Mindskip xzs是中国Mindskip公司开源的一个在线考试系统。 Mindskip xzs 3.9.0及之前版本存在安全漏洞,该漏洞源于教师端接口/api/teacher/user/delete/{id}未验证当前用户权限,导致已认证的教师用户可删除管理员账户,形成垂直权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82954 | 9.9 CRITICAL | Dokploy Settings application.ts writeTraefikConfigInPath path traversal |
| CVE-2026-82608 | 7.4 HIGH | Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds |
| CVE-2026-82598 | 7.3 HIGH | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82630 | 7.3 HIGH | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection |
| CVE-2026-82600 | 7.3 HIGH | SeaCMS zyapi.php sql injection |
| CVE-2026-82599 | 5.4 MEDIUM | SeaCMS Avatar Upload member.php unlink path traversal |
| CVE-2026-82603 | 5.4 MEDIUM | SeaCMS Comment Cache member.php del_pl path traversal |
| CVE-2026-82602 | 5.3 MEDIUM | SeaCMS ass.php authorization |
| CVE-2026-82623 | 5.3 MEDIUM | open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange |
| CVE-2026-82821 | 4.3 MEDIUM | FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference |
| CVE-2026-82805 | 4.3 MEDIUM | Typora Mermaid Rendering cross site scripting |
| CVE-2026-82820 | 4.3 MEDIUM | FLVMeta AMF String Processing amf.c amf_string_new heap-based overflow |
| CVE-2026-82601 | 4.3 MEDIUM | SeaCMS err.php cross site scripting |
| CVE-2026-82596 | 3.3 LOW | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru |
| CVE-2026-51723 | TOTOLINK T6 安全漏洞 | |
| CVE-2026-51722 | TOTOLINK T6 安全漏洞 | |
| CVE-2026-51720 | TOTOLINK T6 权限许可和访问控制问题漏洞 | |
| CVE-2026-51718 | TOTOLINK T6 安全漏洞 | |
| CVE-2026-51719 | TOTOLINK T6 安全漏洞 | |
| CVE-2026-51717 | TOTOLINK T6 安全漏洞 |
Showing top 20 of 95 CVEs. View all on vendor page → →
No comments yet