Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Featured AI POCs

Top 50 recently published CVEs with comprehensive Shenlong AI analysis. Each entry includes vulnerability mechanism, trigger conditions, exploit chain, and reproducible POC. Free users get 3 free unlocks per month. JSON

CVE-2026-70619 High CVSS 8.8
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
CVE-2026-18897 High CVSS 8.8
UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow
CVE-2026-18898 High CVSS 8.8
UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow
CVE-2026-18895 High CVSS 8.8
UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow
CVE-2026-70374 High CVSS 8.8
HashBrown CMS - OS Command Injection in Media Upload Thumbnail Generation
CVE-2026-70375 High CVSS 8.8
HashBrown CMS - OS Command Injection via Git Deployer Branch Field
CVE-2026-55997 High CVSS 8.8
Long-lived Rancher registration token exposed in plaintext
CVE-2026-71235 High CVSS 8.8
Magistrala IoT Platform - Unrestricted Go/Lua Script Execution in Rules Engine
CVE-2026-60009 High CVSS 8.8
Eclipse Theia 路径遍历漏洞
CVE-2026-71243 High CVSS 8.8
backmeup (npm) - OS Command Injection via Backup Option Values
CVE-2026-71281 High CVSS 8.8
peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA and
CVE-2026-71287 High CVSS 8.8
Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions Lea
CVE-2026-71291 High CVSS 8.8
Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Renderi
CVE-2026-71288 High CVSS 8.8
Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.
CVE-2026-70492 High CVSS 8.7
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered mes
CVE-2026-45084 High CVSS 8.7
OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-
CVE-2026-45809 High CVSS 8.7
OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher
CVE-2026-46334 High CVSS 8.7
OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning
CVE-2026-71233 High CVSS 8.7
InvoiceNinja - Stored XSS via Invoice/Quote Terms Field
CVE-2026-71236 High CVSS 8.7
Grocy - Stored XSS via HTMLPurifier Output Double-Decode
CVE-2026-71255 High CVSS 8.6
nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device
CVE-2026-71270 High CVSS 8.6
Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPrint
CVE-2026-71259 High CVSS 8.6
ESPHome external_components file:// Scheme Validation Bypass Leading to Remote C
CVE-2026-18953 High CVSS 8.6
Improper limitation of a pathname to a restricted directory in aws-transform-mcp
CVE-2026-71309 High CVSS 8.6
rclone: Incomplete path validation allows backend root escape in serve restic
CVE-2026-66298 High CVSS 8.6
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed g
CVE-2026-65986 High CVSS 8.5
CVAT has stored XSS via annotation guide assets
CVE-2026-71271 High CVSS 8.5
Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass
CVE-2026-71280 High CVSS 8.5
go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch
CVE-2026-71272 High CVSS 8.5
Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()
CVE-2026-71274 High CVSS 8.5
OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels
CVE-2026-70476 High CVSS 8.3
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Ten
CVE-2026-70486 High CVSS 8.2
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe
CVE-2026-55739 High CVSS 8.2
Crater - Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Company C
CVE-2026-71206 High CVSS 8.2
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privile
CVE-2026-71252 High CVSS 8.2
toner-management - Unauthenticated State-Changing Admin Actions
CVE-2026-71242 High CVSS 8.2
Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in Note
CVE-2026-71264 High CVSS 8.2
WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settings-
CVE-2026-19024 High CVSS 8.2
HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
CVE-2026-71315 High CVSS 8.2
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware
CVE-2026-70482 High CVSS 8.1
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to
CVE-2026-70494 High CVSS 8.1
Open WebUI: A folder write-collaborator can permanently delete the owner's chats
CVE-2026-54418 High CVSS 8.1
Leantime - Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Account
CVE-2026-71239 High CVSS 8.1
DjangoCRM - Server-Side Template Injection in Mass Mail Message Rendering
CVE-2026-71279 High CVSS 8.1
Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Executio
CVE-2026-71285 High CVSS 8.1
Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages
CVE-2026-39923 High CVSS 8.1
Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
CVE-2026-70617 High CVSS 8.1
Spacebar Server Missing Authorization via Group DM Recipient Endpoint
CVE-2026-71320 High CVSS 8.1
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt S
CVE-2026-71312 High CVSS 8.0
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Comma

📥 Want the latest list as JSON? /api/featured-pocs.json

Open repo: github.com/imfht/cve-cn — README auto-generated weekly from this list.