Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

Vulnerability List - Page 65

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-44283 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks etcd-ioetcd None 0.0 2026-05-14 17:01:34 Deep Dive
CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability MicrosoftMicrosoft Authenticator for Android Critical 9.6 2026-05-14 17:00:38 Deep Dive
CVE-2026-42897KEV Microsoft Exchange Server Spoofing Vulnerability EPSS 0.10MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23 High 8.1 2026-05-14 17:00:37 Deep Dive
CVE-2026-42572 Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds` hatchet-devhatchet Medium 5.3 2026-05-14 16:58:43 Deep Dive
CVE-2026-44520 Docling-Graph: SSRF via Missing Internal IP Validation in URLInputHandler docling-projectdocling-graph Medium 5.7 2026-05-14 16:56:58 Deep Dive
CVE-2026-6332 Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC Schneider ElectricEcostruxure™ Machine Expert HVAC--2026-05-14 16:54:50 Deep Dive
CVE-2026-41888 Distribution: Tag deletion bypasses `storage.delete.enabled` configuration distributiondistribution--2026-05-14 16:53:38 Deep Dive
CVE-2026-45448 ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') ntopntopng Medium 4.3 2026-05-14 16:48:19 Deep Dive
CVE-2026-44516 Valtimo: Sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer valtimo-platformvaltimo High 7.6 2026-05-14 16:48:06 Deep Dive
CVE-2026-42555 Valtimo: SpEL injection via StandardEvaluationContext allows Remote Code Execution by admin users valtimo-platformvaltimo Critical 9.1 2026-05-14 16:45:49 Deep Dive
CVE-2026-44348 PoDoFo: Double-free vulnerability in compute_hash_to_sign() podofopodofo Low 2.5 2026-05-14 16:38:46 Deep Dive
CVE-2026-44515 Nextcloud News: Authenticated blind SSRF via feed URL nextcloudnews--2026-05-14 16:36:12 Deep Dive
CVE-2026-44827 Diffusers: None.py Trust Remote Code Bypass huggingfacediffusers High 8.8 2026-05-14 16:33:42 Deep Dive
CVE-2026-44513 Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components huggingfacediffusers High 8.8 2026-05-14 16:26:04 Deep Dive
CVE-2026-44514 Kubetail: Cross-Site WebSocket Hijacking allows attacker to read Kubernetes logs from authenticated users kubetail-orgkubetail Medium 6.5 2026-05-14 16:20:12 Deep Dive
CVE-2025-62305 HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions HCLAION Medium 5.1 2026-05-14 16:17:33 Deep Dive
CVE-2026-44511 Katalyst Koi: Session cookies can be replayed after user logout katalystkoi High 7.4 2026-05-14 16:17:29 Deep Dive
CVE-2026-44312 css_parser allows to MITM included https css urls premailercss_parser Medium 5.8 2026-05-14 16:15:05 Deep Dive
CVE-2026-6923 Nuvoton - CWE-1300: Improper Protection of Physical Side Channels NuvotonNPCT7xx Low 3.8 2026-05-14 16:14:34 Deep Dive
CVE-2025-62317 HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. HCLAION Low 2.6 2026-05-14 16:13:35 Deep Dive