往事不回首,安全不停步。AiRedTeam 的安全随笔,记录那些与代码和漏洞博弈的深夜。代码为剑,漏洞为砺,守一方数字净土。以此笔墨,化作守望万物的白泽。

安全情报

CVE-2026-41640 (CVSS 7.5) - NocoBase is an AI-powered no-code/low-code platform for building business applic

📡 NVD-Latest · 2026-05-07 CVE-2026-41640 (CVSS 7.5) - NocoBase is an AI-powered no-code/low-code platform for building business applic CVE-2026-41640 CVE-2026-41640 CVSS:7.5 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database
阅读时间 1 分钟
安全情报

CVE-2026-41641 (CVSS 7.2) - NocoBase is an AI-powered no-code/low-code platform for building business applic

📡 NVD-Latest · 2026-05-07 CVE-2026-41641 (CVSS 7.2) - NocoBase is an AI-powered no-code/low-code platform for building business applic CVE-2026-41641 CVE-2026-41641 CVSS:7.2 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the checkSQL() validation function that blocks dangerous
阅读时间 1 分钟
安全情报

CVE-2026-7252 (CVSS 8.1) - The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page

📡 NVD-Latest · 2026-05-07 CVE-2026-7252 (CVSS 8.1) - The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page CVE-2026-7252 CVE-2026-7252 CVSS:8.1 The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to
阅读时间 1 分钟
安全情报

CVE-2026-4430 (CVSS 7.8) - Out-of-bounds write vulnerability in The Document Foundation LibreOffice via cra

📡 NVD-Latest · 2026-05-07 CVE-2026-4430 (CVSS 7.8) - Out-of-bounds write vulnerability in The Document Foundation LibreOffice via cra CVE-2026-4430 CVE-2026-4430 CVSS:7.8 Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3,
安全情报

CVE-2026-5784 (CVSS 8.8) - Improper neutralization of input during web page generation ('cross-site scripti

📡 NVD-Latest · 2026-05-07 CVE-2026-5784 (CVSS 8.8) - Improper neutralization of input during web page generation ('cross-site scripti CVE-2026-5784 CVE-2026-5784 CVSS:8.8 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from
安全情报

CVE-2026-6002 (CVSS 8.8) - Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu

📡 NVD-Latest · 2026-05-07 CVE-2026-6002 (CVSS 8.8) - Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu CVE-2026-6002 CVE-2026-6002 CVSS:8.8 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue
安全情报

CVE-2026-41490 (CVSS 8.3) - Dagster is an orchestration platform for the development, production, and observ

📡 NVD-Latest · 2026-05-07 CVE-2026-41490 (CVSS 8.3) - Dagster is an orchestration platform for the development, production, and observ CVE-2026-41490 CVE-2026-41490 CVSS:8.3 Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior to Dagster libraries
阅读时间 1 分钟
安全情报

CVE-2026-44788 - SharpCompress has directory traversal via directory entries in WriteToDirectory

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44788 - SharpCompress has directory traversal via directory entries in WriteToDirectory CVE-2026-44788 GHSA-6c8g-7p36-r338 MEDIUM nuget/SharpCompress CVE: CVE-2026-44788 Summary A path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file
阅读时间 1 分钟
安全情报

CVE-2026-44900 - epa4all-client has a VAU Signature bypass

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44900 - epa4all-client has a VAU Signature bypass CVE-2026-44900 GHSA-g8r3-5hwf-qp96 HIGH maven/com.oviva.telematik:epa4all-client CVE: CVE-2026-44900 Impact In SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm
安全情报

CVE-2026-44896 - Mistune has XSS via unescaped figclass/figwidth in Figure directive

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44896 - Mistune has XSS via unescaped figclass/figwidth in Figure directive CVE-2026-44896 GHSA-58cw-g322-p94v MEDIUM pip/mistune CVE: CVE-2026-44896 In src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping (lines 152-168). This allows attribute injection and XSS
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)