🚨 CVE-2026-36851
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
🎖@cveNotify
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
🎖@cveNotify
GitHub
GitHub - SyntaxSaiyan/CVE-2026-36851: Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0
Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0 - SyntaxSaiyan/CVE-2026-36851
🚨 CVE-2026-68000
The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet keywords like CREATE/TABLE/SET/PREPARE/EXECUTE are not included in the list, allowing for bypassing. Attackers can execute stacked SQL statements without logging in.
🎖@cveNotify
The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet keywords like CREATE/TABLE/SET/PREPARE/EXECUTE are not included in the list, allowing for bypassing. Attackers can execute stacked SQL statements without logging in.
🎖@cveNotify
GitHub
CVE/MCMS/MCMS6.2.0-SQLinjection.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75327
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
🎖@cveNotify
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
🎖@cveNotify
GitHub
CVE/DocSys/DocSys任意文件上传.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75334
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering.
🎖@cveNotify
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering.
🎖@cveNotify
GitHub
CVE/smart-web2/smart-web2 v1.3.1 SQL Injection.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-39275
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components.
🎖@cveNotify
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components.
🎖@cveNotify
GitHub
GitHub - Securify-AI/CVE-2026-39275: CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS
CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS - Securify-AI/CVE-2026-39275
🚨 CVE-2026-52473
An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.
🎖@cveNotify
An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.
🎖@cveNotify
GitHub
CVE/Wgcloud/RCE.md at main · Y4y17/CVE
Contribute to Y4y17/CVE development by creating an account on GitHub.
🚨 CVE-2026-75411
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.
🎖@cveNotify
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through string concatenation and reflection.
🎖@cveNotify
GitHub
[SECURITY] JeecgBoot V3.9.2 airag:flow:add后台RCE · Issue #9691 · jeecgboot/JeecgBoot
版本号:V3.9.2 分支:main 问题描述: JeecgBoot AI Flow 模块的 CodeNode 节点支持 Groovy 脚本执行,SecurityCheck 类使用黑名单机制拦截危险调用(Runtime.getRuntime()、Class.forName、ProcessBuilder、exec( 等)。但 Groovy 动态语言特性允许通过字符串拼接+反射完整绕过黑名单:使...
🚨 CVE-2026-75329
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
🎖@cveNotify
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
🎖@cveNotify
GitHub
CVE/super-diamond/NETTY-NOAUTH.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75331
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
🎖@cveNotify
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
🎖@cveNotify
GitHub
CVE/tamgou/xss.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75333
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
🎖@cveNotify
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
🎖@cveNotify
GitHub
CVE/yx-image-recognition/PATH_TRAVERSAL_REPORT.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75330
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
🎖@cveNotify
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
🎖@cveNotify
GitHub
CVE/super-diamond/SQLI-HTTP.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75332
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
🎖@cveNotify
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
🎖@cveNotify
GitHub
CVE/Zyplayer-Doc/Zyplayer-Doc.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-75336
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
🎖@cveNotify
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
🎖@cveNotify
GitHub
CVE/funiture/SQL Injection.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-26452
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers.
🎖@cveNotify
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers.
🎖@cveNotify
GitHub
GitHub - ipflavors/ccoap: A CoAP library in C
A CoAP library in C. Contribute to ipflavors/ccoap development by creating an account on GitHub.
🚨 CVE-2026-26453
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.
🎖@cveNotify
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.
🎖@cveNotify
GitHub
GitHub - ipflavors/ccoap: A CoAP library in C
A CoAP library in C. Contribute to ipflavors/ccoap development by creating an account on GitHub.
🚨 CVE-2026-26459
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.
🎖@cveNotify
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.
🎖@cveNotify
GitHub
GitHub - ipflavors/ccoap: A CoAP library in C
A CoAP library in C. Contribute to ipflavors/ccoap development by creating an account on GitHub.
🚨 CVE-2026-26897
An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component
🎖@cveNotify
An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component
🎖@cveNotify
🚨 CVE-2026-26899
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
🎖@cveNotify
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
🎖@cveNotify
GitHub
GitHub - iwallplace/CVE-2026-46368-OpenWrt-Exploit: Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection…
Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521) - iwallplace/CVE-2026-46368-OpenWrt-Exploit
🚨 CVE-2026-30046
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
🎖@cveNotify
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
🎖@cveNotify
GitHub
[Bug]: UDM crashes due to reachable assertion when DELETE request omits pduSessionId path parameter · Issue #4264 · open5gs/open5gs
Open5GS Release, Revision, or Tag v2.7.6 Steps to reproduce curl --http2-prior-knowledge -X DELETE -v http://127.0.to.12:7777/nudm-uecm/v1/imsi-001010000000001/registrations/smf-registrations/ Logs...
🚨 CVE-2026-30047
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
🎖@cveNotify
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
🎖@cveNotify
GitHub
[Bug]: smf Crashed due to Assertion `psi != OGS_NAS_PDU_SESSION_IDENTITY_UNASSIGNED' failed. · Issue #4201 · open5gs/open5gs
Open5GS Release, Revision, or Tag v2.7.6 Steps to reproduce curl -X POST --http2-prior-knowledge http://127.0.0.4:7777/nsmf-pdusession/v1/sm-contexts -H "Content-Type: application/json" -...
🚨 CVE-2026-30050
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
🎖@cveNotify
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
🎖@cveNotify
GitHub
[Bugs] AMF Event Exposure ModifyAMFEventSubscriptionProcedure Panics on Negative Path Index · Issue #776 · free5gc/free5gc
Bug Description A vulnerability exists in the ModifyAMFEventSubscriptionProcedure function within the AMF Event Exposure service (processor/event_exposure.go). When processing a PATCH request to mo...