Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 11

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-42456 AnythingLLM: Cross-User TTS Audio Disclosure via Chat ID (IDOR) Mintplex-Labsanything-llm Medium 4.3 2026-05-08 23:01:30 Deep Dive
CVE-2026-42354 Sentry: Improper authentication on SAML SSO process allows user identity linking getsentrysentry Critical 9.1 2026-05-08 22:58:34 Deep Dive
CVE-2026-42454 Termix: OS Command Injection in Docker Container Management Endpoints Termix-SSHTermix Critical 9.9 2026-05-08 22:56:18 Deep Dive
CVE-2026-42453 Termix: Command injection in extractArchive/compressFiles via double-quote escaping bypass Termix-SSHTermix--2026-05-08 22:55:30 Deep Dive
CVE-2026-42452 Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP Termix-SSHTermix High 8.1 2026-05-08 22:54:12 Deep Dive
CVE-2026-42451 Grimmory: Stored XSS via Malicious EPUB Enables Session Token Theft grimmory-toolsgrimmory Medium 6.3 2026-05-08 22:51:22 Deep Dive
CVE-2026-41682 pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion pupnppupnp--2026-05-08 22:47:37 Deep Dive
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading vimvim Medium 6.6 2026-05-08 22:42:35 Deep Dive
CVE-2026-44656 Vim: OS Command Injection via 'path' completion vimvim--2026-05-08 22:40:50 Deep Dive
CVE-2026-42307 Vim: OS Command Injection in netrw vimvim Medium 4.4 2026-05-08 22:38:54 Deep Dive
CVE-2026-42350 Kargo: Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter akuitykargo--2026-05-08 22:35:30 Deep Dive
CVE-2026-42352 pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber geopythonpygeoapi High 8.6 2026-05-08 22:31:50 Deep Dive
CVE-2026-42351 pygeoapi: Path Traversal in STAC FileSystemProvider geopythonpygeoapi High 7.5 2026-05-08 22:31:18 Deep Dive
CVE-2026-42556 Postiz stored XSS in public preview page gitroomhqpostiz-app High 8.9 2026-05-08 22:28:33 Deep Dive
CVE-2026-42346 Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation paths gitroomhqpostiz-app Medium 6.5 2026-05-08 22:26:51 Deep Dive
CVE-2026-42298 Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev gitroomhqpostiz-app Critical 10.0 2026-05-08 22:24:10 Deep Dive
CVE-2026-42339 New API: SSRF Filter Bypass via 0.0.0.0 QuantumNousnew-api--2026-05-08 22:21:54 Deep Dive
CVE-2026-41432 New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud QuantumNousnew-api High 7.1 2026-05-08 22:21:32 Deep Dive
CVE-2026-44286 FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation labringFastGPT--2026-05-08 22:17:18 Deep Dive
CVE-2026-44284 FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution labringFastGPT Medium 6.3 2026-05-08 22:12:40 Deep Dive