最新漏洞情报100
CVE & PoC Alerts in Real Time
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
toml-node: Uncontrolled Recursion
toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
Phoenix: Unbounded channel joins per transport enables DoS over few connections
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
TOON: Prototype pollution when decoding untrusted TOON input
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Orval: Import-time RCE via schema default -> zod module-level template literal
Orval: Import-time RCE via array-items default -> zod module-level template literal
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
ffuf denial of service (OOM) via HTTP response decompression bomb
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
OpenClaw Feishu permission tools could ignore per-account disablement
OpenClaw Feishu tools could ignore per-account disablement
unstructured: Server-Side Request Forgery in the URL-based partitioning
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
Amazon Ion C 资源管理错误漏洞
Siemens SIMATIC 安全漏洞
Proxmox VE身份认证绕过漏洞
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
Plate: SSRF with response disclosure in DOCX image embedding
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Orval: Import-time RCE via query-parameter default -> zod module-level template literal
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
EasyAdmin custom-action dispatcher bypasses access_control on other routes
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
Faker: helpers.fake exploitable into arbritary code execution
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
ShowDoc registerByVerify 未授权远程代码执行漏洞(QVD-2026-61708)
Jenkins PersistenceRoot 反序列化远程代码执行漏洞(CVE-2026-84645)
AMD EPYC 安全漏洞
Proxmox VE 未认证单请求 Root 认证绕过漏洞(QVD-2026-61075)
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
TYPO3 CMS - Broken Access Control in Backend and Install Tool
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
nanoid: Integer Overflow or Wraparound
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
SonicWall SMA1000 服务器端请求伪造漏洞(CVE-2026-83548)
WebPros cPanel 代码注入漏洞
Lutece Core 代码注入漏洞
Composer 命令注入漏洞
cPanel 远程代码执行漏洞
YonBIP产品的cas未授权访问漏洞