最新漏洞情报100

CVE & PoC Alerts in Real Time

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

CVE-2026-59205RCE2026-07-20

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

CVE-2026-59204RCE2026-07-20

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

CVE-2026-59200RCE2026-07-20

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

CVE-2026-59199RCE2026-07-20

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

CVE-2026-59197RCE2026-07-20

Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability

CVE-2026-50651RCE2026-07-20

Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability

CVE-2026-50525RCE2026-07-20

Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability

CVE-2026-50528RCE2026-07-20

Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability

CVE-2026-50648RCE2026-07-20

Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability

CVE-2026-50524RCE2026-07-20

Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability

CVE-2026-47304RCE2026-07-20

Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability

CVE-2026-47302RCE2026-07-20

Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability

CVE-2026-57108RCE2026-07-20

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

RCE2026-07-20

File Browser: Colliding username normalization gives two users the same home directory

CVE-2026-62685RCE2026-07-20

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

CVE-2026-59731RCE2026-07-20

node-tar: Decompression/parse DoS via unlimited input

CVE-2026-59873RCE2026-07-20

node-tar: Negative tar entry size causes infinite loop in archive replace

CVE-2026-59874RCE2026-07-20

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

CVE-2026-59725RCE2026-07-20

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

CVE-2026-13311RCE2026-07-20

Directus: Authorization-dependent response served from unsegmented cache key

CVE-2026-61836RCE2026-07-20

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

CVE-2026-61835RCE2026-07-20

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

CVE-2026-61740RCE2026-07-20

LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests

CVE-2026-61736RCE2026-07-20

Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)

CVE-2026-59922RCE2026-07-20

Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

CVE-2026-59925RCE2026-07-20

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

CVE-2026-59928RCE2026-07-20

js-yaml: YAML merge-key chains can force quadratic CPU consumption

CVE-2026-59869RCE2026-07-20

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

CVE-2026-55667RCE2026-07-20

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

CVE-2026-54560RCE2026-07-20

Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`

CVE-2026-55380RCE2026-07-20

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

CVE-2026-55379RCE2026-07-20

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

CVE-2026-54060RCE2026-07-20

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

CVE-2026-54059RCE2026-07-20

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

CVE-2026-54058RCE2026-07-20

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

CVE-2026-53515RCE2026-07-20

brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

CVE-2026-13149RCE2026-07-20

Composer: Arbitrary file write outside vendor via malicious transitive package name

CVE-2026-59948RCE2026-07-20

vLLM denial of service via prompt embeds on M-RoPE models

CVE-2026-55514RCE2026-07-20

Tornado: Quadratic DoS via Crafted Multipart Parameters

CVE-2025-67726RCE2026-07-20

Tornado: Quadratic DoS via Repeated Header Coalescing

CVE-2025-67725RCE2026-07-20

fastjson <= 1.2.83 任意代码执行漏洞

RCE2026-07-20

Fastjson 1.2.83 远程代码执行漏洞(QVD-2026-43021)

RCE2026-07-20

Fastjson 1.2.83 远程代码执行漏洞

RCE2026-07-20

XStore Theme / SQL 注入漏洞(CVE-2026-3326)

CVE-2026-3326SQL注入2026-07-20

Kubernetes Dashboard /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs 权限绕过漏洞(CVE-2018-18264)

CVE-2018-18264权限绕过2026-07-20

EnjoySCM 供应链管理系统 /BackCommunication/wcfCommunicate.svc SQL 注入漏洞

SQL注入2026-07-20

喰星云数字化餐饮服务系统 /chainsales/head/user/addUser 权限绕过漏洞

权限绕过2026-07-20

企业信息发送平台 /getLicenceDetail 文件读取漏洞

文件读取2026-07-20

北京中科聚网一体化运营平台 /manage/tplresource/importVisualModuleImg 文件上传漏洞

文件上传2026-07-20

Goploy /user/login 默认口令漏洞

默认口令2026-07-20

东胜物流软件 /PriceCarrier/OpSailingDateInfoGridSource.aspx SQL 注入漏洞

SQL注入2026-07-20

东胜物流软件 /PriceCarrier/CrmProxyMailListHtmlGridSource.aspx SQL 注入漏洞

SQL注入2026-07-20

Casdoor /conf/app.conf 信息泄露漏洞(CVE-2024-5587)

CVE-2024-5587信息泄露2026-07-20

天问物业ERP系统 /HM/M_Main/HC/DataGetControl.aspx SQL 注入漏洞

SQL注入2026-07-20

UniFi Access /api/ucore/backup/export 命令执行漏洞(CVE-2025-52665)

CVE-2025-52665命令执行2026-07-20

9router /api/tunnel/tailscale-install 命令执行漏洞

命令执行2026-07-20

智联云采 SRM2.0 /api/sys/app/autologin 权限绕过漏洞

权限绕过2026-07-20

JeecgBoot 积木报表 /jmreport/getDataSourceByPage 信息泄露漏洞

信息泄露2026-07-20

方向标邮件网关 /common/cgi/get_audit.cgi 命令执行漏洞

命令执行2026-07-20

Gorse /api/dump 未授权访问漏洞 (CVE-2026-56782)

CVE-2026-56782未授权访问2026-07-20

用友 U8cloud /service/XChangeServlet SQL 注入漏洞

SQL注入2026-07-20

XMall /item/list SQL 注入漏洞(CVE-2024-24112)

CVE-2024-24112两高一弱20262026-07-20

Versa Concerto /portalapi/v1/roles/option 权限绕过漏洞(CVE-2025-34027)

CVE-2025-34027两高一弱20262026-07-20

WordPress Pie Register / 权限绕过漏洞(CVE-2025-34077)

CVE-2025-34077两高一弱20262026-07-20

云连ERP管理系统 /gateway/download!download.action 代码执行漏洞

代码执行2026-07-20

FOSSBilling /system/string_render 命令执行漏洞(CVE-2026-28496)

CVE-2026-28496命令执行2026-07-20

用友GRP-U8Cloud /jmreport/loadTableData SQL 注入漏洞

SQL注入2026-07-20

泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞

文件读取2026-07-20

用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞

命令执行2026-07-20

用友U8 Cloud MeasureQueryFrameAction SQL 注入漏洞

SQL注入2026-07-20

FlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442)

CVE-2026-46442代码执行2026-07-20

蓝凌EIS智慧协同平台 /common/FI_SelEmp.aspx SQL 注入漏洞

SQL注入2026-07-20

WordPress Core Pre-Auth Batch-Route Confusion RCE (CVE-2026-63030)

CVE-2026-63030RCE2026-07-18

WordPress Core REST API author_exclude参数SQL注入漏洞(CVE-2026-60137)

CVE-2026-60137RCE2026-07-18

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

CVE-2026-55177RCE2026-07-17

Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)

CVE-2026-54567RCE2026-07-17

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

CVE-2026-53597RCE2026-07-17

Prompty: Arbitrary file read via file reference expansion

CVE-2026-53598RCE2026-07-17

meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token

CVE-2026-54547RCE2026-07-17

meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch

CVE-2026-54549RCE2026-07-17

sh _uid does not drop supplementary groups (incomplete privilege drop)

CVE-2026-54552RCE2026-07-17

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

CVE-2026-11400RCE2026-07-17

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

CVE-2026-55574RCE2026-07-17

vLLM has Remote DoS via Invalid Recovered Token Reinjection

CVE-2026-54234RCE2026-07-17

WordPress Core REST API 路由混淆漏洞 (wp2shell)

2026-07-17

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

RCE2026-07-16

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

RCE2026-07-16

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

RCE2026-07-16

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

CVE-2026-59950RCE2026-07-16

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

CVE-2026-55579RCE2026-07-16

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

CVE-2026-55578RCE2026-07-16

ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)

CVE-2026-54076RCE2026-07-16

ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

CVE-2026-54077RCE2026-07-16

Pheditor has an authenticated terminal command whitelist bypass

CVE-2026-54540RCE2026-07-16

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

CVE-2026-52869RCE2026-07-16

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

CVE-2026-52870RCE2026-07-16

Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE

CVE-2026-52833RCE2026-07-16

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

CVE-2026-53714RCE2026-07-16

Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure

CVE-2026-53713RCE2026-07-16