📊 2026-06-22 漏洞情报日报 · 200 条 · 高危 73
每日漏洞情报汇总 · 2026-06-22
📊 2026-06-22 漏洞情报日报
📋 共 200 条
🔥 高危/严重 73 条
🐙 GitHub-Advisory 74 条 🔥37
🛡️ NVD-Latest 36 条 🔥36
⚔️ Sploitus 90 条
🤖 今日安全态势分析
🎯 今日重点关注
- Crawl4AI 多漏洞链 (GHSA-365w-hqf6-vxfg, CVE-2026-56265, CVE-2026-53753): 影响 Docker API 服务器,组合了硬编码 JWT 密钥导致的认证绕过、AST 沙箱逃逸导致的远程代码执行 (RCE) 以及 SSRF 等多个漏洞。攻击者可未授权接管服务,风险极高。
- Prefect GitRepository RCE (CVE-2026-5366, CVSS 9.9): 影响 Prefect 3.6.23。在 Git 仓库的配置中,`commit_sha` 参数缺乏过滤,攻击者可通过构造恶意输入注入命令,实现远程代码执行。
- Langflow 文件读取与 RCE (CVE-2026-55447): 影响基于 `BaseFileComponent` 的多个组件。攻击者可利用任意文件读取漏洞,进一步结合上下文信息实现远程代码执行。
- LobeHub 未授权 SSRF (CVE-2026-54157): 影响 LobeHub 的 `/webapi/proxy` 端点。攻击者无需认证即可服务端发起请求,存在内网探测、泄露敏感信息及 Cookie 注入风险。
- Flowise 配置注入 RCE (CVE-2024-58351, CVSS 9.8): 影响 Flowise 2.1.4 之前版本。攻击者可通过 `overrideConfig` 选项在流程执行时注入恶意配置,导致远程代码执行。
📈 威胁趋势
- 远程代码执行 (RCE) 与命令注入: 今日漏洞中数量最多的类型,涵盖 Crawl4AI、Prefect、Langflow、Flowise 和 WooCommerce。攻击向量包括沙箱逃逸、参数注入和配置篡改。
- 不安全的直接对象引用 (IDOR): 在 Langflow 和 OpenRemote Manager 中出现,允许已认证用户通过篡改请求中的对象 ID 访问或操作其他用户的资源,如执行他人的工作流或批量删除告警。
- 认证绕过与权限提升: Crawl4AI 因硬编码密钥导致认证完全失效。WordPress 的 Branda 插件存在账户接管漏洞,可导致权限提升。
- 服务端请求伪造 (SSRF) 与信息泄露: LobeHub 的 SSRF 漏洞允许未经授权的内网探测。SiYuan 笔记软件的 Bazaar 市场因未对元数据过滤,可被注入恶意代码导致信
🛡️ 缓解建议
- 立即更新受影响软件: 优先排查并更新 Crawl4AI、Prefect、Langflow 等今日披露的严重产品。对于暂时无法升级的,启用 Web 应用防火墙 (WAF) 拦截已知攻击特征。
- 强化认证与密钥管理: 更改所有 Docker 容器及服务的默认 JWT 密钥。对内部服务的 API 端点(如 Langflow 的 `/api/v1/responses`)实施严格的访问控制和用户身份验证。
- 审计与限制 API 输入: 审查所有接受用户输入并执行命令或发起请求的 API(如代理、Git 操作接口),对输入内容进行严格的校验和消毒,禁止传递特殊字符。
- 审查应用插件与市场来源: 对于支持插件或包管理的应用(如 SiYuan),在安装非官方来源的包时需格外谨慎,建议仅在确认来源可靠后再进行安装。
🐙 GitHub-Advisory(74 条)
Critical (6 条)
- GHSA-365w-hqf6-vxfg - Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, X Critical 9.1
Summary Multiple security vulnerabilities in the Crawl4AI Docker API server affecting endpoints for crawling, markdown/LLM extraction, screenshots, PDFs,… - CVE-2026-55255 - Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticate
CVE-2026-55255Critical
## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/responses` endpoint allows an authenticated attacker to execute any flow belonging… - CVE-2026-55447 - Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-55447Critical
Summary All components based on `BaseFileComponent` are vulnerable to the following vulnerability: 1. Docling (`DoclingInlineComponent`) 2. Docling Serve… - GHSA-h3m5-97jq-qjrf - OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete) Critical
Summary OpenRemote Manager is vulnerable to a cross-tenant Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint. An authenticated user… - CVE-2026-53753 - Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker
CVE-2026-53753Critical
Summary The `_safe_eval_expression()` function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore.… - CVE-2026-54157 - LobeHub: Unauthenticated SSRF in `/webapi/proxy`
CVE-2026-54157Critical
## Unauthenticated SSRF in /webapi/proxy allows anyone to proxy requests and inject cookies on lobehub.com ## Summary The `/webapi/proxy` endpoint on…
High (31 条)
- CVE-2026-55446 - Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-55446High
Summary An attacker can send a `/api/v1/files/upload/` request without any authentication token/cookies and abuse a very long multipart form boundary to make… - CVE-2026-55692 - StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wg
CVE-2026-55692High
Summary With $wgEmbedVideoRequireConsent enabled (the default), the urls for videos are stored in a json-ified data attribute`data-mw-iframeconfig`. When given… - CVE-2026-55878 - symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Craf
CVE-2026-55878High
Description The `ux:install` console command installs files from a recipe kit by copying paths listed in a `copy-files` map. The only guard against malicious… - GHSA-2fmp-9rvw-hc96 - Network-AI: Poisoned environment backup manifest allows arbitrary recursive dele High
Summary `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()`… - GHSA-xcqx-9jf5-w339 - SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `we High
## Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` Summary The `web_url_read` MCP tool in mcp-searxng enforces its 5 MiB response-size… - GHSA-mrvx-jmjw-vggc - SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read` High
## DNS-resolved Private Hostname SSRF in `web_url_read` Summary The `web_url_read` MCP tool in `mcp-searxng` is vulnerable to Server-Side Request Forgery… - GHSA-6vxv-wg6j-5qwp - Gogs: XSS in .ipynb files renderer due to outdated notebookjs High
Summary Gogs renders Jupyter notebook files (`.ipynb`) using [jsvine/notebookjs](https://github.com/jsvine/notebookjs), but the version is outdated, missing… - GHSA-6v7p-g79w-8964 - MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a cau High
Impact If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. If the Unpacker is used repeatedly to unpack untrusted… - GHSA-x26h-xmv8-gxf7 - stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind High
Summary On a multi-tenant stigmem node, RTBF (right-to-be-forgotten) tombstones were mis-scoped two ways. (1) `issue_tombstone` defaulted the tenant to… - GHSA-xhv3-q4xx-349r - stistigmem-node: quarantine review surface exposes and mutates other tenants' qu High
Summary On a multi-tenant stigmem node, a tenant administrator could list, read, and **admit or reject** quarantined facts belonging to **other** tenants. The… - GHSA-6gqw-jqv7-v88m - stigmem-node: decay sweep expires and counts facts across all tenants (cross-ten High
Summary On a multi-tenant stigmem node, a caller holding a `write` credential for **one** tenant can run a decay sweep that acts on **every** tenant's facts.… - GHSA-v3f4-w7r7-v3hm - Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost request High
## Impact Uni-CLI versions before 0.225.2 exposed the legacy JSON-RPC-over-HTTP MCP transport on loopback without validating browser Origin headers before… - GHSA-c795-2g9c-j48m - EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id High
EverOS versions 1.0.0 and earlier are vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint. The per-message sender_id field was not… - GHSA-x975-rgx4-5fh4 - appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGenerato High
## Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI) Summary `appium-mcp`'s `createLocatorGeneratorUI` function interpolates… - GHSA-c3xh-98xp-6qhf - githubtoplanguages: Command Injection via Issue Title in Discord Notification Wo High
Summary A GitHub Actions workflow is vulnerable to command injection through the issue title. The workflow is triggered when an issue is opened or closed, and… - GHSA-f4xh-w4cj-qxq8 - LangSmith SDK TracingMiddleware: Arbitrary server-side file read High
# Summary An attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file… - GHSA-h5x8-xp6m-x6q4 - @jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Sign High
## Arbitrary Cloudinary API Parameter Signing in @jhb.software/payload-cloudinary-plugin Summary `@jhb.software/payload-cloudinary-plugin` v0.3.4 exposes a… - GHSA-g2gw-q38m-vjfc - Lokka: Azure Resource Manager URL path validation issue High
Lokka versions prior to 2.1.2 constructed Azure Resource Manager request URLs using direct string concatenation with user-controlled path input. Specially… - GHSA-cc8f-fcx3-gpjr - SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter High
SurrealDB's full-text search lets you define a text analyzer whose `mapper` filter loads a term-mapping file from disk (`DEFINE ANALYZER ... FILTERS… - GHSA-869j-r97x-hx2g - Anki's local HTTP server does not sufficiently validate requests High
## Summary Anki launches a local HTTP server to serve media files and web pages for parts of its interface. The server fails to validate requests in the… - CVE-2026-49402 - Deno: Command Injection via spawnSync & spawn on Windows
CVE-2026-49402High
## Summary Deno's `node:child_process` implementation provided an `escapeShellArg()` helper used when callers passed `shell: true` to `spawn` / `spawnSync` /… - CVE-2026-49440 - Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-49440High
## Summary `node:crypto.checkPrime(candidate[, options][, callback])` and `crypto.checkPrimeSync(candidate[, options])` ran no Miller-Rabin rounds at all when… - CVE-2026-50023 - yt-dlp: Dangerous file type creation via insufficient filename sanitization (Byp
CVE-2026-50023High
Summary A vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as `.desktop`, `.url`, `.webloc`) to the… - CVE-2026-53754 - Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 /
CVE-2026-53754High
Summary The Docker API server's SSRF protection (`validate_webhook_url` / `validate_url_destination` in `deploy/docker/utils.py`) used an explicit IPv4/IPv6… - GHSA-f989-c77f-r2cq - Crawl4AI: LLM credential exfiltration in Docker server via request base_url and High
Summary The Docker API server let a request control where LLM calls were sent and which environment variable an LLM token resolved from. Both could be abused… - GHSA-7cx2-g3h9-382p - Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header inje High
Summary Three backward-compatible hardening fixes in the Docker API server. The headline issue is an arbitrary file write via the screenshot/PDF `output_path`.… - CVE-2026-53755 - Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SS
CVE-2026-53755High
Summary The Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could… - CVE-2026-53622 - Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mix
CVE-2026-53622High
## Summary There is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass… - CVE-2026-54321 - Daytona: Public sandbox previews remain accessible for up to one hour after bein
CVE-2026-54321High
Summary Sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a… - CVE-2026-50574 - yt-dlp: Arbitrary code execution via manifest downloads with aria2c
CVE-2026-50574High
Summary If aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input… - CVE-2026-52844 - Caddy: Windows `file_server` path authorization bypass via encoded backslash
CVE-2026-52844High
Summary On Windows, Caddy `path` matchers treat `/private\secret.txt` as outside `/private/*`, but `file_server` later resolves the same request path as…
Medium (32 条)
- GHSA-jvcm-f35g-w78p - Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside th Medium 3.1
Summary `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A… - CVE-2026-55187 - Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechan
CVE-2026-55187Medium
## Summary The remediation shipped in mailpit v1.29.2 for [GHSA-mpf7-p9x7-96r3](https://github.com/axllent/mailpit/security/advisories/GHSA-mpf7-p9x7-96r3)… - CVE-2026-55195 - py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction
CVE-2026-55195Medium
py7zr's `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the… - CVE-2026-55206 - py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
CVE-2026-55206Medium
Summary PackInfo._read() uses an O(n^2) cumulative sum pattern where numstreams is read directly from the archive header. A crafted .7z archive with a large… - CVE-2026-55423 - Langflow: Logout button does not clear session
CVE-2026-55423Medium
Summary The logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. Details Not in auto login mode.… - CVE-2026-55650 - Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposu
CVE-2026-55650Medium
## Summary A Stored Cross-Site Scripting (XSS) issue previously existed in the Text Widget in Board of Outerbase Studio where unsanitized HTML could be… - CVE-2026-55770 - OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-55770Medium
## 1. Description Component `sdk/helper/ldaputil/client.go` — the shared LDAP utility library used by both the LDAP authentication backend and OpenLDAP secrets… - CVE-2026-55776 - OpenBao: Transit secrets engine crashes on key creation with `derived: true` for
CVE-2026-55776Medium
On OpenBao 2.5.4 and 2.5.2(and likely earlier versions also), an authenticated caller with write access to `transit/keys/*` can crash the OpenBao server by…
…另有 24 条 Medium 级漏洞(已省略)
Low (5 条)
- CVE-2026-55774 - OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revo
CVE-2026-55774Low
Summary OpenBao users with access to the `sys/leases/revoke/:lease_id` endpoint in any namespace can revoke leases in any other namespace as long as the lease… - CVE-2026-55775 - OpenBao's System Backend allows Unauthorized Management of the containing Namesp
CVE-2026-55775Low
Summary A user that is granted namespace management (`/sys/namespaces`) capabilities within a non-root namespace ("the victim namespace") can abuse special… - CVE-2026-55866 - SpiceDB: Checks involving relations with caveats can result in unconditional per
CVE-2026-55866Low
Impact Under concurrency, `CheckPermission` and `CheckBulkPermissions` can return `PERMISSIONSHIP_HAS_PERMISSION` for a (resource, permission, subject) whose…
…另有 2 条 Low 级漏洞(已省略)
🛡️ NVD-Latest(36 条)
Critical (8 条)
- CVE-2026-5366 Prefect version 3.6.23 is vulnerable to remote code execution due to improper ha
CVE-2026-5366Critical 9.9
CVE-2026-5366 CVSS:9.9 Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository`… - CVE-2026-56265 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a h
CVE-2026-56265Critical 9.8
CVE-2026-56265 CVSS:9.8 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API… - CVE-2024-58351 Flowise before 2.1.4 allows configuration to be injected into the Chainflow duri
CVE-2024-58351Critical 9.8
CVE-2024-58351 CVSS:9.8 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported… - CVE-2022-50972 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows att
CVE-2022-50972Critical 9.8
CVE-2022-50972 CVSS:9.8 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell… - CVE-2019-25763 WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication
CVE-2019-25763Critical 9.8
CVE-2019-25763 CVSS:9.8 WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain… - CVE-2026-11551 The Branda plugin for WordPress is vulnerable to privilege escalation via accoun
CVE-2026-11551Critical 9.8
CVE-2026-11551 CVSS:9.8 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including,… - CVE-2026-56397 SiYuan before v3.6.1 fails to sanitize package metadata and README content in th
CVE-2026-56397Critical 9.6
CVE-2026-56397 CVSS:9.6 SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package… - CVE-2026-56395 SiYuan before v3.6.1 fails to sanitize package metadata and README content in th
CVE-2026-56395Critical 9.6
CVE-2026-56395 CVSS:9.6 SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package…
High (28 条)
- CVE-2026-56396 phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser
CVE-2026-56396High 8.8
CVE-2026-56396 CVSS:8.8 phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow… - CVE-2026-56340 vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in mul
CVE-2026-56340High 8.8
CVE-2026-56340 CVSS:8.8 vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables… - CVE-2026-56216 Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /fun
CVE-2026-56216High 8.8
CVE-2026-56216 CVSS:8.8 Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API… - CVE-2026-56215 Capgo before 12.128.12 allows authenticated users to modify their mutable public
CVE-2026-56215High 8.3
CVE-2026-56215 CVSS:8.3 Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO… - CVE-2025-71378 picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickl
CVE-2025-71378High 8.1
CVE-2025-71378 CVSS:8.1 picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute… - CVE-2025-71357 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.py
CVE-2025-71357High 8.1
CVE-2025-71357 CVSS:8.1 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods.… - CVE-2025-71348 picklescan before 0.0.28 fails to detect malicious pickle files that invoke torc
CVE-2025-71348High 8.1
CVE-2025-71348 CVSS:8.1 picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within… - CVE-2026-56345 AVideo through 29.0 contains an authorization bypass vulnerability in the Meet p
CVE-2026-56345High 8.1
CVE-2026-56345 CVSS:8.1 AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that… - CVE-2026-9843 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress i
CVE-2026-9843High 8.1
CVE-2026-9843 CVSS:8.1 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to… - CVE-2026-12786 A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76
CVE-2026-12786High 7.8
CVE-2026-12786 CVSS:7.8 A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality… - CVE-2026-12784 A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This a
CVE-2026-12784High 7.8
CVE-2026-12784 CVSS:7.8 A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys… - CVE-2026-12782 A security flaw has been discovered in EaseUS Partition Master up to 14.5. The i
CVE-2026-12782High 7.8
CVE-2026-12782 CVSS:7.8 A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library… - CVE-2026-12781 A vulnerability was identified in EaseUS Partition Master up to 14.5. The affect
CVE-2026-12781High 7.8
CVE-2026-12781 CVSS:7.8 A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library… - CVE-2026-12780 A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an un
CVE-2026-12780High 7.8
CVE-2026-12780 CVSS:7.8 A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the… - CVE-2026-12779 A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issu
CVE-2026-12779High 7.8
CVE-2026-12779 CVSS:7.8 A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library… - CVE-2026-12778 A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This
CVE-2026-12778High 7.8
CVE-2026-12778 CVSS:7.8 A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library… - CVE-2026-56239 Capgo before 12.128.2 contains a potential privilege escalation vulnerability in
CVE-2026-56239High 7.6
CVE-2026-56239 CVSS:7.6 Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER… - CVE-2026-56253 Capgo before 12.128.2 contains an improper access control vulnerability in the p
CVE-2026-56253High 7.5
CVE-2026-56253 CVSS:7.5 Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows… - CVE-2026-56242 Capgo before 12.128.2 contains an unauthenticated security definer RPC function
CVE-2026-56242High 7.5
CVE-2026-56242 CVSS:7.5 Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning… - CVE-2026-56341 AVideo through version 26.0 contains multiple unauthenticated list.json.php endp
CVE-2026-56341High 7.5
CVE-2026-56341 CVSS:7.5 AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks,… - CVE-2020-37255 WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerab
CVE-2020-37255High 7.5
CVE-2020-37255 CVSS:7.5 WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain… - CVE-2026-11912 The Simple File List plugin for WordPress is vulnerable to arbitrary file modifi
CVE-2026-11912High 7.5
CVE-2026-11912 CVSS:7.5 The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all… - CVE-2026-11911 The Simple File List plugin for WordPress is vulnerable to arbitrary file deleti
CVE-2026-11911High 7.5
CVE-2026-11911 CVSS:7.5 The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the… - CVE-2026-56214 Capgo before 12.128.2 contains an information disclosure vulnerability in Supaba
CVE-2026-56214High 7.5
CVE-2026-56214 CVSS:7.5 Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and… - CVE-2026-12795 A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the
CVE-2026-12795High 7.3
CVE-2026-12795 CVSS:7.3 A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file… - CVE-2026-12775 A vulnerability was detected in Montodel House-Rental-Management up to 90010017b
CVE-2026-12775High 7.3
CVE-2026-12775 CVSS:7.3 A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue… - CVE-2026-12773 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the
CVE-2026-12773High 7.3
CVE-2026-12773 CVSS:7.3 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file… - CVE-2026-56382 Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contai
CVE-2026-56382High 7.2
CVE-2026-56382 CVSS:7.2 Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the…
⚔️ Sploitus(90 条)
Unknown (90 条)
- Exploit for CVE-2026-47729 exploit
CVE-2026-47729
Exploit for CVE-2026-47729 exploit - Exploit for Improper Control of Dynamically-Managed Code Resources in N8N exploit
Exploit for Improper Control of Dynamically-Managed Code Resources in N8N exploit
…另有 88 条 Unknown 级漏洞(已省略)
🤖 漏洞情报自动汇总 · 2026-06-22 · 数据来源: NVD / GitHub Advisory / Sploitus / CISA-KEV