Bonsai是Bonsai组织开源的一个基于响应式编程的数据流可视化开发平台。 Bonsai 6.0版本存在安全漏洞,该漏洞源于访问控制不当,可能导致已通过身份验证的攻击者具有Editor权限提升为Administrator权限并执行未授权的账户、密码和配置更改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12198 | 7.3 HIGH | Microweber API Endpoint thumbnail_img userfiles_path path traversal |
| CVE-2026-12204 | 7.3 HIGH | ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization |
| CVE-2025-55647 | GPAC mp4box 数字错误漏洞 | |
| CVE-2026-50882 | Anna paste 安全漏洞 | |
| CVE-2025-55648 | GPAC mp4box 缓冲区错误漏洞 | |
| CVE-2026-30120 | remotion-dev remotion 安全漏洞 | |
| CVE-2026-30121 | remotion-dev remotion 安全漏洞 | |
| CVE-2026-50876 | Deck9 Input 安全漏洞 | |
| CVE-2026-50870 | Ben Busby Woogle Search 安全漏洞 | |
| CVE-2026-50874 | kanishka-linux Reminiscence 安全漏洞 | |
| CVE-2026-50871 | kanishka-linux Reminiscence 命令注入漏洞 | |
| CVE-2026-50889 | LLDAP 拒绝服务漏洞 | |
| CVE-2026-50878 | Feuerhamster MailForm 安全漏洞 | |
| CVE-2026-50880 | YouTransfer 安全漏洞 | |
| CVE-2026-50877 | Zhoros SuperBin 安全漏洞 | |
| CVE-2026-50872 | fossar Selfoss 安全漏洞 | |
| CVE-2026-50869 | Bludit 安全漏洞 | |
| CVE-2026-50890 | grocy 安全漏洞 | |
| CVE-2026-50873 | flatnotes 安全漏洞 | |
| CVE-2025-55652 | GPAC mp4box 缓冲区错误漏洞 |
Showing top 20 of 66 CVEs. View all on vendor page → →
No comments yet