References https://nvd.nist.gov/vuln/detail/CVE-2023-31474 https://www.gl-inet.com/blog/vulnerabilities-and-bug-fix-20230518/ https://access.redhat.com/security/cve/cve-2023-31474 https://www.vulmon.com/vulnerabilitydetails?qid=CVE-2023-31474&scoretype=cvssv4
Related VulnerabilitiesJuggle /h2-console 命令执行漏洞(CVE-2026-67208)PoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege EscalationPoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCgoogle-api-key: Google API KeyPoCCVE-2026-53629: GLPI - Blind SQL Injection in History Log Filter (LogBleed)PoCCVE-2026-67208: Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database ConsoleWP Google 地图 < 9.0.48 - 未经身份验证的存储 XSS (CVE-2025-11307)PoCCVE-2026-8732: WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauthenticated Administrator Account CreationPalo Alto Networks PAN-OS GlobalProtect /ssl-vpn/login.esp 权限绕过漏洞(CVE-2026-0257)厦门四信水利信息化平台接口configList存在sql注入漏洞Glowroot /backend/admin/users 未授权访问漏洞PoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2026-4810: Google ADK-Python - Unauthenticated Builder Endpoint