Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 43011+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 3.7
OpenSourceOSPOS Login Pre-Auth Rate Limiting Bypass and ReCAPTCHA Timing Oracle
github.com · 2026-08-15

### Vulnerability Overview **Vulnerability Name**: OpenSourcePOS Login Endpoint — Missing Authentication Rate-Limiting / Account-Lockout, Compounded by Post-Password CAPTCHA Validation Ordering **Vuln…

Read more
Premium intel
CVSS 8.1
GHSA-j4cx-787j-xjxg: @fastify/jwt Auth Bypass via Global Key Override (CVE-2025-18500)
github.com · 2026-08-15

# @fastify/jwt Vulnerability Summary ## Vulnerability Overview - **Vulnerability Name**: @fastify/jwt authorization bypass vulnerability allowing global key override of per-request keys - **Vulnerabil…

Read more
CVSS 6.3
Hospital Management System V1.0 SQL Injection in /viewmedicine.php
github.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: itsourcecode Hospital Management System V1.0 SQL Injection Vulnerability #18 - **Vulnerability Type**: SQL Injection - **Affected Product**: Hospit…

Read more
Perl DBI prepare() Heap Buffer Overflow Vulnerability with PoC
github.com · 2026-08-15

### Vulnerability Overview An integer overflow in the DBI `prepare()` function leads to a heap buffer overflow (on 32-bit Perl). Specifically, the `prepare()` function calculates the output buffer siz…

Read more
Perl DBI Placeholder Bypass Leading to SQL Injection (CVE-2026-73194)
github.com · 2026-08-15

### Vulnerability Overview This vulnerability involves an issue where restrictions on placeholders in the DBI (Database Interface) module can be bypassed. Specifically, using `#` and `$` as placeholde…

Read more
CVE-2022-4993: html-formhandler Locale::MakeText routing flaw fix
github.com · 2026-08-15

### Vulnerability Overview - **Vulnerability ID**: CVE-2022-4993 - **Description**: In the `Locale::MakeText` format, external text is not correctly routed, leading to potential security issues. ### S…

Read more
CVE-2026-73193: 32-bit Integer Overflow in ODBC Driver preparseSV Function
github.com · 2026-08-15

### Vulnerability Overview - **Vulnerability ID**: CVE-2026-73193 - **Description**: A memory overflow risk arises due to the improper limiting of placeholder counts in prepared statements. Specifical…

Read more
CVSS 6.4
Hydra Booking WordPress Plugin Stored XSS Vulnerability Advisory (CVE-2026-15948)
www.wordfence.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter - **CVE ID**: CVE-2026-15948 - **CVSS Score**…

Read more
CVSS 6.5
KiviCare <= 4.5.1 Authenticated SQL Injection via searchTerm (CVE-2026-15453)
www.wordfence.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: KiviCare <= 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter - **CVE ID**: CVE-2026-15453 - **CVSS Score**: 6.5 (Medium) - …

Read more
Struts 2 S2-074 Advisory: Localized Text Cache DoS via CVE-2026-73635
cwiki.apache.org · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: S2-074 - **Vulnerability Description**: Unrestricted text cache growth due to request localization leads to memory exhaustion (Denial of Service). …

Read more
Struts 2 S2-070 Vulnerability Advisory: JSON Plugin Shared Parsing State Issue
cwiki.apache.org · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: S2-070 - **Vulnerability Description**: Shared parsing state in the JSON plugin can lead to data leakage, data integrity issues, and bypass of conf…

Read more
Struts 2 S2-073: Unrestricted CSP Report Reading Leading to DoS
cwiki.apache.org · 2026-08-15

# S2-073 ## Vulnerability Overview - **Vulnerability Name**: S2-073 - **Description**: Unbounded read in Content Security Policy violation report collection. - **Reporter**: Lukasz Lenart - **Last Upd…

Read more
CVSS 4.3
Astro Booking Engine <=1.4.0 CSRF Vulnerability (CVE-2025-10308) Advisory
www.wordfence.com · 2026-08-15

### Vulnerability Overview - **Vulnerability Name**: Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset - **Vulnerability Type**: Cross-Site Request Forgery (CSRF) - **CVSS S…

Read more
Premium intel
CVSS 8.8
WordPress Templately Plugin SQLi/RCE Vulnerability Analysis and Fix
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview The webpage screenshot displays a PHP file named `Gutenberg.php`, which belongs to the `Templately` plugin in the WordPress plugin directory. The file contains multiple func…

Read more
Premium intel
CVSS 8.8
WordPress Templately Plugin 3.7.1 File Upload Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview The provided webpage screenshot displays a PHP file named `MyClouds.php`, located in the `templately/tags/3.7.1/includes/API/` directory of a WordPress plugin. A potential s…

Read more
Premium intel
CVSS 8.8
WordPress Templately Plugin Template Import Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview The provided screenshot displays the source code for the `Import.php` file of the `templately` WordPress plugin. The file contains a potential security vulnerability, specif…

Read more
Premium intel
CVSS 8.8
Templately WordPress Plugin API Unauthorized Access Vulnerability
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview The provided webpage screenshot displays the file `templately/tags/3.7.1/includes/API/API.php`, which contains a potential vulnerability. The issue primarily concerns API pe…

Read more
Premium intel
CVSS 8.8
WordPress Templately Plugin File Upload Vulnerability Analysis
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview The webpage screenshot displays a file named `MyClouds.php`, located within the WordPress plugin directory at the path `templately/tags/3.6.5/includes/API/`. The file contai…

Read more
Premium intel
CVSS 8.8
WordPress Templatly Plugin Arbitrary File Upload Vulnerability Analysis and Patch
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview This vulnerability involves the `WPImport.php` file in the WordPress plugin directory, specifically located at `templatly/trunk/includes/Core/Importer/WPImport.php`. The fix…

Read more
Premium intel
CVSS 9.8
Profile Builder Plugin Username Handling Logic Code Analysis
plugins.trac.wordpress.org · 2026-08-15

### Vulnerability Overview The attached screenshot displays a code file from the WordPress plugin directory, specifically located at `profile-builder/tags/3.16.4/front-end/default-fields/username/user…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.