Aggregator
2026-05-31: Seven days of scans and probes and web traffic hitting my web server
4 days 4 hours hence
hvv 2026 - 字典扫不到的后台,AI 猜出来了:DEF CON 105 页拆解下一代 HVV 打点术
9 hours 34 minutes ago
护网里最让人麻木的场景之一:目录扫描器跑了一整夜。
威努特网络安全解决方案:构建安全可信的医院网络安全防线
10 hours 6 minutes ago
从基础防护到安全运营,构建智慧医院安全体系。
CVE-2026-55833 | Netty up to 4.1.135.Final/4.2.15.Final SpdyFrameCodec allocation of resources
10 hours 24 minutes ago
A vulnerability classified as problematic has been found in Netty up to 4.1.135.Final/4.2.15.Final. Affected by this issue is some unknown functionality of the component SpdyFrameCodec. Performing a manipulation results in allocation of resources.
This vulnerability is cataloged as CVE-2026-55833. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-55831 | Netty up to 4.1.135.Final/4.2.15.Final SPDY SETTINGS decoder heap-based overflow
10 hours 25 minutes ago
A vulnerability described as problematic has been identified in Netty up to 4.1.135.Final/4.2.15.Final. Affected by this vulnerability is an unknown functionality of the component SPDY SETTINGS decoder. Such manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-55831. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-64624 | FreeRDP up to 3.27.x CLI parser certificate validation
11 hours 39 minutes ago
A vulnerability marked as problematic has been reported in FreeRDP up to 3.27.x. Affected is an unknown function of the component CLI parser. This manipulation causes improper certificate validation.
This vulnerability is tracked as CVE-2026-64624. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-47255 | AgenticMail api/core input validation
11 hours 40 minutes ago
A vulnerability labeled as critical has been found in AgenticMail. This impacts an unknown function of the component api/core. The manipulation results in improper input validation.
This vulnerability is identified as CVE-2026-47255. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-64626 | WWBN AVideo Encoder downloadURL server-side request forgery
11 hours 41 minutes ago
A vulnerability identified as critical has been detected in WWBN AVideo. This affects an unknown function of the component Encoder. The manipulation of the argument downloadURL leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-64626. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-57494 | AgenticMail prior 0.9.64 Task Management pending GET /api/agenticmail/tasks/pending assignee authorization
11 hours 42 minutes ago
A vulnerability categorized as critical has been discovered in AgenticMail. The impacted element is the function GET /api/agenticmail/tasks/pending of the file /api/agenticmail/tasks/pending of the component Task Management. Executing a manipulation of the argument assignee can lead to authorization bypass.
The identification of this vulnerability is CVE-2026-57494. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-57852 | Trilby Media Grav CMS scheduler-webhook Plugin up to 1.1.3/2.0.8 webhook token validation Remote Code Execution
11 hours 43 minutes ago
A vulnerability was found in Trilby Media Grav CMS scheduler-webhook Plugin up to 1.1.3/2.0.8. It has been rated as critical. The affected element is an unknown function of the component webhook token validation. Performing a manipulation results in Remote Code Execution.
This vulnerability was named CVE-2026-57852. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-47144 | BKDDFS shamefile up to 0.1.6 shame next shamefile.yaml path traversal
11 hours 44 minutes ago
A vulnerability was found in BKDDFS shamefile up to 0.1.6. It has been declared as problematic. Impacted is an unknown function of the file shamefile.yaml of the component shame next. Such manipulation of the argument shamefile.yaml leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-47144. Local access is required to approach this attack. No exploit exists.
vuldb.com
CVE-2026-64625 | WWBN AVideo up to 28.x Live plugin on_publish.php execAsync os command injection
11 hours 45 minutes ago
A vulnerability was found in WWBN AVideo up to 28.x. It has been classified as problematic. This issue affects the function execAsync of the file on_publish.php of the component Live plugin. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-64625. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-57495 | agenticmail claudecode/codex/core/openclaw prior 0.2.39/0.1.33/0.9.43/0.5.71 Mail from/subject/preview permission
11 hours 46 minutes ago
A vulnerability was found in agenticmail claudecode, codex, core and openclaw and classified as critical. This vulnerability affects unknown code of the component Mail Handler. The manipulation of the argument from/subject/preview results in permission issues.
This vulnerability is known as CVE-2026-57495. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-51031 | FlareSolverr up to 3.4.6 API server-side request forgery
11 hours 56 minutes ago
A vulnerability has been found in FlareSolverr up to 3.4.6 and classified as critical. This affects an unknown part of the component API. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-51031. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-51025 | fuint Member Marketing System up to 1.0 ClientMessageController cross site scripting
11 hours 57 minutes ago
A vulnerability, which was classified as problematic, was found in fuint Member Marketing System up to 1.0. Affected by this issue is some unknown functionality of the file ClientMessageController of the component ClientMessageController. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-51025. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-52656 | Allwinner SJ4000-Air up to 1.4C FEX file privilege escalation
11 hours 58 minutes ago
A vulnerability, which was classified as very critical, has been found in Allwinner SJ4000-Air up to 1.4C. Affected by this vulnerability is an unknown functionality of the component FEX file Handler. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-52656. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-47128 | always-further nono up to 0.54.x landlock sandbox
11 hours 59 minutes ago
A vulnerability classified as problematic was found in always-further nono up to 0.54.x. Affected is an unknown function of the component landlock. Such manipulation leads to sandbox issue.
This vulnerability is documented as CVE-2026-47128. The attack needs to be performed locally. There is not any exploit available.
vuldb.com
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
11 hours 59 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CVE-2026-12900 | Brainstormforce Spectra Legacy Plugin up to 2.19.28 on WordPress uagb image cross site scripting
12 hours ago
A vulnerability classified as problematic has been found in Brainstormforce Spectra Legacy Plugin up to 2.19.28 on WordPress. This impacts an unknown function of the component uagb image. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-12900. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com