Posts of last few hours
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
Currently trending CVE - Hype Score: 15 - An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation ...
https://cvemon.intruder.io/cves/CVE-2026-81578
Currently trending CVE - Hype Score: 15 - An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an ...
https://cvemon.intruder.io/cves/CVE-2026-82078
Currently trending CVE - Hype Score: 8 - Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (XSS). The frontend can render attacker-controlled Mermaid diagrams using mermaid.render(), then ...
https://cvemon.intruder.io/cves/CVE-2026-23630
Currently trending CVE - Hype Score: 13 - An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
https://cvemon.intruder.io/cves/CVE-2026-66384
Currently trending CVE - Hype Score: 16 - An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted ...
https://cvemon.intruder.io/cves/CVE-2023-49105
Currently trending CVE - Hype Score: 22 - In the Linux kernel, the following vulnerability has been resolved:
xfrm: nat_keepalive: avoid double free on send error
nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6
send helper reports an error.
That cleanup is only correct before the skb is handed ...
https://cvemon.intruder.io/cves/CVE-2026-72137
Currently trending CVE - Hype Score: 13 - In the Linux kernel, the following vulnerability has been resolved:
ipv6: account for fraggap on the paged allocation path
In __ip6_append_data(), when the paged-allocation branch is taken
(MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are
computed ...
https://cvemon.intruder.io/cves/CVE-2026-53362
Currently trending CVE - Hype Score: 14 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
https://cvemon.intruder.io/cves/CVE-2025-55182
Currently trending CVE - Hype Score: 8 - Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. ...
https://cvemon.intruder.io/cves/CVE-2025-58434
Currently trending CVE - Hype Score: 24 - A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time ...
https://cvemon.intruder.io/cves/CVE-2024-6387
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
A vulnerability categorized as critical has been discovered in JFrog Artifactory up to 7.161.19. This impacts an unknown function. Executing a manipulation can lead to improper privilege management.
This vulnerability is tracked as CVE-2026-82329. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/396923
A vulnerability was found in runatlantis Atlantis up to 0.47.1. It has been rated as critical. This affects an unknown function of the file /github-app/setup. Performing a manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-82282. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/396922
A vulnerability was found in dataelement Bisheng up to 2.6.0-fix2. It has been declared as critical. The impacted element is an unknown function of the file /api/v1/workflow/report/callback of the component Callback Endpoint. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-82285. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/396921
A vulnerability was found in Portkey-AI Gateway up to 1.15.2. It has been classified as problematic. The affected element is an unknown function. This manipulation of the argument x-portkey-custom-host causes server-side request forgery.
The identification of this vulnerability is CVE-2026-82270. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/396920
A vulnerability was found in QwenLM Qwen-Agent up to 0.0.34 and classified as problematic. Impacted is an unknown function of the component Document Parsing. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-82268. The attack may be performed from remote. There is no available exploit.
https://vuldb.com/vuln/396919
A vulnerability has been found in argoproj argo-rollouts up to 1.10.0 and classified as problematic. This issue affects some unknown processing of the component Dashboard. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2026-82277. The attack is possible to be carried out remotely. No exploit exists.
https://vuldb.com/vuln/396918
A vulnerability, which was classified as problematic, was found in HeyForm 3.0.0-rc.7. This vulnerability affects unknown code of the component CORS. Executing a manipulation of the argument Origin can lead to permissive cross-domain policy with untrusted domains.
This vulnerability is handled as CVE-2026-82291. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/396917
A vulnerability, which was classified as problematic, has been found in Chainlit up to 2.12.0. This affects an unknown part. Performing a manipulation results in improper privilege management.
This vulnerability is known as CVE-2026-82290. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/396916
Latest Blog Posts
- 5 days 23 hours ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 7 months ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago