Vulnerability-Lookup是Vulnerability-Lookup团队开源的一个漏洞查询与扫描工具。 Vulnerability-Lookup 5.5.1及之前版本存在授权问题漏洞,该漏洞源于REST API和SSE流接口之间授权执行不一致,仅通过X-API-KEY匹配进行身份验证而未验证账户激活和确认状态,导致未激活或未确认账户可通过/pubsub/subscribe/<topic>端点订阅服务器发送事件流,可能暴露新提交或未审核的评论等数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vulnerability-lookup | vulnerability-lookup | ≤ 5.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vulnerability-lookup | vulnerability-lookup | 0 ~ 5.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73431 | 8.8 HIGH | Reusable Account Activation and Recovery Tokens Allow Repeated Account Takeover in vulnera |
| CVE-2026-73374 | 6.1 MEDIUM | Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in vulnerability-lookup |
| CVE-2026-73432 | 5.1 MEDIUM | Stored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Int |
No comments yet