Stomper 5e2741e 存在“释放后使用”(Use-After-Free)漏洞。当单个客户端通过同一连接反复对同一目标地址发送 SUBSCRIBE 命令,随后关闭该连接时,Broker 对其内部订阅结构执行了错误的清理操作。这导致在销毁 StompClient 时发生堆内存中的“释放后使用”,进而使 Broker 进程崩溃。未认证的客户端可利用此漏洞可靠地触发服务拒绝(Denial of Service)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-51679 | openRISC OR1200 83ac6b RTL与网表不一致 | |
| CVE-2025-61478 | Acre SPC5300.000 v3.14.1 SYN报文致拒绝服务 | |
| CVE-2026-75333 | yx-image-recognition v1.0 路径遍历漏洞 | |
| CVE-2026-75330 | super-diamond-server 1.3.3 前端接口 SQL注入 | |
| CVE-2026-75332 | Zyplayer-Doc 1.0.0 存在SSRF漏洞 | |
| CVE-2026-75338 | Disconf 2.6.36 未认证访问控制缺陷 | |
| CVE-2026-75336 | Funiture 1.0.0 后台接口SQL注入 | |
| CVE-2026-75340 | JetLinks 2.11 设备接口SSRF漏洞 | |
| CVE-2026-75328 | DocSys V2.02.85 downloadDocEx任意文件读取 | |
| CVE-2025-51675 | openRISC OR1200 DoS:PC更新不准确 | |
| CVE-2025-61479 | SACRE SPC5300.000 v3.14.1 SPC Connect Pro DoS漏洞 | |
| CVE-2026-39275 | Cockpit CMS v2.13.5前XSS漏洞 | |
| CVE-2026-52103 | SimpleX Chat 6.5前Terminal远程代码执行漏洞 | |
| CVE-2026-52473 | Wgcloud 3.6.4远程命令执行漏洞 | |
| CVE-2026-75415 | AntFlow V2.0.0 访问控制缺陷 | |
| CVE-2026-75413 | DocSys V2.02.80任意文件下载漏洞 | |
| CVE-2026-75364 | Comfast CF-N1-S 2.6.0.1 webmgnt命令注入漏洞 | |
| CVE-2026-75411 | JeecgBoot 3.9.2 远程命令执行漏洞 | |
| CVE-2026-75363 | Comfast CF-WR630AX 远程代码执行漏洞 | |
| CVE-2026-75414 | AntFlow 2.0.0 JUEL表达式未过滤导致命令执行 |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet