<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
    <title>漏洞情报订阅 - BiuPoC</title>
    <link>https://rss.biu.life/</link>
    <description>BiuPoC 漏洞情报平台，聚合最新 CVE、PoC、EXP 与漏洞复现资料，支持按软件产品与攻击路径检索，助力安全研究与攻防自查。</description>
    <language>zh-CN</language>
    <atom:link href="https://rss.biu.life/feed/" rel="self" type="application/rss+xml"/>
    <follow_challenge>
    <feedId>157646199064826880</feedId>
    <userId>76992525282223104</userId>
</follow_challenge>

    <item>
        <title>CVE-2020-29134: TOTVS Fluig &lt;= 1.7.0 - Arbitrary File Read</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29134.yaml</link>
        <description>TOTVS Fluig platform contains a path traversal caused by base64-encoded manipulation of the &#x27;file&#x27; parameter, letting attackers access arbitrary files, exploit requires attacker to control the &#x27;file&#x27; parameter.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2023-54391: Proxmox VE - Default Credentials with TFA Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-54391.yaml</link>
        <description>Detected Proxmox VE was accessible using default root@pam credentials combined with a TFA challenge bypass. An attacker could authenticate as root by submitting the default password &quot;root@pam&quot; along with a crafted tfa-challenge parameter, thereby bypassing two-factor authentication enforcement and gaining full administrative access to the hypervisor management interface.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2025-51683: mJobTime &lt;= 15.7.2 - Unauthenticated Blind SQL Injection to RCE</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-51683.yaml</link>
        <description>mJobtime v15.7.2 contains a sql injection caused by crafted POST request to /Default.aspx/update_profile_Server, letting unauthenticated attackers execute arbitrary SQL statements remotely, exploit requires no special privileges.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2025-57231: Docmost 0.2.1-0.21.0 - Arbitrary File Read</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-57231.yaml</link>
        <description>Docmost v0.21.0 contains a path traversal caused by improper handling of avatar attachments, letting unauthenticated attackers disclose local files via a POST request on a public URL.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-0561: Shield Security &lt;= 21.0.8 - Unauthenticated Reflected XSS</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0561.yaml</link>
        <description>Shield Security WordPress plugin &lt;= 21.0.8 contains a reflected cross-site scripting caused by insufficient input sanitization and output escaping in the &#x27;message&#x27; parameter, letting unauthenticated attackers inject scripts, exploit requires user interaction.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-0650: OpenFlagr &lt;= 1.1.18 - Authentication Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0650.yaml</link>
        <description>OpenFlagr &lt;= 1.1.18 contains an authentication bypass caused by improper path normalization handling in HTTP middleware whitelist logic, letting attackers access protected API endpoints without valid credentials, exploit requires crafted requests.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-0702: VidShop for WooCommerce &lt;= 1.1.4 - SQL Injection</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0702.yaml</link>
        <description>VidShop – Shoppable Videos for WooCommerce plugin for WordPress &lt;= 1.1.4 contains a time-based SQL injection caused by insufficient escaping of the &#x27;fields&#x27; parameter, letting unauthenticated attackers extract sensitive database information.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-0768: Langflow &lt;=1.2.x - Unauthenticated Remote Code Execution via validate_code</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0768.yaml</link>
        <description>Langflow &lt;= 1.2.x exposes POST /api/v1/validate/code without any authentication. The endpoint calls validate_code() which exec()s user-supplied Python code. Default-argument expressions in Python execute at function-definition time, allowing arbitrary OS command execution without authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-1281: Ivanti EPMM &lt;=12.7.0.0 - Unauthenticated Code Injection</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-1281.yaml</link>
        <description>Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 through 12.7.0.0 contain a code injection vulnerability that allows unauthenticated remote attackers to achieve arbitrary code execution on the target system.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-19092: Tutor LMS &lt; 4.0.6 - Unauthenticated Arbitrary PHP Function Invocation</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-19092.yaml</link>
        <description>Tutor LMS WordPress plugin &lt; 4.0.6 contains a template injection caused by insufficient prevention of request data overwriting internal variables during template rendering, letting unauthenticated attackers invoke arbitrary zero-argument PHP functions and receive their output.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-19632: TranslatePress &lt;= 3.3.1 - Unauthenticated Account Takeover</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-19632.yaml</link>
        <description>TranslatePress WordPress plugin &lt;= 3.3.1 contains a sensitive information exposure caused by the &#x27;trp_get_translations_regular&#x27; AJAX action saving password-reset URLs in translation dictionary, letting unauthenticated attackers extract admin password-reset URLs, exploit requires automatic string saving enabled and admin profile locale set to a published secondary language.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-2113: tpadmin &lt;= 1.3.12 - Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-2113.yaml</link>
        <description>yuan1994 tpadmin up to version 1.3.12 is vulnerable to Remote Code Execution via unrestricted file upload in the WebUploader preview component (/public/static/admin/lib/webuploader/0.1.5/server/preview.php). An unauthenticated remote attacker can submit base64-encoded PHP payloads leading to arbitrary code execution with web server privileges.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-21875: ClipBucket v5 &lt;= 5.5.2 - Unauthenticated Blind SQL Injection</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-21875.yaml</link>
        <description>ClipBucket v5.5.2-#187 and below contain a blind SQL injection caused by unsanitized obj_id parameter in /actions/ajax.php used in user_exists function, letting attackers perform blind SQL injection remotely, exploit requires crafted POST request.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-23693: ElementsKit Lite &lt;3.7.9 - Unauthenticated Mailchimp Proxy</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-23693.yaml</link>
        <description>The ElementsKit Elementor Addons Lite (elementskit-lite) plugin for WordPress before 3.7.9 registers the REST route /wp-json/elementskit/v1/widget/mailchimp/subscribe with no authentication or capability check (CWE-306). The handler accepts client-supplied Mailchimp API credentials and a `list` parameter and issues upstream Mailchimp API requests, letting an unauthenticated attacker use the site as an open proxy to Mailchimp.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-26265.yaml</link>
        <description>Discourse prior to 2025.12.2, 2026.1.1, and 2026.2.0 contains an IDOR vulnerability caused by lack of authorization checks on user_field_ids parameter in DirectoryItemsController#index, letting any user retrieve private user field values, exploit requires no authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-27454: Discourse &lt;=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27454.yaml</link>
        <description>Discourse versions before 2026.1.2, 2026.2.1, and 2026.3.0-latest.1 contain an authorization bypass in PostsController#display_post. The controller calls post.revert_to(params[:version]) directly whenever a version query parameter is present, without checking whether the corresponding PostRevision is hidden or whether the caller has permission to view edit history. By requesting a post at its publicly known version number via GET /posts/:id.json?version=&lt;public_version&gt;, the next PostRevision&#x27;s stored modifications are applied unconditionally. If staff have hidden that revision, its pre-edit content is returned to an unauthenticated caller. On patched installs the same request is rejected with 403 because guardian.ensure_can_see!(post_revision) is evaluated first.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-28141: NextGEN Gallery &lt;= 4.2.3 - Reflected Cross-Site Scripting</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-28141.yaml</link>
        <description>NextGEN Gallery through 4.2.3 reflects a URL-decoded `ngg_tag` route value into the generated tag page without the context-specific escaping added in 4.2.4. An unauthenticated attacker can break out of the tag context and inject an auto-executing script. This template injects an `svg onload` payload carrying a random nonce and matches its unencoded reflection; slash and backtick syntax keep the request off common WAF signatures.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-28411: WeGIA &lt; 3.6.5 - Unauthenticated Authentication Bypass via extract()</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-28411.yaml</link>
        <description>WeGIA &lt; 3.6.5 contains an authentication bypass caused by unsafe use of extract() on $_REQUEST, letting unauthenticated attackers bypass authentication and access protected areas, exploit requires no authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-29962: HSC MailInspector - Local File Inclusion</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29962.yaml</link>
        <description>HSC MailInspector v5.3.3-7 contains a path traversal caused by improper control of user-supplied file paths in /vendor/phpunit/phpunit.php, letting remote attackers read arbitrary files, exploit requires crafted request.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-29963: HSC MailInspector - Unauthenticated Arbitrary File Read</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29963.yaml</link>
        <description>HSC MailInspector 5.3.3-7 contains a path traversal caused by improper validation of user-supplied input in /tap/dw.php text parameter, letting remote attackers access arbitrary files, exploit requires crafted request.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-30849: MantisBT &lt; 2.28.1 - SOAP API Authentication Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-30849.yaml</link>
        <description>Mantis Bug Tracker &lt; 2.28.1 on MySQL databases contains an authentication bypass caused by improper type checking on the password parameter in the SOAP API, letting attackers login without the actual password using a crafted SOAP envelope, exploit requires knowing the victim&#x27;s username.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-34234: CtrlPanel &lt;= 1.1.1 - Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-34234.yaml</link>
        <description>CtrlPanel versions &lt;= 1.1.1 are vulnerable to unauthenticated Remote Code Execution (RCE) via the web installer endpoint (public/installer/index.php). The installer loaded and executed form handler files before checking for the install.lock gate, allowing attackers to reach installer forms on fully-deployed instances. User-supplied POST values (url, key, clientkey) from the Pterodactyl configuration form were interpolated directly into shell command strings executed via bash -c without sanitization, enabling command injection. The vulnerability is confirmed actively exploited in the wild.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-41452: Krayin CRM &lt; 2.2.1 - Installer Authentication Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41452.yaml</link>
        <description>Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-41456: Bludit CMS &lt;= 3.20.0 - Cross-Site Scripting</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41456.yaml</link>
        <description>Bludit CMS contains a reflected XSS caused by improper sanitization in the search plugin, letting unauthenticated attackers inject arbitrary JavaScript, exploit requires crafted malicious search query.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-41679: Paperclip - Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41679.yaml</link>
        <description>Paperclip &lt; 2026.416.0 contains a remote code execution caused by a chain of six unauthenticated API calls in authenticated mode with default configuration, letting unauthenticated attackers execute arbitrary code remotely, exploit requires network access to the target.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-41948: Dify &lt;=1.14.1 - Unauthenticated Plugin Daemon Path Traversal</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41948.yaml</link>
        <description>Dify version 1.14.1 and prior are affected by an unauthenticated path traversal in the Plugin Daemon icon proxy endpoint. The /console/api/workspaces/current/plugin/icon endpoint requires no authentication and passes the filename query parameter unsanitized into the internal Plugin Daemon REST API URL. Using ../ dot-sequence traversal an attacker escapes the authorized plugin/{tenant_id}/asset/ namespace and reaches arbitrary internal Plugin Daemon endpoints. The /health/check endpoint is always available and returns Plugin Daemon version, build time and pool status confirming exploitation.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-42221: Nginx UI &lt;= 2.3.7 - Unauthenticated Installer Exposure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42221.yaml</link>
        <description>Nginx UI 2.0.0 to 2.3.8 contains an authentication bypass caused by unauthenticated access to /api/install during first-run setup, letting remote attackers claim the initial admin account, exploit requires attacker to access the service before legitimate operator.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-44343: WGDashboard &lt; 4.3.2 - Unauthenticated File Read</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-44343.yaml</link>
        <description>WGDashboard &lt; 4.3.2 contains a path traversal vulnerability caused by improper access control, letting unauthorized attackers access the host file system without authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-48558: SimpleHelp &lt;=5.5.15 - OIDC JWT Authentication Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-48558.yaml</link>
        <description>SimpleHelp &lt;= 5.5.15 and 6.0 pre-release contain an authentication bypass caused by lack of cryptographic signature verification in OIDC tokens, letting remote unauthenticated attackers gain technician sessions, exploit requires OIDC authentication configured.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-53595: FreeScout &lt; 1.8.224 - Invite Hash Authorization Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-53595.yaml</link>
        <description>FreeScout prior to 1.8.224 contains an authentication bypass caused by improper invite_hash handling and decryption failure in user setup endpoint, letting anonymous attackers reset credentials and log in as the lowest-id activated user, exploit requires no authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-5524: Divi Form Builder &lt;=5.1.8 - Unauthenticated Arbitrary File Upload RCE</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-5524.yaml</link>
        <description>The Divi Form Builder plugin for WordPress versions 5.1.8 and prior contains an unauthenticated arbitrary file upload vulnerability in the do_image_upload() AJAX handler. The user-controlled acceptFileTypes POST parameter is injected unsanitized into a PHP regex for file extension validation. By supplying acceptFileTypes=phtml the constructed regex accepts .phtml files while the plugin&#x27;s .htaccess only blocks .php, so Apache executes .phtml files as PHP. The required nonce (fb_nonce) is publicly embedded in any page containing a Divi form via the de_fb_obj JavaScript object. Uploaded shells land in /wp-content/uploads/de_fb_uploads/. Fixed in 5.1.9.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-5562: Provectus kafka-ui &lt;=0.7.2 - Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-5562.yaml</link>
        <description>Provectus kafka-ui versions 0.7.0 through 0.7.2 are vulnerable to code injection in the `/api/smartfilters/testexecutions` endpoint. The `filterCode` parameter is evaluated as a Groovy expression without sandboxing, allowing an unauthenticated attacker to execute arbitrary code and operating-system commands on the host.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-56292: AcyMailing &lt; 10.11.1 - Unauthenticated SQL Injection</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-56292.yaml</link>
        <description>AcyMailing component for Joomla &lt;10.11.1 contains a sql injection caused by improper input sanitization, letting attackers access unauthorized database data, exploit requires crafted input.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-57582: GeoNetwork - Reflected Cross-Site Scripting</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-57582.yaml</link>
        <description>GeoNetwork versions 4.4.5 through 4.4.11 are vulnerable to reflected cross-site scripting (XSS) in the public unauthenticated catalog search functionality. The uiconfig query parameter of the catalog.search endpoint is reflected into a JavaScript context without sufficient sanitization, allowing arbitrary JavaScript execution in a victim&#x27;s browser.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-58123: Hermes WebUI &lt; 0.51.788 - Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-58123.yaml</link>
        <description>Hermes WebUI &lt; 0.51.788 contains an unauthenticated remote code execution caused by improper access control in embedded terminal API endpoints, letting remote attackers execute arbitrary shell commands without credentials.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-58191: Appium base-driver &lt;=10.6.0 - Reflected Cross-Site Scripting</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-58191.yaml</link>
        <description>Appium &lt;= 10.7.0 contains a reflected XSS caused by unescaped reflection of throwError query parameter, comments POST field, and User-Agent header in base-driver routes, letting remote attackers execute arbitrary JavaScript, exploit requires crafted HTTP requests.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-59177: ESPHome Device Builder &lt;1.0.10 - Unauthenticated Dashboard Access</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-59177.yaml</link>
        <description>ESPHome Device Builder versions before 1.0.10 bind the trusted Home Assistant ingress site to all interfaces. A client that can reach the ingress port can therefore access the dashboard without the Supervisor&#x27;s authentication proxy.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-59509: cve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-59509.yaml</link>
        <description>cve-search versions 4.0 through 6.0.0 expose an unauthenticated DataTables endpoint that accepts attacker-controlled MongoDB collection, projection, filtering, and pagination parameters. This detector uses a harmless invalid projection field against the intended cves collection; version 6.0.1 rejects that field.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-59726: ruflo MCP Bridge - Unauthenticated RCE via terminal_execute</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-59726.yaml</link>
        <description>ruflo MCP bridge (&lt; 3.16.3) in its default docker-compose deployment exposes POST /mcp with no authentication and binds to all interfaces (0.0.0.0:3001). The executeTool() function has no server-side deny list for dangerous tools, allowing an unauthenticated attacker to invoke tools/call with ruflo__terminal_execute, which runs execSync(command) on attacker-supplied input. This yields arbitrary command execution as the node user (uid 1000) inside the bridge container. The blocklist (AUTOPILOT_BLOCKED_PATTERNS + isBlockedTool()) is enforced only in the autopilot SSE handler; POST /mcp and POST /mcp/:group bypass it entirely.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-60105: Monsta FTP &lt;= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-60105.yaml</link>
        <description>Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-61736: LightRAG &lt;= 1.5.3 - Credentialed CORS Wildcard</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-61736.yaml</link>
        <description>LightRAG &lt;= 1.5.4 contains a broken access control vulnerability caused by default CORS_ORIGINS=* with allow_credentials=True in lightrag_server.py, letting malicious websites perform authenticated API requests, exploit requires authenticated user.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-62382.yaml</link>
        <description>PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-81199: MasterStudy LMS &lt; 3.7.46 - Unauthenticated Student Statistics Disclosure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-81199.yaml</link>
        <description>MasterStudy LMS WordPress plugin before 3.7.46 contains an information disclosure vulnerability caused by missing authorization checks in student learning statistics, letting unauthenticated attackers access sensitive user course data, exploit requires no authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-81578: PaperCut NG/MF &lt;=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-81578.yaml</link>
        <description>PaperCut NG and PaperCut MF versions 24.x through 26.x contain an authentication bypass vulnerability in the Apache Tapestry-based web interface. By crafting a complex-direct service request that specifies the public Home page as the render target while invoking the privileged ConfigEditor page&#x27;s form listeners, an unauthenticated remote attacker can search and modify server configuration options. PaperCut&#x27;s access control validates the render page but fails to validate the component page, allowing full configuration access without authentication. When chained with CVE-2026-82078, an attacker reconfigures external user lookup to use a malicious JDBC URL whose initialization SQL evaluates arbitrary Groovy code, achieving unauthenticated remote code execution. This vulnerability is actively exploited in the wild.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-82222: GiveWP &lt;= 4.16.7.1 - Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-82222.yaml</link>
        <description>GiveWP &lt;= 4.16.7.1 contains an insecure deserialization vulnerability caused by deserialization of untrusted data, letting attackers perform object injection remotely, exploit requires crafted input
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-82329.yaml</link>
        <description>JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-85200: GEO my WP &lt;=4.5.5.3 - Unauthenticated Local File Inclusion</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-85200.yaml</link>
        <description>GEO my WP WordPress plugin &lt;= 4.5.5.3 contains a local file inclusion caused by improper handling in gmw_posts_locator_ajax_info_window_loader function, letting unauthenticated attackers execute arbitrary PHP code remotely.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-85706: GitLab CE/EE &lt;=19.1.7/19.2.5/19.3.1 - Arbitrary File Read</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-85706.yaml</link>
        <description>GitLab CE/EE contains an unauthenticated arbitrary file read. Workhorse, the reverse proxy in front of Rails, matches upload routes using EscapedPath() and path.Clean without decoding percent sequences, while Puma decodes them before routing to Grape. Appending a trailing slash to commits or percent-encoding a static path segment as %63ommits therefore bypasses Workhorse upload route rewriting, and Rails reaches file_params_from_body_upload() which opens the path given in the file.path parameter before authenticate! is enforced. On the application/x-www-form-urlencoded branch the file bytes are handed to Rack::Utils.parse_nested_query, and any invalid percent sequence raises an ArgumentError whose message is interpolated into the HTTP 400 response body, disclosing file content to an unauthenticated caller.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-86206: N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header Spoofing</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-86206.yaml</link>
        <description>A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-86207: N-able N-central - Authentication Bypass</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-86207.yaml</link>
        <description>An authentication bypass in N-central &lt; 2026.3 HF 3 leads to authentication bypass in internal-only APIs.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-86426: LibreNMS &lt;= 26.7.0 - Unauthenticated API Access</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-86426.yaml</link>
        <description>LibreNMS &lt;= 26.8.0 contains an authentication bypass caused by MySQL type coercion in the REST API token validation, letting unauthenticated attackers access protected endpoints and execute remote code via alert templates.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug Disclosure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-87820.yaml</link>
        <description>CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-88062: OmniRoute &lt; 3.8.49 - Unauthenticated RCE</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-88062.yaml</link>
        <description>OmniRoute &lt;= 3.8.49 contains a remote code execution caused by insufficient validation of interpreter arguments in the POST /api/acp/agents endpoint, letting remote attackers execute arbitrary code, exploit requires anonymous access when requireLogin is false or management session/API key when true.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-9586: Sangoma Switchvox &lt; 8.4.0.2 - Unauthenticated SQL Injection</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-9586.yaml</link>
        <description>Sangoma Switchvox before version 8.4.0.2 contains an unauthenticated SQL injection vulnerability in the /pa endpoint (PhoneAppsHandler.pm). The PhoneIP field extracted from an XML POST body is concatenated directly into an unparameterized PostgreSQL query that runs as a database superuser. An attacker can break out of the single-quoted SQL string context and leverage PostgreSQL COPY TO PROGRAM to execute arbitrary operating system commands without authentication.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>apache-livy-logs: Apache Livy - Logs Exposed</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposures/logs/apache-livy-logs.yaml</link>
        <description>Detects if the logs/metrics page of the Apache Livy server is exposed.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>nacos-v3-auth-scope-bypass: Nacos 3.x - Unauthenticated Admin Takeover</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/nacos/nacos-v3-auth-scope-bypass.yaml</link>
        <description>Nacos 3.0.0 through 3.2.3 contains an authentication scope misassignment vulnerability. The user, role, and permission management API endpoints (UserControllerV3, RoleControllerV3, PermissionControllerV3) have @Secured annotations missing the apiType attribute, defaulting to OPEN_API scope which is guarded by nacos.core.auth.enabled disabled by default.
</description>
        <pubDate>Wed, 16 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title></title>
        <link>https://www.ddpoc.com/DVB-2026-11755.html</link>
        <description></description>
        <pubDate>Thu, 10 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于U9 cloud存在接口XML注入漏洞的安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 821</link>
        <description>U9团队在获知XML注入漏洞后第一时间组织团队进行应急响应，分析接口带来的漏洞问题，并针对该漏洞规避可能引起的其他漏洞如代码执行、信息泄露和数据库提权等；现已修复以上漏洞。</description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于U9 cloud存在接口SQL注入漏洞的安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 823</link>
        <description>U9团队在获知接口SQL注入漏洞后第一时间组织团队进行应急响应，分析接口带来的漏洞问题，并针对该漏洞规避可能引起的其他漏洞如代码执行、信息泄露和数据库提权等；现已修复以上漏洞。</description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于U9 cloud存在接口无授权访问漏洞的安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 822</link>
        <description>U9团队在获知接口无授权访问漏洞后第一时间组织团队进行应急响应，分析接口带来的漏洞问题，并针对该漏洞规避可能引起的其他漏洞如代码执行、信息泄露和数据库提权等；现已修复以上漏洞。</description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 824</link>
        <description>应用在处理文件下载请求时，未对用户传入的文件路径参数进行充分校验或过滤，导致攻击者可以通过构造参数下载服务器上本不应被访问的任意文件。</description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于U8+ EIS服务（企业空间插件）产品存在命令执行漏洞的公告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 818</link>
        <description>U8+ EIS服务（企业空间插件）存在一组已过时的残留文件。当黑客通过其他途径获取到数据库密码后，可利用此残留文件的漏洞实现远程命令执行注入攻击。攻击者可通过此获取服务器信息甚至获得服务器控制权。&lt;br&gt;</description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 820</link>
        <description>&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;NC Cloud及YonBIP高级版存在datacollectservlet接口漏洞，影响系统的安全。&lt;/span&gt;</description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>Jenkins 代码执行漏洞（CVE-2026-84645）</title>
        <link>https://gobysec.net/updates# Jenkins Code Execution Vulnerability (CVE-2026-84645)</link>
        <description>Jenkins 是开源持续集成与持续交付（CI/CD）服务器，提供自动化构建、测试和部署能力，是企业级软件开发流水线的核心平台。Jenkins 存在反序列化漏洞，攻击者可借此在服务器端任意执行代码，写入后门，获取服务器权限，进而控制整个web服务器。</description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>JeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞</title>
        <link>https://gobysec.net/updates# JeecgBoot JimuReport /jmreport/auto/export/python/plugin Code Execution Vulnerability</link>
        <description>JeecgBoot 是北京国炬信息技术有限公司推出的企业级低代码开发平台，提供在线表单、工作流、报表、权限管理、代码生成等能力，适用于政企信息化系统、业务管理平台和快速应用开发场景。其积木报表（JimuReport）组件 /jmreport/auto/export/python/plugin 接口存在未授权代码执行漏洞。攻击者无需登录即可利用该接口执行任意代码及系统命令，进而完全控制服务器。</description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>江苏泰之特测控技术股份有限公司TZTIOT智能在线监测系统存在弱口令漏洞</title>
        <link>https://www.ddpoc.com/DVB-2026-11746.html</link>
        <description>系统存在默认口令，攻击者可获取管理员权限。</description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 797</link>
        <description>攻击者通过POSSyncService.asmx接口构造相关payload，进一步利用，可能会导致SQL注入。</description>
        <pubDate>Fri, 04 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>旭辰資訊｜SmartIT Desktop Manager - 存在4個漏洞</title>
        <link>https://www.twcert.org.tw/tw/cp-132-11176-a4cc2-1.html</link>
        <description>【CVE-2026-85146(Use of Hard-coded Credentials)】未經身分鑑別之遠端攻擊者可於程式碼中取得SmartIT Agent程式之SSH服務帳號與通行碼。【CVE-2026-85147(Use of Hard-coded Credentials)】未經身分鑑別之遠端攻擊者可於程式碼中取得特定密碼，該通行碼可用於取得通訊用之AES加密金鑰。【CVE-2026-85148(Use of Hard-coded Credentials)】未經身分鑑別之遠端攻擊者可利用固定通行碼遠端存取使用者主機。【CVE-2026-85149(Use of Hard-coded Credentials)】未經身分鑑別之遠端攻擊者可於程式碼中取得SmartIT Agent程式之SFTP服務帳號與通行碼，進而瀏覽使用者主機檔案系統。</description>
        <pubDate>Fri, 04 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>英特內｜DreamMaker - 存在2個漏洞</title>
        <link>https://www.twcert.org.tw/tw/cp-132-11183-06a5e-1.html</link>
        <description>【CVE-2026-85540(SQL Injection)】已通過身分鑑別之遠端攻擊者可注入任意SQL指令讀取、修改及刪除資料庫內容。【CVE-2026-85541(Reflected Cross-site Scripting)】已通過身分鑑別之遠端攻擊者可利用惡意網站於使用者端瀏覽器執行任意JavaScript程式碼。</description>
        <pubDate>Fri, 04 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>Proxmox VE身份认证绕过漏洞</title>
        <link>https://stack.chaitin.com/vuldb/detail/7a5ace07-85aa-4720-967b-8db1e476c281</link>
        <description>Proxmox VE 的 libpve-access-control 组件存在身份认证绕过漏洞。攻击者向 API 登录接口提交特制的 tfa-challenge 参数，可绕过密码验证，直接以未启用双因素认证（2FA）的现有用户身份登录，默认影响高权限的 root@pam 账户。</description>
        <pubDate>Thu, 03 Sep 2026 16:28:52 </pubDate>
    </item>

    <item>
        <title>上海小羚羊软件股份有限公司小羚羊ERP系统downloadView存在任意文件读取漏洞</title>
        <link>https://www.ddpoc.com/DVB-2026-11727.html</link>
        <description>上海小羚羊软件股份有限公司小羚羊ERP系统其downloadView接口存在字符串拼接，并且没有鉴权，导致任意文件读取，攻击者可以利用该漏洞获取服务器敏感信息，从而进一步利用。</description>
        <pubDate>Thu, 03 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞</title>
        <link>https://www.ddpoc.com/DVB-2026-11723.html</link>
        <description>北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞，攻击者可通过该漏洞进行敏感数据获取。</description>
        <pubDate>Wed, 02 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于NC系统的任意文件下载漏洞的安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 817</link>
        <description>NC65系统存在任意文件下载漏洞，可窃取服务器敏感信息。</description>
        <pubDate>Wed, 02 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 816</link>
        <description>  用友GRP-U8Cloud产品下x/x/getUsersList及x/x/getNoteCode接口敏感信息泄露漏洞，攻击者通过匿名请求，然后构造参数，可获取项目的某些用户信息，存在安全风险。通过改造停用相关功能，校验token是否有效且在有效期，杜绝无token请求，解决以上的命令执行漏洞，降低相关的安全风险。</description>
        <pubDate>Wed, 02 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>YonBIP产品的cas未授权访问漏洞</title>
        <link>https://stack.chaitin.com/vuldb/detail/2d39959b-1e50-4193-8f58-6867b2e0a9f9</link>
        <description>用友YonBIP旗舰版友户通CAS接口存在用户认证逻辑绕过漏洞。攻击者可利用该漏洞绕过认证机制，直接登录任意账户，导致系统权限失控，存在数据泄露、篡改及业务中断等严重风险。</description>
        <pubDate>Tue, 01 Sep 2026 15:47:54 </pubDate>
    </item>

    <item>
        <title>CVE-2017-8225: GoAhead Camera - Credential Disclosure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2017/CVE-2017-8225.yaml</link>
        <description>GoAhead camera credential disclosure vulnerability in system.ini. The vulnerability affects certain Wireless IP Camera (P2P) WIFICAM devices and allows unauthenticated remote attackers to access the system.ini configuration file through a crafted HTTP request. The exposed configuration may contain sensitive authentication credentials, including usernames and passwords.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2022-39258: Mailcow Dockerized Swagger UI - Cross-Site Scripting</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-39258.yaml</link>
        <description>Mailcow-dockerized before 2022-09a uses a vulnerable version of Swagger UI (before 4.11.1) that is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. When a user accesses the Swagger documentation with a crafted configUrl or url parameter containing JavaScript payloads, arbitrary code execution can occur in the user&#x27;s browser. This allows attackers to steal cookies, session data, or execute actions on behalf of the victim by enticing them to open a malicious Swagger UI link.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-0743: WP Content Permission &lt;= 1.2 - Cross-Site Scripting</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0743.yaml</link>
        <description>The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &#x27;ohmem-message&#x27; parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-32475: Elementor Pro &lt;=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-32475.yaml</link>
        <description>Elementor Pro plugin for WordPress in versions &lt;=4.2.1 is vulnerable to unauthenticated arbitrary file upload in the Forms module File Upload field. The validation() and process_field() methods iterate over submitted file entries with different early-exit logic for UPLOAD_ERR_NO_FILE entries. When an attacker submits two file parts for the same upload field — an empty first entry (blank filename triggering UPLOAD_ERR_NO_FILE) followed by a payload — validation() returns early after the empty entry without ever type-checking the payload, while process_field() only skips (continue) the empty entry and moves the payload to wp-content/uploads/elementor/forms/. The AJAX action elementor_pro_forms_send_form requires no authentication or nonce.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-41042: Apache Gravitino &lt; 1.2.1 - Unauthenticated Remote Code Execution</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41042.yaml</link>
        <description>Apache Gravitino &lt; 1.2.1 contains a remote code execution caused by unsanitized H2 JDBC URL via testConnection API using H2&#x27;s INIT parameter, letting unauthenticated attackers execute arbitrary Java code remotely, exploit requires H2 usage.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-42596: Gotenberg &lt; 8.31.0 - Server-Side Request Forgery</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42596.yaml</link>
        <description>Gotenberg before 8.31.0 is vulnerable to server-side request forgery (SSRF) due to insufficient validation of URLs in the downloadFrom API. An unauthenticated attacker can exploit the flaw by providing specially crafted IPv4-mapped IPv6 addresses (such as http://[::ffff:127.0.0.1]) that bypass the deny-list and allow access to internal resources. Fixed versions properly recognize these addresses and prevent such requests.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path Traversal</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-44177.yaml</link>
        <description>Kirby CMS versions 5.3.0 through 5.4.0 are vulnerable to a path traversal vulnerability via the /api/auth/login endpoint. An unauthenticated attacker may supply a specially crafted email value in the request body containing traversal sequences (such as &quot;../..&quot;), which the application concatenates directly into a filesystem path when hydrating user objects. This can result in the resolution of paths outside the intended accounts directory and may lead to the inclusion of unintended files such as index.php, causing a denial of service by exhausting memory limits. The issue is addressed in version 5.4.1 by properly validating and sanitizing the user-supplied input to prevent directory traversal.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-55229: Gotenberg &lt; 8.34.0 - Local File Disclosure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-55229.yaml</link>
        <description>Gotenberg before 8.34.0 allows SSRF and limited local file disclosure via its /forms/libreoffice/convert endpoint. When LibreOffice is used to convert user-uploaded DOCX files, external relationships within the document (such as a:blip r:link TargetMode=&quot;External&quot;) can instruct LibreOffice to fetch local resources (file://) or remote resources (http/https), which are then included as images in the generated PDF. This can disclose the contents of local files LibreOffice can open as images, or allow outbound requests to attacker-controlled endpoints. Version 8.34.0 disables resolution of external resources during document conversion to mitigate the vulnerability.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-73034: DB-GPT &lt;= 0.8.1 - Arbitrary File Write</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-73034.yaml</link>
        <description>DB-GPT through 0.8.1 allows unauthenticated arbitrary file writes via a path traversal in the user_id HTTP header of the POST /api/v1/python/file/upload endpoint, letting attackers escape the intended upload directory and write files anywhere, as confirmed by the reflected upload path in the JSON response.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>CVE-2026-9133: Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-9133.yaml</link>
        <description>Amazon rabbitmq-aws versions 0.1.0 through 0.2.0 contain active debug code in the ARN resolver. An authenticated RabbitMQ user with management API access can submit an arn:aws-debug:file ARN to the validation endpoint and read arbitrary files accessible to the RabbitMQ process.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>johnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default Login</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/default-logins/johnson/johnson-controls-default-login.yaml</link>
        <description>Detected Johnson Controls Frick Quantum HD Compressor control panels are accessible with default PIN credentials. These are industrial refrigeration controllers used in cold storage and food processing facilities. Default PINs allow full control of the compressor system.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>grafana-loki-api-exposure: Grafana Loki - Unauthenticated API Access</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposures/apis/grafana-loki-api-exposure.yaml</link>
        <description>Grafana Loki API is accessible without authentication, allowing unauthorized access to log streams.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>victoriametrics-vmagent-api-exposure: VictoriaMetrics vmagent - Unauthenticated Targets Exposure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposures/apis/victoriametrics-vmagent-api-exposure.yaml</link>
        <description>VictoriaMetrics vmagent targets endpoint is exposed without authentication, leaking internal service inventory and scrape configuration.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>maven-settings-xml-exposure: Apache Maven settings.xml Credentials - Exposure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposures/configs/maven-settings-xml-exposure.yaml</link>
        <description>Detected An Apache Maven settings.xml file is exposed. The server section of this file stores the credentials Maven uses to authenticate to remote repositories and distribution servers, so a public copy can leak repository usernames and passwords.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>nuget-config-exposure: NuGet.config Package Source Credentials - Exposure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposures/configs/nuget-config-exposure.yaml</link>
        <description>Detected A NuGet.config file with a packageSourceCredentials section is exposed. NuGet stores per-feed authentication in this section and often keeps it as a ClearTextPassword, so a public copy leaks the username and password used to reach private package feeds.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>pypirc-credentials-exposure: Python .pypirc Credentials - Exposure</title>
        <link>https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposures/configs/pypirc-credentials-exposure.yaml</link>
        <description>Detected A Python .pypirc configuration file is exposed. This file stores the credentials used by tools like twine and setuptools to upload packages to PyPI or a private package index, and it commonly holds a plaintext password or an upload API token.
</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>信呼oa task.php 接口存在sql注入、XSS漏洞</title>
        <link>https://www.ddpoc.com/DVB-2026-11720.html</link>
        <description>信呼oa task.php 接口存在sql注入、XSS漏洞，攻击者可通过该漏洞进行敏感信息获取</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>湖南建研信息技术股份有限公司工程质量检测信息管理系统存在任意文件上传漏洞</title>
        <link>https://www.ddpoc.com/DVB-2026-11721.html</link>
        <description>湖南建研信息技术股份有限公司工程质量检测信息管理系统存在任意文件上传漏洞，攻击者可获取服务器权限。</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>关于YonBIP产品的cas未授权访问漏洞安全通告</title>
        <link>https://security.yonyou.com/#/noticeInfo?id= 814</link>
        <description>用友YonBIP旗舰版友户通cas接口存在用户认证逻辑绕过漏洞，攻击者利用此漏洞，可登录任意账户。总部紧急提供解决方案。请战略客户经营机构、区域客户经营机构、海外区、医疗行业客户与解决方案事业部、招聘云事业部实施负责人、客成负责人对应的实施和运维项目，以及各子公司（政务、金融、汽车、新道、烟草等）、商业伙伴部尽快通知所有客户部署，确保客户数据的安全。</description>
        <pubDate>Tue, 01 Sep 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞</title>
        <link>https://gobysec.net/updates# Zhongcheng Kexin Ticket Management System /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL Injection Vulnerability</link>
        <description>中成科信票务管理系统是北京中成科信科技发展有限公司面向旅游景区、演出剧院、体育场馆等场景打造的智慧票务管理平台，提供票类策略管控、售票流程管控、门票核验、营销渠道管理、财务结算等核心功能，支持二维码、RFID等多种防伪载体以及闸机、手持终端等多种检票方式，广泛应用于景区、场馆及活动票务运营。中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx 接口存在SQL注入漏洞，攻击者可获取数据库敏感信息。</description>
        <pubDate>Mon, 31 Aug 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞</title>
        <link>https://gobysec.net/updates# Zhongcheng Kexin Ticket Management System /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL Injection Vulnerability</link>
        <description>中成科信票务管理系统是北京中成科信科技发展有限公司面向旅游景区、演出剧院、体育场馆等场景打造的智慧票务管理平台，提供票类策略管控、售票流程管控、门票核验、营销渠道管理、财务结算等核心功能，支持二维码、RFID等多种防伪载体以及闸机、手持终端等多种检票方式，广泛应用于景区、场馆及活动票务运营。中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx 接口存在SQL注入漏洞，攻击者可获取数据库敏感信息。</description>
        <pubDate>Mon, 31 Aug 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>FileRise /uploads 文件读取漏洞（CVE-2026-25231）</title>
        <link>https://gobysec.net/updates# FileRise /uploads File Read Vulnerability (CVE-2026-25231)</link>
        <description>FileRise 是一款开源的自托管文件管理器，提供文件上传下载、目录管理、WebDAV 访问、标签管理等功能，支持细粒度目录 ACL 权限控制，可部署于 Docker 等环境。FileRise 的 /uploads 目录存在文件读取漏洞，未认证攻击者在获知上传文件路径后可直接读取该目录中的文件，造成敏感数据泄露。</description>
        <pubDate>Mon, 31 Aug 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>用友时空-KSOA /worksheet/agent_worksadd.jsp SQL 注入漏洞</title>
        <link>https://gobysec.net/updates# Yonyou Time-Space KSOA /worksheet/agent_worksadd.jsp SQL Injection Vulnerability</link>
        <description>用友时空-KSOA系统的agent_worksadd.jsp页面存在SQL时间盲注漏洞，攻击者可通过构造恶意id参数注入SQL语句，利用WAITFOR DELAY实现时间延迟，获取数据库敏感信息，进一步可能导致系统被入侵控制。</description>
        <pubDate>Mon, 31 Aug 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>JoomShaper SP LMS /index.php?option=com_splms&amp;view=cart 文件上传漏洞（CVE-2026-48909）</title>
        <link>https://gobysec.net/updates# JoomShaper SP LMS /index.php?option=com_splms&amp;view=cart File Upload Vulnerability (CVE-2026-48909)</link>
        <description>JoomShaper SP LMS 是由 JoomShaper 团队为 Joomla 内容管理系统开发的学习管理系统（LMS）扩展，提供课程管理、在线学习、学员管理等功能，拥有超过 10 万次安装，被广泛应用于教育培训、在线课堂与知识付费等场景。SP LMS /index.php?option=com_splms\u0026view=cart 存在文件上传漏洞，攻击者可利用该漏洞向服务器任意目录写入恶意文件，进而执行任意代码，完全控制受影响系统。</description>
        <pubDate>Mon, 31 Aug 2026 00:00:00 </pubDate>
    </item>

    <item>
        <title>用友时空-KSOA /worksheet/agent_work_report.jsp SQL 注入漏洞</title>
        <link>https://gobysec.net/updates# Yonyou Time-Space KSOA /worksheet/agent_work_report.jsp SQL Injection Vulnerability</link>
        <description>用友时空-KSOA系统的agent_work_report.jsp页面存在SQL时间盲注漏洞，攻击者可通过构造恶意id参数注入SQL语句，利用WAITFOR DELAY实现时间延迟，获取数据库敏感信息，进一步可能导致系统被入侵控制。</description>
        <pubDate>Mon, 31 Aug 2026 00:00:00 </pubDate>
    </item>

</channel>
</rss>
