Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE vulnerability search

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-24263 🧪 NVIDIA DGX Spark固件空指针引用导致代码执行 NVIDIA DGX Spark High 8.2 2026-08-25 16:11:07 Deep Dive
CVE-2026-47626 NVIDIA DGX Spark系统固件越界写入漏洞 NVIDIA DGX Spark High 8.2 2026-08-25 16:10:57 Deep Dive
CVE-2026-24262 NVIDIA DGX Spark固件越界写入漏洞 NVIDIA DGX Spark High 8.2 2026-08-25 16:10:56 Deep Dive
CVE-2026-18444 Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW NI LabVIEW Medium 6.6 2026-08-25 16:09:03 Deep Dive
CVE-2026-55571 djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls djust-org djust High 8.2 2026-08-25 16:05:49 Deep Dive
CVE-2026-13478 Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_count zephyrproject zephyr Medium 5.5 2026-08-25 16:05:39 Deep Dive
CVE-2026-13217 NULL-pointer dereference in Zephyr OCPP CALLRESULT parsing via unchecked strtok_r/atoi zephyrproject zephyr Medium 5.9 2026-08-25 16:05:38 Deep Dive
CVE-2026-13216 Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length zephyrproject zephyr Medium 6.1 2026-08-25 16:05:37 Deep Dive
CVE-2026-55640 🧪 Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) cbcoutinho nextcloud-mcp-server Critical 9.1 2026-08-25 16:03:28 Deep Dive
CVE-2026-79785 X-AnyLabeling before 4.0.0-beta.9 Improper Certificate Validation in Model Downloads CVHub520 X-AnyLabeling Medium 5.9 2026-08-25 16:03:20 Deep Dive
CVE-2026-55580 🧪 mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist sonirico mcp-shell High 8.6 2026-08-25 15:42:36 Deep Dive
CVE-2026-55581 🧪 mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable sonirico mcp-shell High 8.4 2026-08-25 15:40:11 Deep Dive
CVE-2026-55582 🧪 mcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias sonirico mcp-shell High 8.4 2026-08-25 15:37:43 Deep Dive
CVE-2026-55546 🧪 QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input QWED-AI qwed-mcp Critical 9.8 2026-08-25 15:25:35 Deep Dive
CVE-2026-70550 Potential unauthorized access to private Composer repository metadata in JFrog Artifactory jfrog artifactory Medium 6.5 2026-08-25 15:22:53 Deep Dive
CVE-2026-55536 🧪 Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) MervinPraison PraisonAI Critical 9.1 2026-08-25 15:21:53 Deep Dive
CVE-2026-55532 🧪 PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server MervinPraison PraisonAI High 7.6 2026-08-25 15:17:53 Deep Dive
CVE-2026-70548 SSRF In CocoaPods Via JFrog Artifactory External Dependency jfrog artifactory Low 3.5 2026-08-25 15:17:17 Deep Dive
CVE-2026-79783 rclone before 1.74.4 Privilege Escalation via setuid Metadata rclone rclone Low 3.6 2026-08-25 15:16:12 Deep Dive
CVE-2026-79784 🧪 Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration gemelo-ai vocos High 8.8 2026-08-25 15:16:12 Deep Dive