Aggregator
首款由AI研发的零日漏洞利用程序
1 month ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
凌晨三点收到一千条漏洞告警,AI 替我看完了
1 month ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
1 month ago
In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
Aldrin Ceriola
New Release: Tor Browser 15.0.14
1 month ago
Tor Browser 15.0.14 is now available from the Tor Browser download page and also from our distributi
试遍所有 Navidrome 客户端,我最终选择了 Narjo
1 month ago
我是一个对音乐播放体验有点执念的人。自从搭建了 [[Navidrome]] 自托管音乐服务器,我就开始了一段漫长的客户端寻觅之旅。在 iOS 上,我几乎把能找到的 [[Nav
CVE-2026-21789 | HCL Connections 8.0 authorization (KB0129719)
1 month ago
A vulnerability classified as critical was found in HCL Connections 8.0. Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-21789. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-27964 | NeoRazorX facturascripts up to 2025.7 cross site scripting (GHSA-gq5c-rw37-g46c)
1 month ago
A vulnerability classified as problematic has been found in NeoRazorX facturascripts up to 2025.7. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-27964. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-45246 | steipete summarize up to 0.15.0 Config File permission assignment (EUVD-2026-30799)
1 month ago
A vulnerability described as problematic has been identified in steipete summarize up to 0.15.0. This impacts an unknown function of the component Config File. Executing a manipulation can lead to incorrect permission assignment.
This vulnerability is handled as CVE-2026-45246. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-45245 | steipete summarize up to 0.15.0 server-side request forgery
1 month ago
A vulnerability marked as critical has been reported in steipete summarize up to 0.15.0. This affects an unknown function. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-45245. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-45231 | DumbWareio DumbAssets up to 1.0.11 Asset API Endpoint cross site scripting
1 month ago
A vulnerability labeled as problematic has been found in DumbWareio DumbAssets up to 1.0.11. The impacted element is an unknown function of the component Asset API Endpoint. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-45231. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-27737 | BigBlueButton up to 3.0.18 cross site scripting (GHSA-8vv7-vj94-q2pv)
1 month ago
A vulnerability identified as problematic has been detected in BigBlueButton up to 3.0.18. The affected element is an unknown function. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-27737. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-47092 | jarrodwatts claude-hud up to 0.0.12 on Windows Environment Variable execFile uncontrolled search path (Issue 485)
1 month ago
A vulnerability categorized as problematic has been discovered in jarrodwatts claude-hud up to 0.0.12 on Windows. Impacted is the function execFile of the component Environment Variable Handler. The manipulation results in uncontrolled search path.
This vulnerability is reported as CVE-2026-47092. The attack requires a local approach. No exploit exists.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2026-8851 | Alinto SOGo up to 5.12.7 addUserInAcls Endpoint /acls sogo_acl uid sql injection
1 month ago
A vulnerability was found in Alinto SOGo up to 5.12.7. It has been rated as critical. This issue affects the function sogo_acl of the file /acls of the component addUserInAcls Endpoint. The manipulation of the argument uid leads to sql injection.
This vulnerability is documented as CVE-2026-8851. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-27130 | dokploy up to 0.26.6 execAsync appName os command injection (GHSA-fcgq-jjfg-hrhj)
1 month ago
A vulnerability was found in dokploy up to 0.26.6. It has been declared as critical. This vulnerability affects the function execAsync. Executing a manipulation of the argument appName can lead to os command injection.
This vulnerability is registered as CVE-2026-27130. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-26978 | FreePBX up to 16.0.70/17.0.5 Backup unserialize deserialization (GHSA-5v7h-49gr-jcwr / EUVD-2026-30810)
1 month ago
A vulnerability was found in FreePBX up to 16.0.70/17.0.5. It has been classified as critical. This affects the function unserialize of the component Backup Module. Performing a manipulation results in deserialization.
This vulnerability is cataloged as CVE-2026-26978. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-45244 | steipete summarize up to 0.15.0 authorization
1 month ago
A vulnerability was found in steipete summarize up to 0.15.0 and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-45244. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-45242 | steipete summarize up to 0.15.0 /v1/summarize authorization
1 month ago
A vulnerability has been found in steipete summarize up to 0.15.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /v1/summarize. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2026-45242. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-22810 | laurent22 joplin up to 3.5.6 path traversal (GHSA-gcmj-c9gg-9vh6)
1 month ago
A vulnerability, which was classified as problematic, was found in laurent22 joplin up to 3.5.6. Affected is an unknown function. The manipulation results in path traversal: '../filedir'.
This vulnerability is identified as CVE-2026-22810. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-47091 | jarrodwatts claude-hud up to 0.0.12 transcript_path path traversal (Issue 485)
1 month ago
A vulnerability, which was classified as critical, has been found in jarrodwatts claude-hud up to 0.0.12. This impacts an unknown function. The manipulation of the argument transcript_path leads to path traversal.
This vulnerability is referenced as CVE-2026-47091. The attack can only be performed from a local environment. No exploit is available.
It is suggested to install a patch to address this issue.
vuldb.com