在万维科技(Wellav Technologies Co., Ltd.)生产的 WES 紧急广播终端 WES100、WES270、WES280 和 WES290 中(2023 年 8 月 8 日之前发布的版本存在该问题),远程攻击者可通过全局 API 请求包装器函数获取敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97865 | 7.3 HIGH | Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization |
| CVE-2026-97869 | 4.1 MEDIUM | langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerialize |
| CVE-2026-88420 | APSL puput v1.2.1-v2.2.0反射型XSS漏洞 | |
| CVE-2026-88389 | Espruino 2v29空指针解引用致DoS | |
| CVE-2026-88421 | APSL puput 1.2.1-2.2.0 访问控制漏洞 | |
| CVE-2026-51772 | OpenStack Glance v2 SSRF漏洞 | |
| CVE-2026-51773 | OpenStack glance_store datastore驱动认证绕过漏洞 | |
| CVE-2026-78902 | Netgate pfSense 26.03.1 pfBlockerNG跨站脚本漏洞 | |
| CVE-2026-79153 | Seclore FileSecure Desktop Client <3.25.1.0 访问控制漏洞 | |
| CVE-2025-51457 | D-Link DAP-2610<2.06B08r099命令注入漏洞 |
No comments yet