Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 54203+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

227
Sources connected
106
Sources online now
970
New intel in 24h
54,203+
AI-processed intel
Continuous monitoring and AI processing Monitor intel
Examples: RCE · SSRF · GHSA · log4j
Filter
Unidata NetCDF-C Buffer Overflow Advisory with PoC and Fix
github.com · 2026-09-05

# Unidata NetCDF Security Advisory Summary ## Vulnerability Overview - **Vulnerability Type**: Buffer Overflow - **Affected Component**: NetCDF-C Library - **Risk Level**: High - **Vulnerability Descr…

Read more
PX4 temperature_compensation Use-After-Free Race Condition Fix
github.com · 2026-09-05

# Key Vulnerability Information Summary ## Vulnerability Overview - **Type**: Use-After-Free (UAF) - **Root Cause**: Race condition - **Location**: `temperature_compensation` module - **PR**: #28487 (…

Read more
PX4 param_compensation_buffer_overflow_CVE_writeup
github.com · 2026-09-05

## Vulnerability Overview - **Vulnerability Type**: Buffer Overflow - **Location**: `px4/src/modules/param_compensation/param_compensation_calibration/task.cpp` - **Root Cause**: In the `TemperatureCa…

Read more
PX4 temperature_compensation UAF vulnerability fix and code patch analysis
github.com · 2026-09-05

## Vulnerability Overview - **Vulnerability Type**: Use-After-Free (UAF) memory error in the temperature compensation module - **Fix Commit**: Commit `b182e52`, committed by `godesady` 3 days ago - **…

Read more
Node.js Heap Buffer Overflow in napi_json_string_escape: Root Cause, PoC, and Fix
github.com · 2026-09-05

# Vulnerability Key Information Summary ## Vulnerability Overview - **Vulnerability Type**: Heap Buffer Overflow - **Vulnerability Location**: `napi_json_string_escape` function - **Vulnerability Desc…

Read more
PX4-Autopilot CWE-476 null ptr deref in param select with DoS & ASAN POC
github.com · 2026-09-05

# PX4-Autopilot Vulnerability Fix Summary ## Vulnerability Overview - **Type**: CWE-476 Null Pointer Dereference - **Trigger Condition**: When the `param select` or `param select-backup` command is ex…

Read more
PX4 Parameters Module Null Pointer Dereference Fix (Issue #28475)
github.com · 2026-09-05

## Vulnerability Overview - **Vulnerability Type**: Null pointer dereference - **Affected Module**: `param` module - **Fix Commit**: Commit `02eabc9`, committed by `godesay` 4 days ago, verified (Veri…

Read more
Laravel Mail: Email Address Line-Break Validation Fix & CVE Analysis
github.com · 2026-09-05

# Vulnerability Key Information Summary ## Vulnerability Overview - **Title**: Validate against line breaks in emails - **Status**: Merged by `taylorotwell` on May 17 from the `email-validation` branc…

Read more
Laravel Email Address Header Injection Fix & PoC Analysis
github.com · 2026-09-05

# Laravel Framework Security Fix Summary ## Vulnerability Overview This commit (`969e9a66`, branch `v10.x`) fixes an **email address injection vulnerability**. Attackers can craft email addresses cont…

Read more
Laravel Mail Module CRLF Injection Vulnerability and Fix
github.com · 2026-09-05

## Vulnerability Overview - **Vulnerability Type**: CRLF Injection Vulnerability in Email Addresses - **Vulnerability Description**: In email addresses (`Address`), if the address string contains line…

Read more
CVE-2026-46636: php-twig sandbox filter_tag bypass via state change analysis
security-tracker.debian.org · 2026-09-05

## CVE-2026-46636 Key Vulnerability Information Summary ### Vulnerability Overview - **Vulnerability ID**: CVE-2026-46636 - **Related Advisory**: DSA-6111-1 - **Vulnerability Type**: In sandbox mode, …

Read more
Twig Sandbox Bypass CVE-2026-46636: SecurityPolicy Allowlist Circumvention & Fix in v3.27.0
symfony.com · 2026-09-05

# CVE-2026-46636 Vulnerability Summary ## Vulnerability Overview **CVE-2026-46636**: When the sandbox state changes between renders, the sandbox filter, tag, and function allow-lists can be bypassed. …

Read more
Twig Sandbox Bypass CVE-2026-48805/48806 & v3.27.0 Fix
github.com · 2026-09-05

## Key Vulnerability Information Summary **Vulnerability Overview** - **CVE-2026-48805**: Bypass of the sandbox `allow-list` when the sandbox state changes between multiple renders. - **CVE-2026-48806…

Read more
CVSS 5.3
CWE-306 Missing Authentication in freegpt-webui
vuldb.com · 2026-09-05

# Vulnerability Key Information Summary ## Vulnerability Overview - **Vulnerability ID**: #895266 - **Vulnerability Type**: CWE-306 (Missing Authentication for Critical Function) - **Affected Project*…

Read more
CVSS 7.1
ntopng: Add auth capability check for REST delete endpoints (pools, notifications)
github.com · 2026-09-05

# Vulnerability Fix Summary ## Vulnerability Overview - **Commit Message**: `Fix user capability check for deleting notification endpoints and pools` - **Commit Hash**: `7d830f3` - **Committer**: card…

Read more
CVSS 7.1
ntopng pools_rest_utils.lua Privilege Escalation Vulnerability Analysis
github.com · 2026-09-05

# Key Vulnerability Information Summary ## Vulnerability Overview - **Vulnerability Type**: Privilege Escalation / Logic Flaw - **Core Issue**: The `add_pool` function does not perform strict identity…

Read more
CVSS 7.1
ntopng REST API Missing Authorization: Non-Admin Can Delete Endpoints/Host Pools (CWE-862)
github.com · 2026-09-05

# Summary of Key Vulnerability Information ## Overview - **Title**: Missing Authorization Checks in REST API Allow Non-Admin Users to Delete All Notification Endpoints, Recipients, and Host Pools - **…

Read more
CVSS 7.1
Ntop 2023-28 REST API RCE Vulnerability Analysis
github.com · 2026-09-05

# Summary of Key Vulnerability Information ## Vulnerability Overview - **Vulnerability Type**: Remote Code Execution (RCE) - **Affected Component**: `scripts/lua/rest/v2/delete/endpoints.lua` - **Root…

Read more
CVSS 8.7
CVE-2026-60249: python-cryptography Exponential Path-Building in Cert Chains
github.com · 2026-09-05

## Vulnerability Overview - **Vulnerability ID**: CVE-2026-60249 - **Vulnerability Type**: Exponential path-building in `python-cryptography` caused by duplicate self-signed intermediate certificates.…

Read more
CVSS 6.5
Avo attachments_controller upload authorization fix & 403 response analysis
github.com · 2026-09-05

## Vulnerability Overview - **Vulnerability Type**: Attachment upload authorization flaw - **Issue Description**: In `attachments_controller`, the attachment upload operation does not properly validat…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.