Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Featured AI POCs

Top 50 recently published CVEs with comprehensive Shenlong AI analysis. Each entry includes vulnerability mechanism, trigger conditions, exploit chain, and reproducible POC. Free users get 3 free unlocks per month. JSON

CVE-2026-19200 High CVSS 8.9
Velociraptor Analyst overwrites live built-in artifacts through verify()
CVE-2026-77751 High CVSS 8.8
Path Traversal in MISP Object Template Resolution During STIX Import and Export
CVE-2026-77234 High CVSS 8.8
Improper input validation in FreeRTOS-Kernel timer command handling
CVE-2026-62677 High CVSS 8.8
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesyste
CVE-2026-62675 High CVSS 8.8
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Calla
CVE-2026-62316 High CVSS 8.8
Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution
CVE-2026-50538 High CVSS 8.8
libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write
CVE-2026-53527 High CVSS 8.8
LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update
CVE-2026-53528 High CVSS 8.8
FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter
CVE-2026-48050 High CVSS 8.8
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and
CVE-2026-19883 High CVSS 8.8
WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Esc
CVE-2026-78170 High CVSS 8.8
UTT HiPER 1200GW formConfigFastDirectionW strcpy buffer overflow
CVE-2026-78369 High CVSS 8.8
Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLo
CVE-2026-76841 High CVSS 8.8
Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code
CVE-2026-76836 High CVSS 8.8
AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Seriali
CVE-2026-78551 High CVSS 8.8
RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottl
CVE-2026-56702 High CVSS 8.8
Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload
CVE-2026-16520 High CVSS 8.7
Genians Genian NAC 输入验证错误漏洞
CVE-2026-77811 High CVSS 8.7
Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboa
CVE-2026-77354 High CVSS 8.7
kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject quer
CVE-2026-78416 High CVSS 8.7
Authenticated RCE via `condition.config` JSON cleanse bypass
CVE-2026-72848 High CVSS 8.6
langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nest
CVE-2026-77775 High CVSS 8.6
Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Add
CVE-2026-46682 High CVSS 8.5
BigBlueButton: Blind SQL Injection AUTH (Moderator)
CVE-2026-72860 High CVSS 8.5
9router Server-Side Request Forgery via /api/provider-nodes/validate Because the
CVE-2026-55765 High CVSS 8.5
CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow pri
CVE-2026-76838 High CVSS 8.5
Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webhook
CVE-2026-59561 High CVSS 8.4
Sakura Editor Development Community Sakura Editor 命令注入漏洞
CVE-2026-48105 High CVSS 8.3
Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths withou
CVE-2026-48106 High CVSS 8.3
Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync mess
CVE-2026-75542 High CVSS 8.3
OAuth token exchange grants repository scopes for organizations the principal ca
CVE-2026-54682 High CVSS 8.2
DiscordChatExporter: Stored XSS in HTML export when markdown formatting is disab
CVE-2026-61824 High CVSS 8.2
Defuddle: XSS via unescaped attribute interpolation in site extractors
CVE-2026-63135 High CVSS 8.2
YOURLS: Stored XSS in referrer statistics chart via crafted Referer header
CVE-2026-78209 High CVSS 8.2
exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values
CVE-2026-77634 High CVSS 8.2
CakePHP: SmtpTransport vulnerable to CRLF header injection
CVE-2026-64679 High CVSS 8.1
Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Dir
CVE-2026-77567 High CVSS 8.1
Filament: App-based MFA can be bypassed when recovery codes are enabled
CVE-2026-34968 High CVSS 8.1
Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop
CVE-2026-68766 High CVSS 7.8
hashcat through 7.1.2 Arbitrary File Write via Restore File Option Injection
CVE-2026-41450 High CVSS 7.8
UAC < 3.3.0 Command Injection via command_collector.sh
CVE-2026-41451 High CVSS 7.8
UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh
CVE-2026-54071 High CVSS 7.8
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/p
CVE-2026-49360 High CVSS 7.8
Recce server has unauthenticated SQL execution that allows local file read/write
CVE-2026-57998 High CVSS 7.8
better-npm-audit OS Command Injection via registry flag
CVE-2026-76843 High CVSS 7.8
Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel.lo
CVE-2026-55621 High CVSS 7.7
Incus has a project restriction bypass for custom volume copy across projects
CVE-2026-55622 High CVSS 7.7
Incus has a project restriction bypass in instance copy across projects
CVE-2026-54457 High CVSS 7.7
TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object
CVE-2026-49217 High CVSS 7.5
Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthent

📥 Want the latest list as JSON? /api/featured-pocs.json

Open repo: github.com/imfht/cve-cn — README auto-generated weekly from this list.