FUXA是frangoteam开源的一个基于web的过程可视化软件。 FUXA 1.2.8及之前版本存在安全漏洞,该漏洞源于身份验证绕过,server/api/jwt-helper.js中间件不当信任HTTP Referer标头验证内部请求,可能导致远程未认证攻击者通过伪造Referer标头绕过JWT身份验证,进而访问受保护的/api/runscript端点并在服务器上执行任意Node.js代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3102 | 6.3 MEDIUM | exiftool PNG File MacOS.pm SetMacOSTags os command injection |
| CVE-2026-3067 | 6.3 MEDIUM | HummerRisk Archive Extraction CommandUtils.java extractZip path traversal |
| CVE-2026-3066 | 6.3 MEDIUM | HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection |
| CVE-2026-3065 | 6.3 MEDIUM | HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult c |
| CVE-2026-3064 | 6.3 MEDIUM | HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection |
| CVE-2025-15589 | 3.8 LOW | MuYuCMS Template Management Template.php delete_dir_file path traversal |
| CVE-2025-67445 | TOTOLINK X5000R 安全漏洞 | |
| CVE-2025-63409 | GCOM EPON 1GE 安全漏洞 |
No comments yet