Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 74

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-40567 FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables freescout-help-deskfreescout Medium 5.8 2026-04-21 16:06:40 Deep Dive
CVE-2026-25542 Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching tektoncdpipeline Medium 6.5 2026-04-21 16:05:43 Deep Dive
CVE-2026-40566 FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints freescout-help-deskfreescout Medium 4.1 2026-04-21 16:04:36 Deep Dive
CVE-2026-40565 FreeScout has Stored XSS / CSS Injection via linkify() — Unescaped URL in Anchor href freescout-help-deskfreescout Medium 6.1 2026-04-21 15:52:39 Deep Dive
CVE-2025-15638 Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt ATRODONet::Dropbear--2026-04-21 15:34:19 Deep Dive
CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow NWCLARKStorable--2026-04-21 15:26:18 Deep Dive
CVE-2025-41011 HTML injection in PHP Point Of Sale PHP Point Of SalePHP Point Of Sale--2026-04-21 15:15:32 Deep Dive
CVE-2026-40498 FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron freescout-help-deskfreescout--2026-04-21 15:01:20 Deep Dive
CVE-2025-41029 SQL injection in Zeon Academy Pro by Zeon Global Tech Zeon Global TechZeon Academy Pro--2026-04-21 14:59:40 Deep Dive
CVE-2026-3298 Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes Python Software FoundationCPython--2026-04-21 14:45:02 Deep Dive
CVE-2025-10354 Reflected Cross-Site Scripting (XSS) in Semantic MediaWiki Semantic MediaWikiSemantic MediaWiki--2026-04-21 14:42:38 Deep Dive
CVE-2025-31981 HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption HCLSoftwareBigFix Service Management (SM) Medium 5.3 2026-04-21 14:26:39 Deep Dive
CVE-2026-5789 Search path without quotes in CivetWeb CivetWebCivetWeb--2026-04-21 14:22:06 Deep Dive
CVE-2026-1089 User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups FortraGoAnywhere MFT Medium 6.5 2026-04-21 14:14:58 Deep Dive
CVE-2026-0972 HTML Injection possible in system generated emails in Fortra's GoAnywhere MFT FortraGoAnywhere MFT Medium 5.4 2026-04-21 14:14:38 Deep Dive
CVE-2026-0971 GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout FortraGoAnywhere MFT Medium 4.3 2026-04-21 14:14:23 Deep Dive
CVE-2025-14362 GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances FortraGoAnywhere MFT High 7.3 2026-04-21 14:14:08 Deep Dive
CVE-2025-1241 Encryption vulnerable to brute-force decryption in GoAnywhere MFT FortraGoAnywhere MFT Medium 5.8 2026-04-21 14:10:10 Deep Dive
CVE-2025-31958 HCL BigFix Service Management (SM) is susceptible to HTTP Request Smuggling HCLSoftwareBigFix Service Management (SM) Low 3.7 2026-04-21 13:59:15 Deep Dive
CVE-2026-6786 Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 MozillaFirefox--2026-04-21 12:41:15 Deep Dive