Moonshot AI Kimi AI是中国月之暗面(Moonshot AI)公司的一款具备长文本理解、多模态交互、智能搜索与Agent能力的人工智能助手。 Moonshot AI Kimi AI 1.0版本存在安全漏洞,该漏洞源于Web界面预览功能未能正确清理或编码AI模型生成的HTML/JavaScript有效载荷,可能导致受害者浏览器会话中执行任意JavaScript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10766 | 3.6 LOW | mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash |
| CVE-2026-10705 | 3.1 LOW | dask HLL hyperloglog.py nunique_approx resource consumption |
| CVE-2025-70100 | lwext4 安全漏洞 | |
| CVE-2025-70101 | lwext4 安全漏洞 | |
| CVE-2025-60477 | GPAC 安全漏洞 | |
| CVE-2026-37700 | MaxSite CMS 安全漏洞 | |
| CVE-2026-37462 | GoBGP 安全漏洞 | |
| CVE-2026-37460 | FRRouting 安全漏洞 | |
| CVE-2026-36606 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36605 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36604 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36616 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36615 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36608 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36612 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36610 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36618 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36609 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36603 | Mercusys AC12G 安全漏洞 | |
| CVE-2026-36607 | Mercusys AC12G 安全漏洞 |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet