最新漏洞情报100

CVE & PoC Alerts in Real Time

Note Mark has Stored XSS via Unrestricted Asset Upload

CVE-2026-40262RCE2026-04-13

Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username

CVE-2026-40193RCE2026-04-13

FITS GZIP decompression bomb in Pillow

CVE-2026-40192RCE2026-04-13

Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix

CVE-2026-35582RCE2026-04-13

External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine

CVE-2026-34984RCE2026-04-13

simple-git Affected by Command Execution via Option-Parsing Bypass

CVE-2026-28291RCE2026-04-13

Decidim has a cross-site scripting (XSS) in user name

CVE-2026-23891RCE2026-04-13

Keras远程代码执行漏洞

RCE2026-04-13

Adobe Acrobat Reader 远程代码执行漏洞(CVE-2026-34621)

CVE-2026-34621RCE2026-04-11

Daptin has Unauthenticated Path Traversal and Zip Slip

RCE2026-04-10

mathjs 允许对动态确定的对象属性进行不当控制的修改

RCE2026-04-10

Paperclip 通过导入授权绕过实现未经身份验证的远程代码执行 (RCE)

RCE2026-04-10
PoC

Juju: CloudSpec 方法导致云凭据泄露

CVE-2026-5412RCE2026-04-10

gramps-webapi: 媒体存档导入中的 Zip Slip 路径穿越漏洞

RCE2026-04-10
PoC

n8n-mcp HTTP 传输层存在未授权会话终止与信息泄露漏洞

RCE2026-04-10

Arcane 模板获取端点存在未经身份验证的 SSRF 漏洞(带条件响应反射)

CVE-2026-40242RCE2026-04-10
PoC

DotNetNuke.Core 通过上传 SVG 文件导致存储型跨站脚本 (XSS) 漏洞

RCE2026-04-10
PoC

basic-ftp: CRLF 注入保护不完整导致可通过凭据和 MKD 命令执行任意 FTP 命令

RCE2026-04-10
PoC

goshs has a file-based ACL authorization bypass in goshs state-changing routes

CVE-2026-40189RCE2026-04-10

goshs is Missing Write Protection for Parametric Data Values

CVE-2026-40188RCE2026-04-10

nimiq-blockchain is missing a wall-clock upper bound on block timestamps

CVE-2026-40093RCE2026-04-10

ajenti.plugin.core has password bypass when 2FA is activated

CVE-2026-40177RCE2026-04-10

Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

CVE-2026-40175RCE2026-04-10

Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export

RCE2026-04-10

PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

RCE2026-04-10

PraisonAI has critical RCE via `type: job` workflow YAML

RCE2026-04-10

PraisonAI Vulnerable to RCE via Automatic tools.py Import

RCE2026-04-10

SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

RCE2026-04-10

SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`

RCE2026-04-10

Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble

CVE-2026-40162RCE2026-04-10

Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read

CVE-2026-40163RCE2026-04-10

PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API

CVE-2026-40114RCE2026-04-10

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

CVE-2026-40160RCE2026-04-10

PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

RCE2026-04-10

PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`

CVE-2026-40157RCE2026-04-10

PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading

CVE-2026-40156RCE2026-04-10

PraisonAI Vulnerable Untrusted Remote Template Code Execution

CVE-2026-40154RCE2026-04-10

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution

RCE2026-04-10

PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure

CVE-2026-40158RCE2026-04-10

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

CVE-2026-40153RCE2026-04-10

PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls

CVE-2026-40149RCE2026-04-10

PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool

CVE-2026-40150RCE2026-04-10

PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits

CVE-2026-40116RCE2026-04-10

PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars

CVE-2026-40113RCE2026-04-10

PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)

CVE-2026-40111RCE2026-04-10

SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering

CVE-2026-40107RCE2026-04-10

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

CVE-2026-34177RCE2026-04-10

LXD: Importing a crafted backup leads to project restriction bypass

CVE-2026-34178RCE2026-04-10

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

CVE-2026-34179RCE2026-04-10

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

CVE-2026-40073RCE2026-04-10

@vitejs/plugin-rsc has a Denial of Service with React Server Components

RCE2026-04-10

Next.js has a Denial of Service with Server Components

CVE-2026-23869RCE2026-04-10

Vikunja vulnerable to Privilege Escalation via Project Reparenting

CVE-2026-35595RCE2026-04-10

Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

CVE-2026-35205RCE2026-04-10

Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

CVE-2026-35204RCE2026-04-10

Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

CVE-2026-34987RCE2026-04-10

Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path

CVE-2026-34727RCE2026-04-10

Apache ActiveMQ: 由于内存耗尽导致的拒绝服务漏洞

CVE-2026-39304RCE2026-04-10

parisneo/lollms 社交功能存在存储型 XSS 漏洞

CVE-2026-1115RCE2026-04-10
PoC

Spring Cloud Gateway SSL bundle 配置被静默绕过

CVE-2026-22750RCE2026-04-10
PoC

OpenClaw Gateway: 通过 device.pair.approve 实现从 operator.pairing 到 operator.admin 的权限提升与 RCE

CVE-2026-35639RCE2026-04-10

Axios SSRF漏洞

SSRF2026-04-10

Parisneo /lollms漏洞

2026-04-10

云帆在线考试培训系统存在弱口令

弱口令2026-04-10

Langflow autologin 致 access_token 泄漏

2026-04-10

泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞

SQL注入2026-04-10

PyLoad /login 默认口令漏洞

默认口令2026-04-10

Pentaho /pentaho/j_spring_security_check 默认口令漏洞

默认口令2026-04-10

FreePBX /admin/config.php 默认口令漏洞

默认口令2026-04-10

Owncast /api/admin/serverconfig 默认口令漏洞

默认口令2026-04-10

Siemens SIMATIC HMI MiniWeb /FormLogin 默认口令漏洞

默认口令2026-04-10

PowerJob /appInfo/assert 默认口令漏洞

默认口令2026-04-10

泛微E-Cology9 /services/WorkPlanService SQL 注入漏洞

SQL注入2026-04-10

用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞

文件读取2026-04-10

Meshery /api/system/fileDownload 文件读取漏洞

文件读取2026-04-10

Meshery /api/system/fileView 文件读取漏洞

文件读取2026-04-10

Vite Dev Server /node_modules/.vite/deps 文件读取漏洞 (CVE-2026-39365)

CVE-2026-39365文件读取2026-04-10

深科特 LEAN MES 系统 /Handler/AutoComplete.ashx SQL 注入漏洞

SQL注入2026-04-10

万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞

SQL注入2026-04-10

Stirling-PDF /api/v1/convert/markdown/pdf 服务器端请求伪造漏洞 (CVE-2025-55161)

CVE-2025-55161服务器端请求伪造2026-04-10

Alfresco Content Services /alfresco/service/api/login 默认口令漏洞

默认口令2026-04-10

Homebridge Config UI X /api/auth/login 默认口令漏洞

默认口令2026-04-10

月子会所ERP管理云平台 /Page/ContractManager/ashx/Handler.ashx 文件上传漏洞

文件上传2026-04-10

WordPress Elementor Page Builder 插件 / 文件读取漏洞

文件读取2026-04-10

elecV2P /store 文件读取漏洞

文件读取2026-04-10

elecV2P /rpc 代码执行漏洞

代码执行2026-04-10

Ech0 /api/allusers 信息泄露漏洞(CVE-2026-33638)

CVE-2026-33638信息泄露2026-04-10

Dolibarr /index.php 默认口令漏洞

默认口令2026-04-10

ILIAS LMS /ilias.php 默认口令漏洞

默认口令2026-04-10

用友U8 Cloud uapbd.refdef.query SQL 注入漏洞

SQL注入2026-04-10

Rundeck /j_security_check 默认口令漏洞

默认口令2026-04-10

Marimo-team Marimo 远程代码执行漏洞

RCE2026-04-10

Apache Tomcat: CLIENT_CERT 身份验证在预期情况下未失败

CVE-2026-29145RCE2026-04-09

bsv-sdk ARC 广播器将 INVALID/MALFORMED/ORPHAN 响应误认为广播成功

CVE-2026-40069RCE2026-04-09
PoC

bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)

CVE-2026-40070RCE2026-04-09

Wasmtime: aarch64 Cranelift 编译错误导致沙箱逃逸

CVE-2026-34971RCE2026-04-09

OpenClaw: `fetchWithSsrFGuard` 在跨域重定向时重放不安全的请求体

RCE2026-04-09

OpenClaw: 节点配对重连命令提权绕过 operator.admin 权限限制

RCE2026-04-09

MinIO S3 Select CSV 解析中的无限制内存分配导致拒绝服务 (DoS) 漏洞

CVE-2026-39414RCE2026-04-09
PoC

Axios NO_PROXY 主机名规范化绕过导致 SSRF

CVE-2025-62718RCE2026-04-09
PoC