最新漏洞情报100
CVE & PoC Alerts in Real Time
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
File Browser: Colliding username normalization gives two users the same home directory
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
node-tar: Decompression/parse DoS via unlimited input
node-tar: Negative tar entry size causes infinite loop in archive replace
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
Directus: Authorization-dependent response served from unsegmented cache key
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
js-yaml: YAML merge-key chains can force quadratic CPU consumption
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
Composer: Arbitrary file write outside vendor via malicious transitive package name
vLLM denial of service via prompt embeds on M-RoPE models
Tornado: Quadratic DoS via Crafted Multipart Parameters
Tornado: Quadratic DoS via Repeated Header Coalescing
fastjson <= 1.2.83 任意代码执行漏洞
Fastjson 1.2.83 远程代码执行漏洞(QVD-2026-43021)
Fastjson 1.2.83 远程代码执行漏洞
XStore Theme / SQL 注入漏洞(CVE-2026-3326)
Kubernetes Dashboard /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs 权限绕过漏洞(CVE-2018-18264)
EnjoySCM 供应链管理系统 /BackCommunication/wcfCommunicate.svc SQL 注入漏洞
喰星云数字化餐饮服务系统 /chainsales/head/user/addUser 权限绕过漏洞
企业信息发送平台 /getLicenceDetail 文件读取漏洞
北京中科聚网一体化运营平台 /manage/tplresource/importVisualModuleImg 文件上传漏洞
Goploy /user/login 默认口令漏洞
东胜物流软件 /PriceCarrier/OpSailingDateInfoGridSource.aspx SQL 注入漏洞
东胜物流软件 /PriceCarrier/CrmProxyMailListHtmlGridSource.aspx SQL 注入漏洞
Casdoor /conf/app.conf 信息泄露漏洞(CVE-2024-5587)
天问物业ERP系统 /HM/M_Main/HC/DataGetControl.aspx SQL 注入漏洞
UniFi Access /api/ucore/backup/export 命令执行漏洞(CVE-2025-52665)
9router /api/tunnel/tailscale-install 命令执行漏洞
智联云采 SRM2.0 /api/sys/app/autologin 权限绕过漏洞
JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞
方向标邮件网关 /common/cgi/get_audit.cgi 命令执行漏洞
Gorse /api/dump 未授权访问漏洞 (CVE-2026-56782)
用友 U8cloud /service/XChangeServlet SQL 注入漏洞
XMall /item/list SQL 注入漏洞(CVE-2024-24112)
Versa Concerto /portalapi/v1/roles/option 权限绕过漏洞(CVE-2025-34027)
WordPress Pie Register / 权限绕过漏洞(CVE-2025-34077)
云连ERP管理系统 /gateway/download!download.action 代码执行漏洞
FOSSBilling /system/string_render 命令执行漏洞(CVE-2026-28496)
用友GRP-U8Cloud /jmreport/loadTableData SQL 注入漏洞
泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞
用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞
用友U8 Cloud MeasureQueryFrameAction SQL 注入漏洞
FlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442)
蓝凌EIS智慧协同平台 /common/FI_SelEmp.aspx SQL 注入漏洞
WordPress Core Pre-Auth Batch-Route Confusion RCE (CVE-2026-63030)
WordPress Core REST API author_exclude参数SQL注入漏洞(CVE-2026-60137)
CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary file read via file reference expansion
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
sh _uid does not drop supplementary groups (incomplete privilege drop)
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
vLLM has Remote DoS via Invalid Recovered Token Reinjection
WordPress Core REST API 路由混淆漏洞 (wp2shell)
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
Pheditor has an authenticated terminal command whitelist bypass
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure