Heimdall是LinuxServer.io开源的一个应用程序面板和启动器。 Heimdall 2.6.3-ls307版本存在安全漏洞,该漏洞源于HTTP头处理不当,可能导致主机头注入和开放重定向攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LinuxServer.io Heimdall 2.6.3-ls307 contains a host header injection caused by improper validation of user-supplied HTTP headers `X-Forwarded-Host` and `Referer`, letting unauthenticated remote attackers perform host header injection and open redirect attacks, exploit requires no special privileges. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-50578.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-45515 | Zimbra Collaboration 安全漏洞 | |
| CVE-2025-50464 | ipTIME NAS 安全漏洞 | |
| CVE-2025-50777 | AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera 安全漏洞 | |
| CVE-2025-51954 | Electronic Hub playground.electronhub.ai 安全漏洞 | |
| CVE-2025-51951 | Andi search 安全漏洞 | |
| CVE-2025-25691 | PrestaShop 安全漏洞 | |
| CVE-2025-25692 | PrestaShop 安全漏洞 | |
| CVE-2025-45619 | AVer PTC310UV2 安全漏洞 | |
| CVE-2025-45620 | Aver PTC310UV2 安全漏洞 | |
| CVE-2025-53022 | TrustedFirmware-M 安全漏洞 | |
| CVE-2025-52187 | Get Projects School Management System 安全漏洞 | |
| CVE-2024-45955 | Rocket Software Rocket Zena 安全漏洞 |
No comments yet