前端的“主机搜索”功能支持按未显示的字段进行过滤,其中包括已存储的 IPMI 和预共享密钥(PSK)凭据。具有读取权限的用户可以猜测某一凭据,并通过搜索结果判断猜测是否正确,从而逐步泄露这些凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59782 | 6.9 MEDIUM | JavaScript preprocessing memory disclosure |
| CVE-2026-59786 | 6.9 MEDIUM | Active agent heartbeat missing TLS check |
| CVE-2026-59788 | 5.6 MEDIUM | Stored XSS vulnerability in OAuth configuration form |
| CVE-2026-59787 | 5.3 MEDIUM | SNMP trap injection in zabbix_trap_receiver.pl |
| CVE-2026-59783 | 2.3 LOW | Server DoS via binary items |
No comments yet