Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE vulnerability search

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-80197 Kimai before 2.57.0 Improper Authorization via Favorite Endpoints kimai kimai Medium 4.3 2026-08-25 23:19:04 Deep Dive
CVE-2026-80198 🧪 Kimai before 2.56.0 Information Disclosure via config() Twig Function kimai kimai High 7.5 2026-08-25 23:19:04 Deep Dive
CVE-2026-80196 🧪 Kimai before 2.58.0 Authentication Bypass via Password Reset Link kimai kimai High 7.5 2026-08-25 23:19:03 Deep Dive
CVE-2026-80194 Kimai before 2.64.0 Missing Authorization via ProjectViewController export kimai kimai Medium 4.3 2026-08-25 23:19:02 Deep Dive
CVE-2026-80195 Kimai before 2.63.0 Team Membership Removal via API kimai kimai Medium 5.4 2026-08-25 23:19:02 Deep Dive
CVE-2026-80193 🧪 Kimai before 2.62.0 Authorization Bypass via QuickEntry kimai kimai High 8.8 2026-08-25 23:19:01 Deep Dive
CVE-2026-80192 better-auth SSO before 1.6.27 Domain Ownership Authentication Bypass better-auth sso High 8.1 2026-08-25 23:19:00 Deep Dive
CVE-2026-80191 🧪 GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthenticated Requests GROWI, Inc. GROWI High 7.5 2026-08-25 23:19:00 Deep Dive
CVE-2026-80189 LeafWiki 0.10.0 through 0.12.0 Uncontrolled Resource Consumption via Unbounded ZIP Extraction perber leafwiki Medium 6.5 2026-08-25 23:18:59 Deep Dive
CVE-2026-57170 🧪 Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) oscal-compass compliance-trestle High 7.8 2026-08-25 23:18:29 Deep Dive
CVE-2026-52776 🧪 Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 oscal-compass compliance-trestle High 8.6 2026-08-25 23:12:25 Deep Dive
CVE-2026-54757 🧪 Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data oscal-compass compliance-trestle High 7.8 2026-08-25 23:02:12 Deep Dive
CVE-2026-44476 Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients with client_secret doorkeeper-gem doorkeeper-openid_connect Medium 6.3 2026-08-25 22:47:55 Deep Dive
CVE-2026-41707 Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay Spring Spring Security High 7.4 2026-08-25 22:34:31 Deep Dive
CVE-2026-79912 🧪 TOTOLINK N600R cstecgi.cgi getCurrentTime command injection TOTOLINK N600R High 8.3 2026-08-25 22:30:12 Deep Dive
CVE-2026-15916 Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010 Drupal Drupal core - - 2026-08-25 22:22:27 Deep Dive
CVE-2026-15917 Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011 Drupal Drupal core - - 2026-08-25 22:22:24 Deep Dive
CVE-2026-55805 Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012 Drupal Drupal core - - 2026-08-25 22:22:21 Deep Dive
CVE-2026-16638 Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080 Drupal Media Folders - - 2026-08-25 22:22:18 Deep Dive
CVE-2026-16639 Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 Drupal Internationalization Single Sign-On - - 2026-08-25 22:22:13 Deep Dive