Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 43011+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 6.2
Huawei HarmonyOS/EMUI August 2026 Security Bulletin: Multiple CVEs (UAF, Privilege Escalation, Null Pointer Dereference)
consumer.huawei.com · 2026-08-17

### Vulnerability Overview Huawei released the August 2026 security update, which includes patches for Huawei and third-party libraries. The key vulnerability details are as follows: #### Huawei Patch…

Read more
CVSS 6.2
Huawei HarmonyOS Monthly Security Bulletin: Patch Advisory for Multiple CVEs including Privilege Escalation and UAF
consumer.huawei.com · 2026-08-17

### Vulnerability Overview Huawei released a monthly security update for its flagship devices in August 2026, which includes patches for Huawei components and third-party libraries. The following deta…

Read more
CVSS 6.2
Huawei HarmonyOS 6.1.0 Security Update: Patch for CVE-2026-49307, UAF, and Null Pointer Dereference
consumer.huawei.com · 2026-08-17

### Vulnerability Overview Huawei released security updates for its PC products in August 2026, including patches for Huawei and third-party libraries. The following is detailed vulnerability informat…

Read more
CVSS 6.2
Huawei HarmonyOS 6.1.0 Security Update Bulletin (CVE Fixes)
consumer.huawei.com · 2026-08-17

### Vulnerability Overview Huawei released the August 2026 security update, including security patches for flagship models. These patches address vulnerabilities in Huawei components and third-party l…

Read more
CVSS 6.3
Assimp MDL7 Format Parsing Heap Buffer Overflow Vulnerability Analysis
github.com · 2026-08-17

### Vulnerability Overview A heap buffer overflow vulnerability was discovered in `MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7`. This vulnerability is located in the `code/AssetLib/MDL/MDLLoader.cpp` fi…

Read more
CVSS 6.3
Buffer Overflow Fix in Asset-Importer-Lib MDL7 Model Import
github.com · 2026-08-17

### Vulnerability Overview - **Vulnerability ID**: 6633 - **Vulnerability Type**: Buffer Overflow - **Description**: The MDL asset loader does not validate the frame size before accessing data, leadin…

Read more
CVSS 6.3
Fix MDL buffer overflow vulnerability in MDLLoader.cpp
github.com · 2026-08-17

### Vulnerability Overview - **Vulnerability Title**: Fix mdl buffer overflow issue 6633 (#6759) - **Description**: This vulnerability involves a buffer overflow issue in the MDL (Material Definition …

Read more
CVSS 6.3
Hospital Management System V1.0 SQL Injection in Viewprescriptionrecord.php with POC
github.com · 2026-08-17

### Vulnerability Overview - **Vulnerability Name**: itsourcecode Hospital Management System V1.0 SQL Injection Vulnerability #3 - **Affected Product**: Hospital Management System - **Vulnerability Ty…

Read more
CVSS 4.3
Reflected XSS Vulnerability in ONLINE SHOPPING SYSTEM offersmail.php
github.com · 2026-08-17

### Vulnerability Overview - **Vulnerability Name**: ONLINE SHOPPING SYSTEM offersmail.php Reflected XSS Vulnerability - **Vulnerability Type**: Reflected Cross-Site Scripting (Reflected XSS) - **Affe…

Read more
CVSS 4.7
Magento v2.4.4 Admin ACL Bypass Allows Unauthorized Access to Arbitrary RMA Data
github.com · 2026-08-17

### Vulnerability Overview In Magento v2.4.4, multiple backend endpoints under `admin/sales/rma/requests/*` are accessible to low-privilege administrators, even if the user lacks the `Sales / RMA` per…

Read more
CVSS 4.3
Bagisto v2.4.4 Broken Access Control: Low-Privilege Admin Can Read Arbitrary Customer Data
github.com · 2026-08-17

### Vulnerability Overview **Broken Access Control Allows Low-Privileged Admin to Read Arbitrary Customer Behavioral Data** In Bagisto v2.4.4, several backend endpoints exposed customer behavioral dat…

Read more
CVSS 3.5
Bagisto v2.4.4 Stored XSS in RMA Message Injection
github.com · 2026-08-17

### Vulnerability Overview In Bagisto v2.4.4, frontend customers can inject malicious HTML or JavaScript code into RMA (Return Merchandise Authorization) conversation messages. Due to the fact that on…

Read more
CVSS 8.3
OPPO ColorOS com.oppo.oppoappstore Intent Redirection Vulnerability
security.oppo.com · 2026-08-17

### Vulnerability Overview This vulnerability affects the ColorOS system on OPPO smartphones, specifically within the `com.oppo.oppoappstore` application. The `com.oppo.oppoappstore.activity.AppDetail…

Read more
CVSS 4.3
Bagisto v2.4.4 RMA Business Logic Bypass via Server-Side State Validation Failure
github.com · 2026-08-17

### Vulnerability Overview In Bagisto v2.4.4, frontend customer RMA status operations are not fully protected by server-side state validation. Specifically: 1. Normal logged-in customers can directly …

Read more
CVSS 6.3
Bagisto v2.4.4 Unauthenticated Access to Backend Config Endpoints and Cache Management
github.com · 2026-08-17

### Vulnerability Overview In Bagisto v2.4.4, endpoints for multiple backend configuration modules are accessible to low-privileged administrator users, even if they lack configuration management perm…

Read more
ShopSmart for WooCommerce <= 1.0.0 Unauthenticated IDOR Sensitive Info Disclosure (CVE-2026-14832)
wpscan.com · 2026-08-17

### Vulnerability Overview - **Vulnerability Name**: ShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone - **Vulnerability Type**: I…

Read more
WooMS <= 9.14 Unauthenticated SSRF and Sensitive Information Disclosure (CVE-2026-13700)
wpscan.com · 2026-08-17

### Vulnerability Overview - **Vulnerability Name**: WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure - **Description**: The plugin does not validate us…

Read more
CVSS 3.1
Orange View DualSafe Chrome Extension postMessage Origin Validation Flaw Leads to Credential Exposure
github.com · 2026-08-17

### Vulnerability Overview Orange View Limited DualSafe Password Manager & Digital Vault version 1.4.35 contains an unvalidated `postMessage` bridge vulnerability, leading to the exposure of stored cr…

Read more
CVSS 5.4
AdBlock for YouTube 7.2.1 Unauth DOM Event Validation Leads to Persistent Ad-Blocker Bypass
github.com · 2026-08-17

### Vulnerability Overview A vulnerability exists in AdBlock for YouTube version 7.2.1 that allows the persistent disabling of ad-blocking functionality via unauthenticated DOM events. The core weakne…

Read more
CVSS 4.3
Alaev SEO Tools Chrome Extension HTML Injection in Popup
github.com · 2026-08-17

### Vulnerability Overview Alaev & Co Alaev SEO Tools version 1.0.10 allows HTML injection into the extension popup via unsanitized page SEO fields. The primary weakness is that user-controlled HTML i…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.