Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 67+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
Premium intel
Unknown
OpenSearch SQL Plugin Async Query Validation Bypass (CVE-2026-18428)
CVE-2026-18428 · aws.amazon.com · 2026-08-14
OpenSearch SQL Plugin v2.13 to v5.6 · Amazon OpenSearch Service v2.13 to v3.5
Read more
Medium
AWS SDK for C++ Out-of-bounds write in Base64 decoder vulnerability advisory (GHSA-xxx3-prfc-69cx)
GHSA-xxx3-prfc-69cx · github.com · 2026-08-13
aws-cpp-sdk-core <= 1.11.861
Read more
Medium
OpenSearch Alerting Improper Authorization Bypass via Execute Monitor API (GHSA-xpqp-q3wh-685q)
GHSA-xpqp-q3wh-685q · github.com · 2026-08-13
OpenSearch Alerting < 2.19.6 · OpenSearch Alerting < 3.8.0
Read more
High
OpenSearch Security Analytics SSRF via Missing Input Validation (CVE-2026-18952)
CVE-2026-18952 · aws.amazon.com · 2026-08-13
OpenSearch Security Analytics Plugin >= 2.15.0 · Amazon OpenSearch Service engine version >= 2.15.0
Read more
High
OpenSearch Alerting Plugin Missing Authorization Vulnerability (CVE-2026-19311)
CVE-2026-19311 · aws.amazon.com · 2026-08-13
OpenSearch Alerting Plugin 2.4.0 · OpenSearch Alerting Plugin 2.19.5 …
Read more
High
AWS Strands Agents Tools Multi-Tenant Memory Isolation Bypass (CVE-2026-1911)
CVE-2026-1911 · github.com · 2026-08-07
strands-agents-tools < 0.8.3
Read more
Medium
CVE-2026-18954: Authorization Bypass in AWS DocumentDB MCP Server Aggregation Pipeline
CVE-2026-18954 · github.com · 2026-08-06
Amazon AWS Labs DocumentDB MCP Server < 1.0.12
Read more
High
CVE-2026-18953: Pathname Limitation Vulnerability in AWS Transform MCP Server Leading to LPE
CVE-2026-18953 · github.com · 2026-08-06
AWS Transform MCP Server <0.1.5
Read more
Premium intel
High
CVE-2026-18830: Amazon Bedrock AgentCore Input Validation Bypass
CVE-2026-18830 · aws.amazon.com · 2026-08-05
Amazon Bedrock AgentCore harness InvokeHarness API versions before 2026-07-31
Read more
Unknown
CVE-2026-18655: AWS Amazon MQ MCP Server Credential Disclosure via Prompt Injection
CVE-2026-18655 · aws.amazon.com · 2026-08-04
aws-labs.amazon-mq-mcp-server <= 2.0.23
Read more
Premium intel
High
AWS Ops Wheel Stored XSS via Participant URL Leads to Account Takeover (CVE-2024-1441)
CVE-2024-1441 · github.com · 2026-08-01
AWS Ops Wheel versions prior to 168
Read more
High
Strands Agents Tools http_request Unauthorized Access Vulnerability CVE-2026-18394 Advisory
CVE-2026-18394 · aws.amazon.com · 2026-08-01
strands-agents-tools < 0.8.2
Read more
Medium
Strands Agents Tools http_request Proxy Injection Vulnerability Advisory
GHSA-qh6w-2h72-m84v · github.com · 2026-08-01
strands-agents/tools < 0.8.2
Read more
Premium intel
Critical
CVE-2026-18481: Stored XSS in AWS Ops Wheel Participant URL Field Leads to Account Takeover
CVE-2026-18481 · aws.amazon.com · 2026-08-01
AWS Ops Wheel v2 (versions prior to or including PR #168)
Read more
High
AWS aws-smithy-json CVE-2026-18140 Uncontrolled Recursion DoS Vulnerability
CVE-2026-18140 · aws.amazon.com · 2026-07-31
aws-smithy-json <= 0.62.6
Read more
High
CVE-2025-18140: Uncontrolled recursion in aws-smithy-json allows remote DoS
CVE-2025-18140 · github.com · 2026-07-31
aws-smithy-json <= 0.62.6
Read more
Premium intel
Critical
CVE-2025-4318: Code Injection in @aws-amplify/codegen-ui-react (CWE-94)
CVE-2025-4318 · github.com · 2026-07-31
@aws-amplify/codegen-ui-react < 2.20.6
Read more
Premium intel
Premium intel
High
AWS Bedrock AgentCore RCE via install_packages() (CVE-2026-16796)
CVE-2026-16796 · github.com · 2026-07-24
AWS Bedrock AgentCore Python SDK <1.18.1
Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.