disconf(分布式配置管理平台)2.6.36 版本存在不正确的访问控制漏洞。 用于获取配置的 API 接口( 、 、 和 )在未认证的情况下对外暴露。 (登录拦截器)明确将上述四个路径加入了白名单,因此任何匿名攻击者均可读取由配置中心管理的所有配置项和配置文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39275 | Cockpit CMS v2.13.5前XSS漏洞 | |
| CVE-2025-61479 | SACRE SPC5300.000 v3.14.1 SPC Connect Pro DoS漏洞 | |
| CVE-2025-61480 | Vanderbilt SPC5300 v3.14.1 远程DoS漏洞 | |
| CVE-2026-75328 | DocSys V2.02.85 downloadDocEx任意文件读取 | |
| CVE-2026-75330 | super-diamond-server 1.3.3 前端接口 SQL注入 | |
| CVE-2026-75332 | Zyplayer-Doc 1.0.0 存在SSRF漏洞 | |
| CVE-2026-75336 | Funiture 1.0.0 后台接口SQL注入 | |
| CVE-2026-75340 | JetLinks 2.11 设备接口SSRF漏洞 | |
| CVE-2026-75329 | super-diamond-server 1.3.3 配置服务认证缺失漏洞 | |
| CVE-2025-51679 | openRISC OR1200 83ac6b RTL与网表不一致 | |
| CVE-2025-51675 | openRISC OR1200 DoS:PC更新不准确 | |
| CVE-2026-52103 | SimpleX Chat 6.5前Terminal远程代码执行漏洞 | |
| CVE-2026-52473 | Wgcloud 3.6.4远程命令执行漏洞 | |
| CVE-2026-75415 | AntFlow V2.0.0 访问控制缺陷 | |
| CVE-2026-75413 | DocSys V2.02.80任意文件下载漏洞 | |
| CVE-2026-75364 | Comfast CF-N1-S 2.6.0.1 webmgnt命令注入漏洞 | |
| CVE-2026-75411 | JeecgBoot 3.9.2 远程命令执行漏洞 | |
| CVE-2026-75363 | Comfast CF-WR630AX 远程代码执行漏洞 | |
| CVE-2026-75414 | AntFlow 2.0.0 JUEL表达式未过滤导致命令执行 | |
| CVE-2026-26448 | Stomper 5e2741e 堆栈释放后使用漏洞 |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet