Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Security Intel Hub 23488+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Cronicle Stored XSS Vulnerability Analysis (CVE-2026-39400)
github.com · 2026-04-08

# Cronicle Stored XSS Vulnerability Summary ## Vulnerability Overview In Cronicle, non-administrator users possessing `create_events` and `run_events` privileges can inject arbitrary JavaScript code i…

Read more
NI LabVIEW LV Class File Parsing Memory Corruption Vulnerability (CVE-2026-32861) and Patch Guide
www.ni.com · 2026-04-08

### Key Vulnerability Summary **Vulnerability Overview** * **Name**: LV Class File Parsing Memory Corruption Vulnerability in NI LabVIEW (NI LabVIEW 中 LV Class 文件解析内存损坏漏洞) * **CVE ID**: CVE-2026-32861…

Read more
Vite Dev Server WebSocket Arbitrary File Read Vulnerability and POC
github.com · 2026-04-08

### Vulnerability Overview **Vulnerability Name**: Arbitrary File Read via Vite Dev Server WebSocket (通过Vite开发服务器WebSocket进行任意文件读取) **Description**: In the Vite development server's WebSocket, the `fe…

Read more
MediaWiki Cargo Extension CSS Injection Vulnerability (CVE-2026-39840) with POC
phabricator.wikimedia.org · 2026-04-08

### Vulnerability Overview * **CVE ID**: CVE-2026-39840 * **Vulnerability Name**: CSS Injection in Multiple Cargo Display Formats (CSS 注入漏洞存在于多种 Cargo 显示格式中) * **Description**: Due to insufficient val…

Read more
Stored XSS in MediaWiki Cargo Extension (CVE-2026-39839) with POC
phabricator.wikimedia.org · 2026-04-08

### Vulnerability Summary **Vulnerability Overview** * **CVE ID:** CVE-2026-39839 * **Title:** Stored XSS via URLs in Cargo's map format (Stored XSS in Cargo Map Format via URLs) * **Description:** An…

Read more
Stored XSS in MediaWiki Cargo Extension (CVE-2026-39837) and Patch
phabricator.wikimedia.org · 2026-04-08

### Vulnerability Summary **Vulnerability Overview** * **CVE ID:** CVE-2026-39837 * **Vulnerability Name:** Stored XSS via the dynamic table format in Cargo (Stored XSS through the dynamic table forma…

Read more
RustFS Authorization Bypass in UploadPartCopy Enables Cross-Bucket Exfiltration
github.com · 2026-04-08

### Vulnerability Overview * **Vulnerability Name**: Authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration (multipart UploadPartCopy 中的授权绕过导致跨桶对象泄露) * **Vulnerabili…

Read more
OpenSSL CVE-2020-31789 Buffer Overflow Fix Analysis
github.com · 2026-04-08

### Vulnerability Key Information Summary **Vulnerability Overview** * **CVE ID:** CVE-2020-31789 * **Vulnerability Type:** Buffer Overflow * **Description:** During the `buf2hex` conversion process, …

Read more
WWBN/AVideo Stored SSRF in Live Restream Log Callback
github.com · 2026-04-08

### Vulnerability Summary **Vulnerability Overview** This vulnerability exists in the **WWBN/AVideo** project, specifically within the **Live restream log callback flow**. * **Vulnerability Type**: St…

Read more
OpenSSL CVE-2020-31789 Buffer Overflow Fix Analysis
github.com · 2026-04-08

### Vulnerability Summary **1. Vulnerability Overview** * **CVE ID**: CVE-2020-31789 * **Vulnerability Type**: Buffer Overflow / Integer Overflow * **Description**: A potential buffer overflow risk ex…

Read more
SiYuan Note Electron Client Stored XSS Leading to RCE (CVE-2020-39640)
github.com · 2026-04-08

### Vulnerability Summary: SiYuan Electron Desktop Client Remote Code Execution (CVE-2020-39640) **Vulnerability Overview** This vulnerability exists in the SiYuan (思源笔记) Electron desktop client. An a…

Read more
MediaWiki Cargo Extension Input Validation Fix
gerrit.wikimedia.org · 2026-04-08

### Vulnerability Key Information Summary **Vulnerability Overview** This page documents a code review patch for the MediaWiki Cargo extension. * **Associated Bug ID:** T416368 * **Problem Description…

Read more
OpenSSL CVE-2020-31789 Buffer Overflow Fix Analysis
github.com · 2026-04-08

### Vulnerability Summary **Vulnerability Overview** * **CVE Identifier**: CVE-2020-31789 * **Vulnerability Type**: Buffer Overflow * **Description**: In the OpenSSL `buf2hexstr_sep` function, when co…

Read more
Podman Desktop WebView Server DoS and Info Disclosure Vulnerability Analysis
github.com · 2026-04-08

### Vulnerability Summary: Podman Desktop WebView Server Security Vulnerabilities **1. Vulnerability Overview** This report identifies two critical security vulnerabilities within the WebView server o…

Read more
OpenSSL CVE-2020-31789 Integer Overflow Heap Buffer Overflow Vulnerability and Fix Analysis
github.com · 2026-04-08

### Vulnerability Summary **1. Vulnerability Overview** * **CVE ID**: CVE-2020-31789 * **Vulnerability Type**: Buffer Overflow caused by Integer Overflow * **Description**: A potential buffer overflow…

Read more
OpenTelemetry baggage header parsing causes Remote DoS amplification
github.com · 2026-04-08

### Vulnerability Overview **Title**: multi-value 'baggage' header extraction causes excessive allocations (remote DoS amplification) **Description**: The multi-value baggage header extraction functio…

Read more
Stored XSS in open-source-os <= 3.4.2 via customer_name
github.com · 2026-04-08

### Vulnerability Summary: Stored XSS in Customer Name (Sales) **Vulnerability Overview** A Stored Cross-Site Scripting (Stored XSS) vulnerability exists within the Daily Sales management table. The `…

Read more
LibreChat Arbitrary File Write Vulnerability in execute_code (v0.8.3)
github.com · 2026-04-08

# LibreChat: `execute_code` Arbitrary File Write Vulnerability ## Vulnerability Overview LibreChat incorrectly trusts the `name` field returned by the `execute_code` sandbox when persisting artifacts …

Read more
Electron clipboard.readImage() DoS Vulnerability in Malformed Image Data
github.com · 2026-04-08

### Vulnerability Overview **Title:** Crash in clipboard.readImage() on malformed clipboard image data **Description:** Applications calling `clipboard.readImage()` may be susceptible to Denial of Ser…

Read more
OpenSSL CVE-2020-20390 NULL Dereference Vulnerability and Fix Analysis
github.com · 2026-04-08

### Vulnerability Key Information Summary **Vulnerability Overview** * **Vulnerability ID**: CVE-2020-20390 * **Vulnerability Type**: NULL pointer dereference / Segmentation fault * **Description**: I…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.