Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 43011+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 7.3
Jinher OA Pre-Auth SQL Injection Vulnerability Report with POC
github.com · 2026-08-16

# Jinher OA SQL Injection Vulnerability Report #1 ## Vulnerability Overview - **Affected Product**: Jinher OA (Jhssoft OA) - **Affected Component**: /C6/JhsSoft.Web.HrmAttendance/attendance_out_approv…

Read more
Premium intel
CVSS 8.1
B-Link B-Link AC1200 TR-069 Hardcoded Credentials Remote Access
github.com · 2026-08-16

### Vulnerability Overview **Vulnerability Name**: Hardcoded TR-069 (easywcmp) Remote Management Credentials **Severity**: CRITICAL **Firmware Version**: X-PRO(ACS), Dual_V1.0.22-20231228-upgrade.bin …

Read more
Premium intel
CVSS 9.8
6Storage Rentals <= 2.27.0 Unauthenticated Account Takeover via 'email' Parameter (CVE-2026-15303)
www.wordfence.com · 2026-08-16

### Vulnerability Overview - **Vulnerability Name**: 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Parameter - **CVE ID**: CVE-2026-15303 - **CVSS Score**: 9.8 (Critical) -…

Read more
Premium intel
CVSS 8.1
B-Link AC1200 Router Hardcoded Credentials Vulnerability & RCE PoC
github.com · 2026-08-16

### Vulnerability Overview - **Vulnerability Name**: B-Link X-PRO(AC6) Router Firmware — Hardcoded Credentials Vulnerability Report - **Severity**: CRITICAL - **Firmware Version**: X-PRO(AC6)_Dual_V1.…

Read more
CVSS 7.3
Class and Exam Timetabling System V1.0 Unauthenticated SQL Injection Vulnerability with POC
github.com · 2026-08-16

### Vulnerability Overview - **Project Name**: Class and Exam Timetabling System Project V1.0 - **Affected File**: `edit_teacher.php` - **Vulnerability Type**: SQL Injection - **Root Cause**: An SQL i…

Read more
Premium intel
CVSS 8.8
Huawei Cloud Stack 8.0.1 OBS Arbitrary File Read Vulnerability with POC
www.wordfence.com · 2026-08-16

### Vulnerability Overview - **Vulnerability Name**: Huawei Cloud Stack 8.0.1 Object Storage Service (OBS) Arbitrary File Read Vulnerability - **Vulnerability Description**: Huawei Cloud Stack 8.0.1 O…

Read more
CVSS 7.1
Red Hat RHSA-2026:54666: CVE-2026-13601 Yelp Flatpak Host File Disclosure
access.redhat.com · 2026-08-16

### Vulnerability Overview - **Vulnerability Name**: RHSA-2026:54666 - Security Advisory - **Publication Date**: 2026-08-13 - **Update Date**: 2026-08-13 - **Severity**: Important - **CVSS Score**: No…

Read more
CVSS 3.7
VictoriaMetrics VMAuth Missing Brute Force Protection Vulnerability
github.com · 2026-08-16

### Vulnerability Overview **Vulnerability Name**: Missing Brute Force Protection #11180 **Description**: The authentication endpoint of VMAuth [ [username] Examples: python3 poc_1001N_002_bruteforce.…

Read more
CVSS 3.7
VictoriaMetrics vmauth Brute-force Mitigation Fix and POC
github.com · 2026-08-16

### Vulnerability Overview This vulnerability affects the `app/vmauth` module in VictoriaMetrics. Attackers can attempt brute-force attacks by sending thousands of authentication requests per second. …

Read more
CVSS 3.7
VictoriaMetrics v1.148.0 Remote Write Stream Aggregation Resource Leak Bug and Security Updates
github.com · 2026-08-16

### Vulnerability Overview A bug causing increased CPU and memory usage was discovered in VictoriaMetrics v1.147.0. This issue arises when using the `-remoteWrite.streamAggr.config` or `remoteWrite.st…

Read more
CVSS 3.7
D-Tale Login Endpoint Lacks Rate Limiting and Uses Plaintext Password Storage
github.com · 2026-08-16

### Vulnerability Overview **Vulnerability Name**: Login Endpoint Lacks Brute-Force Protection (No Rate Limiting / Lockout) #961 **Vulnerability Type**: - CWE-307: Improper Restriction of Excessive Au…

Read more
CVSS 7.2
Apache Xerces-J Base64 DoS Vulnerability Advisory
www.wordfence.com · 2026-08-16

# Vulnerability Overview This vulnerability exists in the `com.sun.org.apache.xerces.internal.impl.dv.util.Base64` class, which is part of the Xerces XML parser and is used to process Base64-encoded d…

Read more
Debian DSA 6443-1: Docker/BuildKit Privilege Escalation & Access Bypass Fixes
lists.debian.org · 2026-08-16

### Vulnerability Overview - **Vulnerability ID**: DSA 6443-1 - **Publication Date**: August 19, 2026 - **Description**: Multiple vulnerabilities have been identified in the Docker container engine an…

Read more
CVSS 3.7
D-Tale Weak SECRET_KEY Causes Session Forgery and Authentication Bypass
github.com · 2026-08-15

### Vulnerability Overview **Vulnerability Name**: Weak Flask SECRET_KEY Leads to Session Forgery / Authentication Bypass #960 **Vulnerability Type**: - CWE-331: Insufficient Entropy - CWE-330: Use of…

Read more
CVSS 6.5
Groundhogg <= 4.5.14 Authenticated SQL Injection via 'tag_query' (CVE-2026-16387)
www.wordfence.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter - **CVE ID**: CVE-2026-16387 - **CVSS Score**: 6.5 (Medium) …

Read more
Premium intel
CVSS 9.8
WordPress User Session Synchronizer Plugin Pre-Auth Authentication Bypass leading to Account Takeover
www.wordfence.com · 2026-08-15

# User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass Leading to Account Takeover ## Vulnerability Overview The User Session Synchronizer plugin for WordPress contains an authen…

Read more
CVSS 7.2
Cookie Banner for GDPR/CCPA <=4.3.5 Authenticated Stored XSS (CVE-2026-13360) Advisory
www.wordfence.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter - **Vulnerability Type…

Read more
CVSS 4.2
Fastify @fastify/oauth2 Login CSRF Vulnerability (CVE-2023-31999) and Patch Details
github.com · 2026-08-15

### Vulnerability Overview `@fastify/oauth2` is affected by a login CSRF vulnerability. Attackers can exploit this flaw by implanting OAuth `state` cookies, allowing them to log into the application a…

Read more
CVSS 6.5
WPML Multilingual CMS <= 4.9.5 Authenticated SQL Injection (CVE-2026-12348)
www.wordfence.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter - **CVE ID**: CVE-2026-12348 - **CVSS Score**: 6…

Read more
CVSS 3.7
Open Source POS: Brute Force Protection Fix & Refund Logic Patch
github.com · 2026-08-15

### Vulnerability Overview The webpage screenshot displays a vulnerability fix commit record for an open-source POS system (opensourcepos). The main issues fixed are: 1. **Undefined ID in CSV Import**…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.