02 11:37:54 Deep Dive
CVE-2026-103763 SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo siyuan-note siyuan Medium 5.8 2026-10-02 11:37:54 Deep Dive
CVE-2026-85088 Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certificate Common Name when subjectAltName entries are present but do not match Apache Software Foundation Apache Thrift Medium 6.9 2026-10-02 11:37:15 Deep Dive
CVE-2026-85087 Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op Apache Software Foundation Apache Thrift Medium 6.9 2026-10-02 11:35:45 Deep Dive
CVE-2026-85086 Apache Thrift: Perl TLS client disables certificate verification by default Apache Software Foundation Apache Thrift Medium 6.9 2026-10-02 11:34:01 Deep Dive
CVE-2026-82459 Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process Apache Software Foundation Apache Thrift High 8.2 2026-10-02 11:32:30 Deep Dive
CVE-2026-82458 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available Apache Software Foundation Apache Thrift High 8.7 2026-10-02 11:30:51 Deep Dive
CVE-2026-96288 Apache Thrift: Erlang generated struct reads have no recursion-depth guard (unbounded memory) Apache Software Foundation Apache Thrift High 8.2 2026-10-02 11:18:37 Deep Dive
CVE-2026-96292 Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line with a backtracking pattern (quadratic) Apache Software Foundation Apache Thrift High 8.2 2026-10-02 11:11:33 Deep Dive
CVE-2026-96294 Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocket connection Apache Software Foundation Apache Thrift High 8.7 2026-10-02 11:09:56 Deep Dive
CVE-2026-61373 Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allocation Apache Software Foundation Apache Thrift High 8.7 2026-10-02 11:07:29 Deep Dive
CVE-2026-96990 Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size bound Apache Software Foundation Apache Thrift High 8.2 2026-10-02 11:00:27 Deep Dive
CVE-2026-94642 Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transport exception Apache Software Foundation Apache Thrift High 8.7 2026-10-02 10:57:15 Deep Dive