Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 23

Found 11868 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2024-58385 Yonyou U8 CRM SQL Injection via fillbacksettingedit.php Yonyou U8 CRM Critical 9.8 2026-09-15 16:43:42 Deep Dive
CVE-2023-54398 Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet Yonyou U8 Cloud Critical 9.8 2026-09-15 16:43:07 Deep Dive
CVE-2026-89026 Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate Issabel Foundation Issabel Framework Critical 9.8 2026-09-15 16:41:39 Deep Dive
CVE-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts Slab safeurl Critical 9.0 2026-09-15 15:38:16 Deep Dive
CVE-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding Slab safeurl Critical 9.0 2026-09-15 15:37:50 Deep Dive
CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass FreeRDP FreeRDP Critical 9.3 2026-09-15 15:18:07 Deep Dive
CVE-2026-61549 Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend woodpecker-ci woodpecker Critical 9.0 2026-09-15 14:53:57 Deep Dive
CVE-2026-63696 Dell SmartFabric OS10.6.1.3前远程代码执行 Dell SmartFabric OS10 Software Critical 9.1 2026-09-15 14:51:33 Deep Dive
CVE-2026-63695 Dell SmartFabric OS 10.6.1.3以下版本会话固定漏洞 Dell SmartFabric OS10 Software Critical 9.8 2026-09-15 14:48:22 Deep Dive
CVE-2026-55158 Conflibot: Command injection via crafted pull request branch names under pull_request_target wktk conflibot Critical 9.1 2026-09-15 14:47:59 Deep Dive
CVE-2026-39919 Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter Artifex Software Ghostscript Critical 9.8 2026-09-15 14:26:07 Deep Dive
CVE-2026-59971 MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) designcomputer mysql_mcp_server Critical 10.0 2026-09-15 14:10:28 Deep Dive
CVE-2026-46495 OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI OpenIdentityPlatform OpenDJ Critical 9.2 2026-09-15 14:09:31 Deep Dive
CVE-2026-77179 Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback Docker Docker Sandboxes Critical 9.4 2026-09-15 13:32:41 Deep Dive
CVE-2026-89308 🧪 Arbitrary command execution in TrxTimeATTENDANCE TREXOM TrxTimeATTENDANCE Critical 9.3 2026-09-15 11:44:01 Deep Dive
CVE-2026-91998 Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp casdoor casdoor Critical 9.9 2026-09-15 11:35:52 Deep Dive
CVE-2026-91995 pig before 4.1.0 Unverified Password Change via /register/password pig-mesh pig Critical 9.1 2026-09-15 11:35:50 Deep Dive
CVE-2026-52824 📌 💣 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover kimai kimai Critical 9.1 2026-09-15 10:40:29 Deep Dive
CVE-2026-57147 praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery MervinPraison PraisonAI Critical 9.8 2026-09-15 10:34:16 Deep Dive
CVE-2026-57148 praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) MervinPraison PraisonAI Critical 9.8 2026-09-15 10:32:23 Deep Dive