Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 57421+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

231
Sources connected
109
Sources online now
73
New intel in 24h
57,421+
AI-processed intel
Continuous monitoring and AI processing Monitor intel
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 6.3
lerve vhr 1.0 mass assignment enables privilege escalation via /hr/info
github.com · 2026-09-13

## Vulnerability Critical Information Summary ### Vulnerability Overview - **Vulnerability ID**: VHR-VULN-001 - **Vulnerability Name**: Mass Assignment Privilege Escalation via PUT /hr/info - **Vendor…

Read more
CVSS 6.3
VHR Unrestricted File Upload (CWE-434) Leading to Stored XSS via SVG
github.com · 2026-09-13

## VHR-VULN-005: Key Vulnerability Information Summary ### Vulnerability Overview - **Vulnerability Name**: vhr (Micro HR) - Unrestricted file upload vulnerability in the POST /hr/userface endpoint - …

Read more
RCE? No: Unauth 2FA Bypass in Really Simple SSL < 9.8.1 (CVE-2026-89080)
wpscan.com · 2026-09-13

# Vulnerability Summary: Really Simple Security "The PoC will be displayed on October 11, 2026, to give users the time to update." (The PoC will be published on October 11, 2026, to allow users time t…

Read more
CVSS 7.5
HAProxy HTTP/3 Truncated Frame Fix: H3_FRAME_ERROR on FIN path
github.com · 2026-09-13

# Vulnerability Summary ## Vulnerability Overview - **Vulnerability ID**: BUG/MAJOR: h3: reject H3 truncated frames - **Issue Description**: When a truncated H3 frame is received, if the frame is trun…

Read more
CVSS 6.3
gsuBs v1.0.3: Unescaped subtitle filename in Electron renderer XSS leads to RCE via nodeRequire
github.com · 2026-09-13

## Vulnerability Overview - **Vulnerability Name**: sanjevirau gsuBs v1.0.3: Unescaped rendering of subtitle filenames in the Electron renderer (XSS) leading to code execution via the reserved `nodeRe…

Read more
CVSS 6.3
NodeRequire RCE (CVE-94): CVSS 9.6 Analysis & POC
github.com · 2026-09-13

## Summary of Key Vulnerability Information ### Vulnerability Overview - **Vulnerability Name**: CVE-94, CVSS 9.6 (Critical) - **Vulnerability Type**: NodeRequire Remote Code Execution (RCE) - **Affec…

Read more
CVSS 6.3
RabbitMQ Deserialization RCE via x-java-serialized-object with PoC
github.com · 2026-09-13

# VHR-VULN-006 — Yakit Vulnerability Summary ## Vulnerability Overview - **Vulnerability ID**: VHR-VULN-006 - **Target**: `127.0.0.1:15672` (RabbitMQ Management) - **Authentication**: Basic authentica…

Read more
CVSS 3.5
XXL-JOB 3.5.0 Stored XSS in /jobinfo/insert: PoC, impact, and HTML-encoding fix
github.com · 2026-09-13

# Summary of the XSS Vulnerability in XXL-JOB 3.5.0 ## Vulnerability Overview In version 3.5.0 of XXL-JOB, the `/jobinfo/insert` endpoint is vulnerable to a Cross-Site Scripting (XSS) attack. Regular …

Read more
CVSS 6.3
xxl-job 3.4.2 Groovy RCE Vulnerability & Sandbox Fix
github.com · 2026-09-13

# Summary of Key Vulnerability Information ## Vulnerability Overview - **Title**: Remote Code Execution (RCE) in xxl-job 3.4.2 via Groovy code execution - **Component**: GlueFactory (GlueFactory/Scrip…

Read more
CVSS 7.1
wasm2c sandbox escape via unhandled calloc failure enables host RCE
github.com · 2026-09-13

# wasm2c Sandbox Escape Vulnerability Summary ## Vulnerability Overview - **Vulnerability Type**: Sandbox Escape - **Root Cause**: In the C code generated by `wasm2c`, the function `wasm_rt_allocate_f…

Read more
CVSS 7.1
Firefox RLBox sandboxing: memory isolation & tainted value hardening
rlbox.dev · 2026-09-13

# Key Information Summary from RLBox Technical Documentation ## Vulnerability Overview - **Background of the Issue**: When a third-party C library is called from C++ code, memory safety vulnerabilitie…

Read more
CVSS 6.3
Custom-Domain Path Resolution Fix & Routing Defect Analysis
github.com · 2026-09-13

# Vulnerability Key Information Summary ## Vulnerability Overview - **Issue Type**: Flaw in the routing/redirect logic within custom-domain request handling. - **Core Defect**: In the legacy logic, cu…

Read more
CVSS 6.3
CVE-2024-45295: status-page Custom Domain & Host Header Injection
github.com · 2026-09-13

## Vulnerability Overview This page presents a commit for the security fix for **CVE-2024-45295** (Commit `8f370c`). The core issue is a **defect in the Custom Domain resolution and rewrite logic**: w…

Read more
Premium intel
CVSS 6.7
IBM WebSphere App Server Vulnerability Advisory: SSRF, Auth Bypass, HTTP Smuggling
www.ibm.com · 2026-09-13

# IBM WebSphere Application Server Security Advisory Summary ## Vulnerability Overview Versions of IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.31 are affected by multiple vulnerabilitie…

Read more
CVSS 7.5
IBM Db2 Stack-based Buffer Overflow: CVE-2026-86093
www.ibm.com · 2026-09-13

# IBM Db2 Security Bulletin (CVE-2026-86093) ## Vulnerability Overview - **CVE ID**: CVE-2026-86093 - **Vulnerability Type**: Stack-based Buffer Overflow - **Description**: An attacker with the abilit…

Read more
Premium intel
CVSS 9.6
IBM DataStage Security Bulletin: 25 CVEs (Path Traversal, SSRF, Command Injection)
www.ibm.com · 2026-09-13

# IBM DataStage on Cloud Pak for Data Security Bulletin Summary ## Vulnerability Overview - **Bulletin Title**: DataStage on Cloud Pak for Data is affected by multiple security vulnerabilities due to …

Read more
Premium intel
CVSS 9.8
IBM ContextForge MCP Gateway Default Credential Vulnerability CVE-2026-78573 Analysis
www.ibm.com · 2026-09-13

## IBM ContextForge MCP Gateway Default Credentials Vulnerability Summary ### Vulnerability Overview - **CVE**: CVE-2026-78573 - **CWE**: CWE-1392: Use of Default Credentials - **CVSS Base Score**: 9.…

Read more
CVSS 4.3
IBM Db2 Path Traversal CVE-2026-86087: Authenticated RFI, CVSS 4.3
www.ibm.com · 2026-09-13

# IBM Db2 Security Bulletin Summary (CVE-2026-86087) ## Vulnerability Overview - **CVE ID**: CVE-2026-86087 - **Vulnerability Type**: Path Traversal (CWE-22: Improper Limitation of Pathname to a Restr…

Read more
CVSS 7.8
Civ2 savegame worklist_load() heap overflow to RCE, CVSS 8.8 & patch details
redmine.freeciv.org · 2026-09-13

## Vulnerability Key Information Summary ### Vulnerability Overview - **ID**: Bug #2161 (Closed) - **Title**: Heap buffer overflow in `worklist_load()` triggered by unbounded `wl_length` (CVSS 8.8) - …

Read more
CVSS 7.4
Flatpak sandbox escape: Symlink-based host FS access and RCE (GHSA-8888-9x26-hhxj)
github.com · 2026-09-13

# Flatpak Sandbox Escape Vulnerability Summary ## Vulnerability Overview - **Title**: Flatpak sandbox escape with full host filesystem access - **Severity**: Critical - **CVE ID**: None assigned yet (…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.