Latest Vulnerabilities
- PoC2026-09-17CVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication Bypass
- PoC2026-09-17CVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User Impersonation
- PoC2026-09-17flowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API Exposure
- PoC2026-09-17langflow-api-exposure: Langflow - Unauthenticated API Exposure
- PoC2026-09-17arangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCE
- PoC2026-09-16CVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File Read
- PoC2026-09-16CVE-2023-54391: Proxmox VE - Default Credentials with TFA Bypass
- PoC2026-09-16CVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCE
- PoC2026-09-16CVE-2025-57231: Docmost 0.2.1-0.21.0 - Arbitrary File Read
- PoC2026-09-16CVE-2026-0561: Shield Security <= 21.0.8 - Unauthenticated Reflected XSS
- PoC2026-09-16CVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication Bypass
- PoC2026-09-16CVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL Injection
- PoC2026-09-16CVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code
- PoC2026-09-16CVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection
- PoC2026-09-16CVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function Invocation
- PoC2026-09-16CVE-2026-19632: TranslatePress <= 3.3.1 - Unauthenticated Account Takeover
- PoC2026-09-16CVE-2026-2113: tpadmin <= 1.3.12 - Remote Code Execution
- PoC2026-09-16CVE-2026-21875: ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL Injection
- PoC2026-09-16CVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy
- PoC2026-09-16CVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR
- PoC2026-09-16CVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass
- PoC2026-09-16CVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site Scripting
- PoC2026-09-16CVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()
- PoC2026-09-16CVE-2026-29962: HSC MailInspector - Local File Inclusion
- PoC2026-09-16CVE-2026-29963: HSC MailInspector - Unauthenticated Arbitrary File Read
- PoC2026-09-16CVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication Bypass
- PoC2026-09-16CVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code Execution
- PoC2026-09-16CVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication Bypass
- PoC2026-09-16CVE-2026-41456: Bludit CMS <= 3.20.0 - Cross-Site Scripting
- PoC2026-09-16CVE-2026-41679: Paperclip - Remote Code Execution
- PoC2026-09-16CVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal
- PoC2026-09-16CVE-2026-42221: Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure
- PoC2026-09-16CVE-2026-44343: WGDashboard < 4.3.2 - Unauthenticated File Read
- PoC2026-09-16CVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass
- PoC2026-09-16CVE-2026-53595: FreeScout < 1.8.224 - Invite Hash Authorization Bypass
- PoC2026-09-16CVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCE
- PoC2026-09-16CVE-2026-5562: Provectus kafka-ui <=0.7.2 - Remote Code Execution
- PoC2026-09-16CVE-2026-56292: AcyMailing < 10.11.1 - Unauthenticated SQL Injection
- PoC2026-09-16CVE-2026-57582: GeoNetwork - Reflected Cross-Site Scripting
- PoC2026-09-16CVE-2026-58123: Hermes WebUI < 0.51.788 - Remote Code Execution
- PoC2026-09-16CVE-2026-58191: Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting
- PoC2026-09-16CVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard Access
- PoC2026-09-16CVE-2026-59509: cve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection
- PoC2026-09-16CVE-2026-59726: ruflo MCP Bridge - Unauthenticated RCE via terminal_execute
- PoC2026-09-16CVE-2026-60105: Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass
- PoC2026-09-16CVE-2026-61736: LightRAG <= 1.5.3 - Credentialed CORS Wildcard
- PoC2026-09-16CVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass
- PoC2026-09-16CVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure
- PoC2026-09-16CVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct
- PoC2026-09-16CVE-2026-82222: GiveWP <= 4.16.7.1 - Remote Code Execution
- PoC2026-09-16CVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication Bypass
- PoC2026-09-16CVE-2026-85200: GEO my WP <=4.5.5.3 - Unauthenticated Local File Inclusion
- PoC2026-09-16CVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read
- PoC2026-09-16CVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header Spoofing
- PoC2026-09-16CVE-2026-86207: N-able N-central - Authentication Bypass
- PoC2026-09-16CVE-2026-86426: LibreNMS <= 26.7.0 - Unauthenticated API Access
- PoC2026-09-16CVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug Disclosure
- PoC2026-09-16CVE-2026-88062: OmniRoute < 3.8.49 - Unauthenticated RCE
- PoC2026-09-16CVE-2026-9586: Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection
- PoC2026-09-16apache-livy-logs: Apache Livy - Logs Exposed
- PoC2026-09-16nacos-v3-auth-scope-bypass: Nacos 3.x - Unauthenticated Admin Takeover
- 2026-09-14关于iuap-print表达式接口漏洞的安全通告
- 2026-09-14思考軟體科技|電子柵欄 - SQL Injection
- 2026-09-11昊亞科技|WeenyGenius - 存在4個漏洞
- 2026-09-11鎧鋒企業|智慧對講系統 - 存在3個漏洞
- 2026-09-10Apache Log4j2 远程代码执行漏洞(CVE-2021-44228)
- 2026-09-09立即科技|企業雲端資料庫 - Arbitrary File Read
- 2026-09-08关于U9 cloud存在接口XML注入漏洞的安全通告
- 2026-09-08关于U9 cloud存在接口SQL注入漏洞的安全通告
- 2026-09-08关于U9 cloud存在接口无授权访问漏洞的安全通告
- 2026-09-08关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告
- 2026-09-07关于U8+ EIS服务(企业空间插件)产品存在命令执行漏洞的公告
- 2026-09-07关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告
- 2026-09-07Jenkins 代码执行漏洞(CVE-2026-84645)
- 2026-09-07JeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞
- 2026-09-07江苏泰之特测控技术股份有限公司TZTIOT智能在线监测系统存在弱口令漏洞
- 2026-09-04畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞
- 2026-09-04旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞
- 2026-09-04英特內|DreamMaker - 存在2個漏洞
- 2026-09-03Proxmox VE身份认证绕过漏洞
- 2026-09-03上海小羚羊软件股份有限公司小羚羊ERP系统downloadView存在任意文件读取漏洞
- 2026-09-02北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞
- 2026-09-02关于NC系统的任意文件下载漏洞的安全通告
- 2026-09-02关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告
- 2026-09-01YonBIP产品的cas未授权访问漏洞
- PoC2026-09-01CVE-2017-8225: GoAhead Camera - Credential Disclosure
- PoC2026-09-01CVE-2022-39258: Mailcow Dockerized Swagger UI - Cross-Site Scripting
- PoC2026-09-01CVE-2026-0743: WP Content Permission <= 1.2 - Cross-Site Scripting
- PoC2026-09-01CVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler
- PoC2026-09-01CVE-2026-41042: Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution
- PoC2026-09-01CVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request Forgery
- PoC2026-09-01CVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path Traversal
- PoC2026-09-01CVE-2026-55229: Gotenberg < 8.34.0 - Local File Disclosure
- PoC2026-09-01CVE-2026-73034: DB-GPT <= 0.8.1 - Arbitrary File Write
- PoC2026-09-01CVE-2026-9133: Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read
- PoC2026-09-01johnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default Login
- PoC2026-09-01grafana-loki-api-exposure: Grafana Loki - Unauthenticated API Access
- PoC2026-09-01victoriametrics-vmagent-api-exposure: VictoriaMetrics vmagent - Unauthenticated Targets Exposure
- PoC2026-09-01maven-settings-xml-exposure: Apache Maven settings.xml Credentials - Exposure
- PoC2026-09-01nuget-config-exposure: NuGet.config Package Source Credentials - Exposure