Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 53

Found 11881 results
CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-53578 Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml TriliumNext Trilium Critical 9.3 2026-08-27 19:21:21 Deep Dive
CVE-2026-74820 Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause ServiceNow ServiceNow AI Platform Critical 10.0 2026-08-27 19:05:05 Deep Dive
CVE-2026-18886 Unauthenticated Privilege Escalation via System Configuration Image Upload Processor ServiceNow ServiceNow AI Platform Critical 10.0 2026-08-27 19:00:02 Deep Dive
CVE-2026-18885 Unauthenticated Remote Code Execution in GraphQL Composite Data API ServiceNow ServiceNow AI Platform Critical 10.0 2026-08-27 18:54:15 Deep Dive
CVE-2026-6876 Sandbox Escape in ServiceNow AI Platform ServiceNow ServiceNow AI Platform Critical 10.0 2026-08-27 18:46:05 Deep Dive
CVE-2026-48996 Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the desktop client TriliumNext Trilium Critical 9.3 2026-08-27 17:36:07 Deep Dive
CVE-2026-19092 📌 💣 Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing Unknown Tutor LMS Critical 9.8 2026-08-27 17:05:38 Deep Dive
CVE-2026-81735 UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution bytedance UI-TARS-desktop Critical 10.0 2026-08-27 14:51:20 Deep Dive
CVE-2026-81707 openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email jahlives openssl_encrypt Critical 9.8 2026-08-27 14:51:09 Deep Dive
CVE-2026-81702 openssl_encrypt before 1.4.9 Key Substitution via Identity Load jahlives openssl_encrypt Critical 9.8 2026-08-27 14:51:06 Deep Dive
CVE-2026-81701 openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin jahlives openssl_encrypt Critical 9.8 2026-08-27 14:51:05 Deep Dive
CVE-2026-81700 openssl_encrypt before 1.4.9 GPG Signature Verification Bypass jahlives openssl_encrypt Critical 9.8 2026-08-27 14:51:04 Deep Dive
CVE-2026-81098 Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport team-telnyx telnyx-mcp Critical 9.1 2026-08-27 14:50:38 Deep Dive
CVE-2026-81096 ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape mims-harvard ToolUniverse Critical 10.0 2026-08-27 14:50:37 Deep Dive
CVE-2026-81094 mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Without Requiring Authentication mcp-router mcp-router Critical 9.1 2026-08-27 14:50:35 Deep Dive
CVE-2026-16279 Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x Dassault Systèmes 3DSwymer Critical 9.3 2026-08-27 14:11:34 Deep Dive
CVE-2026-57499 Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) limanmys core Critical 9.1 2026-08-27 13:50:52 Deep Dive
CVE-2026-81826 Flowintel Fails to Invalidate Active Sessions After Password Change flowintel flowintel Critical 9.1 2026-08-27 13:32:48 Deep Dive
CVE-2026-81675 Multiple Vulnerabilities in TOOOLS' iSquad TOOOLS iSquad Critical 9.3 2026-08-27 12:07:48 Deep Dive
CVE-2026-81674 Multiple Vulnerabilities in TOOOLS' iSquad TOOOLS iSquad Critical 9.3 2026-08-27 12:06:36 Deep Dive