目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

安全情报专区 11+

精选漏洞公告、利用分析、安全博客、GHSA Advisory 等情报来源,已自动清洗 + 中英双语呈现,持续更新。

240
已接入情报源
113
当前稳定在线
136
24 小时新增
11+
AI 处理情报
持续监听、清洗、翻译并进行 AI 分析 监听情报
示例:RCE · SSRF · GHSA · 反序列化
筛选
清除筛选
High
Strapi v4.5.0 以下版本 sanitize-html 模块 XSS 漏洞修复与 DOMPurify 迁移分析
github.com · 2026-09-13
strapi v4.5.0 · strapi versions prior to v4.5.0 using sanitize-html
Read more
精品
High
Strapi 5.45.0 WYSIWYG 编辑器 XSS 漏洞及修复指南
github.com · 2026-09-13
Strapi 5.45.0 · Strapi 5.46.0
Read more
Critical
Strapi 内容管理器 WYSIWYG 组件存储型 XSS 漏洞及修复
GHSA-j7c8-9v4m-x2f3 · github.com · 2026-09-13
Strapi (content-manager, WYSIWYG rich text preview component)
Read more
High
Strapi users-permissions模块速率限制绕过修复
github.com · 2026-05-22
Strapi users-permissions module
Read more
Critical
Strapi Content Type Builder 严重SQL注入漏洞 (CVE-2026-22599) 公告
CVE-2026-22599 · github.com · 2026-05-22
@strapi/content-type-builder>=5.0.0,<5.33.1 · @strapi/plugin-content-type-builder>=4.0.0,<4.26.0
Read more
Medium
CVE-2025-64526: Strapi 认证路由速率限制绕过漏洞分析
CVE-2025-64526 · github.com · 2026-05-22
@strapi/plugin-users-permissions <= 4.4.0
Read more
Medium
Strapi @strapi/plugin-upload 拒绝服务漏洞 (CVE-2024-31217)
CVE-2024-31217 · github.com · 2025-11-10
@strapi/plugin-upload <=4.21.0
Read more
Low
Strapi @strapi/core 弱密码长度验证漏洞 (CVE-2025-25298)
GHSA-2cjv-6wg9-f4f3 · github.com · 2025-10-17
@strapi/core < 5.10.3
Read more
Medium
Strapi SSRF漏洞(CVE-2021-41788)分析及复现
CVE-2021-41788 · github.com · 2025-05-30
@strapi/admin <1.25.2
Read more

每篇文章经过自动 HTML→Markdown 清洗 + LLM 去噪 + 中英双语翻译。原始链接保留在文章末尾。

想看哪个安全博客 / 公告源?邮件告诉我们,每周新接 1-2 个。