Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vulnerability List - Page 3

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-58262🧪 Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum klever-ioklever-go High 7.1 2026-08-07 22:00:57 Deep Dive
CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory kata-containerskata-containers Medium 5.7 2026-08-07 21:47:21 Deep Dive
CVE-2026-47243🧪 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs kata-containerskata-containers Critical 9.2 2026-08-07 21:36:50 Deep Dive
CVE-2026-48170🧪 scimPatch vulnerable to prototype pollution via unfiltered keys in patch thomaspoignantscim-patch Critical 9.1 2026-08-07 21:26:55 Deep Dive
CVE-2026-48169🧪 PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API MervinPraisonpraisonai-platform High 8.8 2026-08-07 21:22:04 Deep Dive
CVE-2026-45808🧪 OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL openbaoopenbao High 7.1 2026-08-07 21:15:01 Deep Dive
CVE-2026-46405 OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens openbaoopenbao Medium 5.3 2026-08-07 21:14:36 Deep Dive
CVE-2026-11743 Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write zephyrprojectzephyr Medium 6.6 2026-08-07 21:10:23 Deep Dive
CVE-2026-11742 Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock zephyrprojectzephyr Low 3.6 2026-08-07 21:10:23 Deep Dive
CVE-2026-19246 HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery HKUDSnanobot Medium 6.3 2026-08-07 21:00:14 Deep Dive
CVE-2026-50540🧪 Kata Containers: Config Path Annotation Arbitrary File Loading kata-containerskata-containers Critical 9.6 2026-08-07 20:56:26 Deep Dive
CVE-2026-54338 JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login jupyterhubjupyterhub Medium 5.3 2026-08-07 20:52:55 Deep Dive
CVE-2026-69207 Hono: ReDoS in CORS middleware via Access-Control-Request-Headers honojshono Medium 5.3 2026-08-07 20:51:04 Deep Dive
CVE-2026-19245 HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure HKUDSnanobot Low 3.3 2026-08-07 20:45:13 Deep Dive
CVE-2026-66061🧪 Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution home-assistantcore High 7.1 2026-08-07 20:43:42 Deep Dive
CVE-2026-9031 Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 TP-Link Systems Inc.Archer A6 v4 Medium 6.8 2026-08-07 20:40:19 Deep Dive
CVE-2026-9030 Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6 TP-Link Systems Inc.Archer A6 v4 Medium 6.8 2026-08-07 20:38:35 Deep Dive
CVE-2026-66060 Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers home-assistantcore High 7.1 2026-08-07 20:35:47 Deep Dive
CVE-2026-46358 OpenBao's Inline Auth Incorrectly Redacted Headers openbaoopenbao Medium 5.4 2026-08-07 20:32:37 Deep Dive
CVE-2026-19244 HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control HKUDSnanobot Medium 4.7 2026-08-07 20:30:14 Deep Dive