浏览 28+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-27678 | Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures) | SAP_SE | SAP S/4HANA Backend OData Service (Manage Reference Structures) | Medium | 6.5 | 2026-04-14 00:07:33 | Deep Dive |
| CVE-2026-39880 | Remnawave Backend has a race condition in HWID device limit allows bypassing max devices | remnawave | backend | Medium | 5.0 | 2026-04-08 20:01:22 | Deep Dive |
| CVE-2026-32237 | @backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint | @backstage | plugin-scaffolder-backend | Medium | 4.4 | 2026-03-12 18:38:57 | Deep Dive |
| CVE-2026-32236 | @backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch | @backstage | plugin-auth-backend | 低危 | - | 2026-03-12 18:37:11 | Deep Dive |
| CVE-2026-32235 | @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass | @backstage | plugin-auth-backend | Medium | 5.9 | 2026-03-12 18:35:06 | Deep Dive |
| CVE-2026-2663 | Alixhan xh-admin-backend Database Query query sql injection | Alixhan | xh-admin-backend | Medium | 6.3 | 2026-02-18 19:32:09 | Deep Dive |
| CVE-2025-69417 | Plex Media Server 安全漏洞 | Plex | plex.tv backend | Medium | 5.0 | 2026-01-02 16:55:18 | Deep Dive |
| CVE-2025-69416 | Plex media server 安全漏洞 | Plex | plex.tv backend | Medium | 5.0 | 2026-01-02 16:52:57 | Deep Dive |
| CVE-2025-61959 | Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information | Vertikal Systems | Hospital Manager Backend Services | Medium | 5.3 | 2025-10-29 21:54:52 | Deep Dive |
| CVE-2025-54459 | Vertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control Sphere | Vertikal Systems | Hospital Manager Backend Services | High | 7.5 | 2025-10-29 21:51:34 | Deep Dive |
| CVE-2025-58059 | Valtimo scripting engine can be used to gain access to sensitive data or resources | valtimo-platform | valtimo-backend-libraries | Critical | 9.1 | 2025-08-28 17:50:51 | Deep Dive |
| CVE-2025-50891 | Adform Site Tracking 安全漏洞 | Adform | server-side backend for Site Tracking | High | 7.2 | 2025-08-19 00:00:00 | Deep Dive |
| CVE-2025-54428 | RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak) | musombi123 | RevelaCode-Backend | Critical | 9.8 | 2025-07-28 20:28:03 | Deep Dive |
| CVE-2025-48881 | Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users | valtimo-platform | valtimo-backend-libraries | High | 8.3 | 2025-05-30 05:21:30 | Deep Dive |
| CVE-2025-5173 | HumanSignal label-studio-ml-backend PT File neural_nets.py load deserialization | HumanSignal | label-studio-ml-backend | Medium | 5.3 | 2025-05-26 06:31:05 | Deep Dive |
| CVE-2025-47730 | TeleMessage archiving backend 安全漏洞 | TeleMessage | archiving backend | Medium | 4.8 | 2025-05-08 00:00:00 | Deep Dive |
| CVE-2025-47729 | TeleMessage archiving backend 安全漏洞 | TeleMessage | archiving backend | Low | 1.9 | 2025-05-08 00:00:00 | Deep Dive |
| CVE-2025-23837 | WordPress One Backend Language Plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | martinjuhasz | One Backend Language | High | 7.1 | 2025-01-24 10:52:57 | Deep Dive |
| CVE-2024-32591 | WordPress Backend Designer plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | Daniele De Rosa | Backend Designer | Medium | 5.9 | 2024-04-18 08:41:58 | Deep Dive |
| CVE-2024-26164 | Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | Microsoft | SQL Server backend for Django | High | 8.8 | 2024-03-12 16:57:56 | Deep Dive |