stomper 5e2741e 版本存在拒绝服务(DoS)漏洞。恶意客户端可以发送不完整的 STOMP 帧并保持 TCP 连接打开。由于该 broker 在使用 时结合了边沿触发式的 epoll(EPOLLET)和 ,这会导致套接字进入永久的半读取状态。当足够多的此类连接累积时,broker 将停止接收这些套接字的后续 epoll 事件,并最终在 中挂起,从而无法处理新的消息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-51679 | openRISC OR1200 83ac6b RTL与网表不一致 | |
| CVE-2025-61478 | Acre SPC5300.000 v3.14.1 SYN报文致拒绝服务 | |
| CVE-2026-75333 | yx-image-recognition v1.0 路径遍历漏洞 | |
| CVE-2026-75330 | super-diamond-server 1.3.3 前端接口 SQL注入 | |
| CVE-2026-75332 | Zyplayer-Doc 1.0.0 存在SSRF漏洞 | |
| CVE-2026-75338 | Disconf 2.6.36 未认证访问控制缺陷 | |
| CVE-2026-75336 | Funiture 1.0.0 后台接口SQL注入 | |
| CVE-2026-75340 | JetLinks 2.11 设备接口SSRF漏洞 | |
| CVE-2026-75328 | DocSys V2.02.85 downloadDocEx任意文件读取 | |
| CVE-2025-51675 | openRISC OR1200 DoS:PC更新不准确 | |
| CVE-2025-61479 | SACRE SPC5300.000 v3.14.1 SPC Connect Pro DoS漏洞 | |
| CVE-2026-39275 | Cockpit CMS v2.13.5前XSS漏洞 | |
| CVE-2026-52103 | SimpleX Chat 6.5前Terminal远程代码执行漏洞 | |
| CVE-2026-52473 | Wgcloud 3.6.4远程命令执行漏洞 | |
| CVE-2026-75415 | AntFlow V2.0.0 访问控制缺陷 | |
| CVE-2026-75413 | DocSys V2.02.80任意文件下载漏洞 | |
| CVE-2026-75364 | Comfast CF-N1-S 2.6.0.1 webmgnt命令注入漏洞 | |
| CVE-2026-75411 | JeecgBoot 3.9.2 远程命令执行漏洞 | |
| CVE-2026-75363 | Comfast CF-WR630AX 远程代码执行漏洞 | |
| CVE-2026-75414 | AntFlow 2.0.0 JUEL表达式未过滤导致命令执行 |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet