最新漏洞情报100

CVE & PoC Alerts in Real Time

SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking

CVE-2026-72801RCE2026-09-03

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

CVE-2026-72804RCE2026-09-03

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

CVE-2026-72807RCE2026-09-03

SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy

CVE-2026-72809RCE2026-09-03

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

CVE-2026-72810RCE2026-09-03

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

CVE-2026-72811RCE2026-09-03

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

CVE-2026-68584RCE2026-09-03

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

CVE-2026-68586RCE2026-09-03

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

CVE-2026-68587RCE2026-09-03

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

CVE-2026-69083RCE2026-09-03

toml-node: Uncontrolled Recursion

CVE-2026-77465RCE2026-09-03

toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization

CVE-2026-63376RCE2026-09-03

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

CVE-2026-69086RCE2026-09-03

Phoenix: Unbounded channel joins per transport enables DoS over few connections

CVE-2026-56811RCE2026-09-03

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

CVE-2026-69084RCE2026-09-03

amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload

CVE-2026-79921RCE2026-09-03

TOON: Prototype pollution when decoding untrusted TOON input

CVE-2026-82404RCE2026-09-03

Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)

CVE-2026-73222RCE2026-09-03

Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

CVE-2026-73293RCE2026-09-03

Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

CVE-2026-73292RCE2026-09-03

Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

CVE-2026-62681RCE2026-09-03

Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

CVE-2026-62682RCE2026-09-03

Orval: Import-time RCE via schema default -> zod module-level template literal

CVE-2026-72717RCE2026-09-03

Orval: Import-time RCE via array-items default -> zod module-level template literal

CVE-2026-71869RCE2026-09-03

Orval: Import-time RCE via header-parameter default -> zod module-level template literal

CVE-2026-71871RCE2026-09-03

Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator

CVE-2026-71867RCE2026-09-03

Orval: Import-time RCE via enum-typed default -> zod module-level template literal

CVE-2026-71868RCE2026-09-03

Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli

CVE-2026-71865RCE2026-09-03

Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

CVE-2026-71864RCE2026-09-03

ffuf denial of service (OOM) via HTTP response decompression bomb

CVE-2026-73232RCE2026-09-03

LiquidJS has an infinite loop vulnerability in its `strip_html` filter

CVE-2026-61556RCE2026-09-03

OpenClaw Feishu permission tools could ignore per-account disablement

RCE2026-09-03

OpenClaw Feishu tools could ignore per-account disablement

RCE2026-09-03

unstructured: Server-Side Request Forgery in the URL-based partitioning

CVE-2026-71428RCE2026-09-03

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

RCE2026-09-03

Amazon Ion C 资源管理错误漏洞

CVE-2026-84851DoS2026-09-03

Siemens SIMATIC 安全漏洞

CVE-2021-384892026-09-03

Proxmox VE身份认证绕过漏洞

2026-09-03

OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

CVE-2026-73667RCE2026-09-02

OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

CVE-2026-73841RCE2026-09-02

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

CVE-2026-73843RCE2026-09-02

Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection

CVE-2026-67445RCE2026-09-02

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

CVE-2026-72921RCE2026-09-02

Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling

CVE-2026-67446RCE2026-09-02

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

CVE-2026-84366RCE2026-09-02

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

CVE-2026-62676RCE2026-09-02

Plate: SSRF with response disclosure in DOCX image embedding

CVE-2026-65842RCE2026-09-02

Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass

CVE-2026-63490RCE2026-09-02

Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge

CVE-2026-62669RCE2026-09-02

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

CVE-2026-62677RCE2026-09-02

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

CVE-2026-62674RCE2026-09-02

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

CVE-2026-62675RCE2026-09-02

link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897

CVE-2026-61704RCE2026-09-02

fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references

CVE-2026-75931RCE2026-09-02

fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization

CVE-2026-75975RCE2026-09-02

fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding

CVE-2026-75899RCE2026-09-02

fast-uri vulnerable to host confusion via percent-encoded scheme normalization

CVE-2026-76172RCE2026-09-02

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

CVE-2026-62388RCE2026-09-02

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

CVE-2026-76098RCE2026-09-02

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

CVE-2026-71553RCE2026-09-02

Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

CVE-2026-62680RCE2026-09-02

Orval: Import-time RCE via query-parameter default -> zod module-level template literal

CVE-2026-72716RCE2026-09-02

Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client

CVE-2026-71866RCE2026-09-02

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

CVE-2026-72920RCE2026-09-02

Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

CVE-2026-64850RCE2026-09-02

EasyAdmin custom-action dispatcher bypasses access_control on other routes

CVE-2026-81892RCE2026-09-02

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

CVE-2026-82397RCE2026-09-02

elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

CVE-2026-81891RCE2026-09-02

pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph

CVE-2026-82392RCE2026-09-02

pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install

CVE-2026-82393RCE2026-09-02

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

CVE-2026-81726RCE2026-09-02

Faker: helpers.fake exploitable into arbritary code execution

CVE-2026-73231RCE2026-09-02

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

CVE-2026-59832RCE2026-09-02

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

CVE-2026-59834RCE2026-09-02

ShowDoc registerByVerify 未授权远程代码执行漏洞(QVD-2026-61708)

RCE2026-09-02

Jenkins PersistenceRoot 反序列化远程代码执行漏洞(CVE-2026-84645)

CVE-2026-84645RCE2026-09-02

AMD EPYC 安全漏洞

CVE-2023-20577RCE2026-09-02

Proxmox VE 未认证单请求 Root 认证绕过漏洞(QVD-2026-61075)

2026-09-02

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

CVE-2026-84304RCE2026-09-01

TYPO3 CMS - Broken Access Control in Backend and Install Tool

CVE-2026-19418RCE2026-09-01

Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled

CVE-2026-77567RCE2026-09-01

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

CVE-2026-79675RCE2026-09-01

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

RCE2026-09-01

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

CVE-2026-78680RCE2026-09-01

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

RCE2026-09-01

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

RCE2026-09-01

league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters

RCE2026-09-01

nanoid: Integer Overflow or Wraparound

CVE-2026-73086RCE2026-09-01

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

RCE2026-09-01

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

RCE2026-09-01

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

CVE-2024-37052RCE2026-09-01

Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM

CVE-2026-73089RCE2026-09-01

Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)

CVE-2026-73088RCE2026-09-01

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

RCE2026-09-01

SonicWall SMA1000 服务器端请求伪造漏洞(CVE-2026-83548)

CVE-2026-835482026-09-01

WebPros cPanel 代码注入漏洞

2026-09-01

Lutece Core 代码注入漏洞

2026-09-01

Composer 命令注入漏洞

2026-09-01

cPanel 远程代码执行漏洞

CVE-2026-65643RCE2026-09-01

YonBIP产品的cas未授权访问漏洞

2026-09-01