Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 40525+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 9.8
Fix Path Traversal in gitroomhq/postiz-app upload route
github.com · 2026-08-07

### Vulnerability Overview This vulnerability involves a Path Traversal issue that could lead to unauthorized file access. ### Scope of Impact - **Project**: `gitroomhq/postiz-app` - **File**: `apps/f…

Read more
Premium intel
CVSS 9.8
Postiz Unauth File Read via Path Traversal Leading to Instance Takeover (CVE-2026-19264)
gadvisory.org · 2026-08-07

### Vulnerability Overview - **Vulnerability Name**: Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover - **Vulnerability Description…

Read more
Crestron DMC-STRO Remote Root RCE via OS Command Injection (CVE-2019-18184) with POC
cyberleap.it · 2026-08-07

### Vulnerability Overview - **Vulnerability Name**: Crestron DMC-STRO Remote Root RCE - **CVE ID**: CVE-2019-18184 - **Discovered by**: Gabrio Tognazzi - **Publication Date**: November 27, 2019 - **V…

Read more
CRESTRON DMC-STRO Remote Code Execution via Shell Injection
web.archive.org · 2026-08-07

# CRESTRON DMC-STRO Remote Code Execution Vulnerability ## Vulnerability Overview A critical vulnerability was discovered in the CTP console, allowing system commands to be executed as the root user t…

Read more
CVSS 5.3
OOB Read Vulnerability in SV Subscriber confRev Handling: Analysis and Fix
github.com · 2026-08-07

# Out-of-Bounds Read in SV Subscriber confRev Handling via Missing Fixed-Length Validation #598 ## Vulnerability Overview - **Vulnerability Type**: Out-of-Bounds Read - **Trigger Condition**: A malici…

Read more
CVSS 5.3
Out-of-Bounds Read in SV Subscriber confRev Parsing Analysis
github.com · 2026-08-07

# Out-of-Bounds Read in SV Subscriber confRev Handling via Missing Fixed-Length Validation #598 ## Vulnerability Overview - **Vulnerability Type**: Heap Buffer Overflow / Out-of-Bounds Read - **Attack…

Read more
CVSS 5.3
LIB61850: Fixed OOB Read in SV subscriber parseASDU due to missing length validation
github.com · 2026-08-07

### Vulnerability Overview - **Vulnerability Name**: SV subscriber: Fixed missing length validation of some ASDU elements that can cause OOB reads when these fields are later used by the application (…

Read more
CVSS 2.3
CVE-2026-61477: libvirt network XML newline injection leads to dnsmasq config injection and arbitrary command execution
bugzilla.redhat.com · 2026-08-07

### Vulnerability Overview - **Vulnerability ID**: CVE-2026-61477 - **Description**: The network XML DNS TXT/SRV fields in libvirt allow newline characters to be injected via dnsmasq configuration dir…

Read more
CVSS 2.3
KVM/libvirt DoS via DNS TXT/SRV XML Parsing via Numeric Char Refs (CVE-2020-61477)
gitlab.com · 2026-08-07

### Vulnerability Overview This vulnerability involves a denial of service issue in the handling of line breaks (LF and CR) within DNS TXT and SRV records. Specifically, when numeric character referen…

Read more
CVSS 5.9
SuperTokens Core Cross-Tenant Session Trust Vulnerability (CVE-2026-37171)
whitenbaker.com · 2026-08-07

# Cross-Tenant Session Trust Vulnerability in SuperTokens Core ## Vulnerability Overview - **CVE ID**: CVE-2026-37171 - **Severity**: 7.1 High - **Weakness Type**: Incorrect Authorization (CWE-863) - …

Read more
Premium intel
CVSS 9.8
TrueBooker <= 1.2.3 Missing Authorization Unauthenticated Arbitrary Password Reset (CVE-2026-14365)
www.wordfence.com · 2026-08-07

### Vulnerability Overview - **Vulnerability Name**: TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' - **CVE ID**: CVE-2026-14365 - …

Read more
Premium intel
CVSS 9.3
Kadence Memberships <=4.0.0 Unauthenticated Password Reset Link Poisoning to Account Takeover (CVE-2026-9273)
www.wordfence.com · 2026-08-07

### Vulnerability Overview - **Vulnerability Name**: Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover - **CVE ID**: CVE-2026-9273 - …

Read more
CVSS 7.1
Telefunken Smart TV SSRF Vulnerability in SmartCenter (CVE-2026-15270) Advisory
firebasestorage.googleapis.com · 2026-08-07

### Vulnerability Overview Vestel has identified a vulnerability in the SmartCenter feature found in the Telefunken TE2553B45V20Z Smart TV, which is based on the Vestel MIB11 / Voltos3.1 / TiVo OS pla…

Read more
CVSS 5.3
WordPress ShareOpenly Plugin Cross-Site Scripting (XSS) via Missing esc_url()
github.com · 2026-08-07

### Vulnerability Overview **Vulnerability Name**: Cross-Site Scripting (XSS) via Missing `esc_url()` on Shared URL in Content Output **CVE ID**: CVE-2025-8204 **Severity**: Moderate **Affected Versio…

Read more
CVSS 5.9
Postgrex Elixir SQL Injection Vulnerability (CVE-2024-6838) via :comment Option and Fix
github.com · 2026-08-07

### Vulnerability Overview **Vulnerability Name**: SQL injection via the `:comment` option in `Postgrex.stream/4` **Description**: Postgrex does not sanitize the `:comment` query option when used in s…

Read more
CVSS 7.7
Dell OMSA Pre-Auth Authentication Bypass & Path Traversal Advisory (CVE-2026-56793/94)
www.dell.com · 2026-08-07

### Vulnerability Overview - **CVE-2026-56793**: Dell OpenManage Server Administrator (OMSA) prior to version 11.1.0.2 contains an incorrect authentication vulnerability. An unauthenticated attacker c…

Read more
CVSS 5.9
Postgrex Elixir Driver SQL Injection via Invalid Comment Handling Fix
github.com · 2026-08-07

### Vulnerability Overview This vulnerability involves improper handling of invalid comments during PostgreSQL streaming operations. Specifically, when SQL statements containing invalid comments are e…

Read more
CVSS 5.9
SQL Injection in Elixir Ecto Postgres Driver (CVE-2026-66838)
cna.erlef.org · 2026-08-07

### Vulnerability Overview - **CVE ID**: CVE-2026-66838 - **Published Date**: 2026-06-07 - **Updated Date**: 2026-06-07 - **Vulnerability Type**: SQL Injection - **Description**: A SQL injection vulne…

Read more
CVSS 5.9
postgrex Elixir SQL Injection Fix via Comment Validation
github.com · 2026-08-07

### Vulnerability Overview This vulnerability involves the handling of invalid comments in the `elixir-ecto/postgrex` repository. The submitter `josevalim` pushed a fix one hour ago, rejecting invalid…

Read more
Premium intel
CVSS 8.8
WordPress File Manager Arbitrary File Read/Delete via Missing Authorization (CVE-2026-15991)
www.wordfence.com · 2026-08-07

### Vulnerability Overview - **Vulnerability Name**: File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter - **CVE ID…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.