全部/科技/实时热榜

NVD · 实时热榜

HISTORY2026年8月14日176 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS176 个热搜
  1. 01
    CVE-2026-19617 · MEDIUM 5.5

    A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems.

    最高第 114:22 达到14:22 首次观测上榜20:30 观测离榜累计约6小时8分
  2. 02
    CVE-2026-19756 · LOW 2.1

    A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 107:24 达到07:24 首次观测上榜13:34 观测离榜累计约6小时10分
  3. 03
    CVE-2026-19765 · LOW 2.1

    A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the function loadSource of the file src/utils/swagger-parser.ts of the component fetch_swagger. Performing a manipulation results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 109:32 达到09:32 首次观测上榜14:22 观测离榜累计约4小时50分
  4. 04
    CVE-2026-19771 · HIGH 7.3

    A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 110:20 达到10:20 首次观测上榜15:26 观测离榜累计约5小时6分
  5. 05
    CVE-2026-19787 · LOW 2

    A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

    最高第 111:24 达到11:24 首次观测上榜17:18 观测离榜累计约5小时54分
  6. 06
    CVE-2026-19792 · HIGH 7.4

    A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

    最高第 113:34 达到13:34 首次观测上榜20:30 观测离榜累计约6小时56分
  7. 07
    CVE-2026-19811 · HIGH 7.4

    A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

    最高第 115:26 达到15:26 首次观测上榜20:30 观测离榜累计约5小时4分
  8. 08
    CVE-2026-19813 · HIGH 7.4

    A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

    最高第 116:30 达到16:30 首次观测上榜20:30 观测离榜累计约4小时
  9. 09
    CVE-2026-19815 · HIGH 7.4

    A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

    最高第 117:18 达到17:18 首次观测上榜20:30 观测离榜累计约3小时12分
  10. 10
    CVE-2026-19821 · HIGH 7.4

    A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

    最高第 119:26 达到19:26 首次观测上榜20:30 观测离榜累计约1小时4分
  11. 11
    CVE-2026-19870 · HIGH 8.6

    Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership

    最高第 121:18 达到21:18 首次观测上榜当日结束时仍在榜累计约2小时40分
  12. 12
    CVE-2026-69101 · HIGH 8.3

    Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a malicious XML document containing an external DTD reference to the edit_workflow action, causing the server to issue outbound HTTP requests to attacker-controlled infrastructure and exfiltrate local files readable by the TIS process user, including configuration files and Derby database credentials.

    最高第 123:26 达到23:26 首次观测上榜当日结束时仍在榜累计约32分钟
  13. 13
    CVE-2026-73266 · HIGH 7.1

    A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.

    最高第 101:19 达到01:19 首次观测上榜06:04 观测离榜累计约4小时46分
  14. 14
    CVE-2026-73558 · MEDIUM 5.3

    vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause act_and_mul_kernel to consume another batched user's input, allowing a request processed in the same inference batch to receive a partial or complete copy of another user's inference result. This issue is fixed in version 0.27.0.

    最高第 100:00 达到当日首次采集时已在榜01:19 观测离榜累计约1小时19分
  15. 15
    CVE-2026-73630 · MEDIUM 6.9

    SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never sets a failure code, so its outcome is signalled entirely by the response message and by the presence of a Set-Cookie header, and these signals differ across access tiers. By submitting requests with an empty password for a candidate document identifier, an anonymous attacker can distinguish whether a document is public/nonexistent, password-protected, or exists at the hidden or forbidden tier, thereby confirming the existence of documents they are not permitted to access. Because hidden and forbidden entries store an empty password, such requests also cause the server to issue a publish-auth cookie for forbidden documents.

    最高第 120:30 达到20:30 首次观测上榜当日结束时仍在榜累计约3小时28分
  16. 16
    CVE-2026-73633 · HIGH 7.5

    Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin's configurable JSON input length limit does not bound this read. The JSON plugin is an optional component; applications that do not use it, or use it without enabling JSON request-body handling, are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

    最高第 122:22 达到22:22 首次观测上榜当日结束时仍在榜累计约1小时36分
  17. 17
    CVE-2026-73671 · MEDIUM 5.1

    Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can craft a malicious logout URL containing an arbitrary external domain or javascript: URI scheme to redirect authenticated users to attacker-controlled phishing pages after session destruction, enabling credential theft and OAuth redirect abuse.

    最高第 100:31 达到00:31 首次观测上榜01:19 观测离榜累计约48分钟
  18. 18
    CVE-2026-73673 · HIGH 8.7

    Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.

    最高第 121:34 达到21:34 首次观测上榜当日结束时仍在榜累计约2小时24分
  19. 19
    CVE-2026-73843 · CRITICAL 9.6

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2.

    最高第 106:20 达到06:20 首次观测上榜13:34 观测离榜累计约7小时14分
  20. 20
    CVE-2026-8715 · CRITICAL 9.6

    Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.

    最高第 106:04 达到06:04 首次观测上榜06:20 观测离榜累计约16分钟
  21. 21
    CVE-2026-18039 · UNKNOWN

    The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

    最高第 214:22 达到14:22 首次观测上榜20:30 观测离榜累计约6小时8分
  22. 22
    CVE-2026-19753 · MEDIUM 5.5

    A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 207:24 达到07:24 首次观测上榜13:34 观测离榜累计约6小时10分
  23. 23
    CVE-2026-19764 · MEDIUM 5.5

    A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 209:32 达到09:32 首次观测上榜14:22 观测离榜累计约4小时50分
  24. 24
    CVE-2026-19770 · LOW 1.9

    A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-reporting/src/index.ts of the component Download Endpoint. The manipulation of the argument downloadUrl leads to server-side request forgery. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 210:20 达到10:20 首次观测上榜14:22 观测离榜累计约4小时2分
  25. 25
    CVE-2026-19786 · MEDIUM 5.3

    A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. Upgrading to version 12.9 is capable of addressing this issue. The patch is named 801a71272c82cf4bf695fdc5ed42a9b7511d124d. It is recommended to upgrade the affected component.

    最高第 211:24 达到11:24 首次观测上榜17:18 观测离榜累计约5小时54分
  26. 26
    CVE-2026-19791 · HIGH 7.4

    A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    最高第 213:34 达到13:34 首次观测上榜20:30 观测离榜累计约6小时56分
  27. 27
    CVE-2026-19812 · HIGH 7.4

    A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

    最高第 216:30 达到16:30 首次观测上榜20:30 观测离榜累计约4小时
  28. 28
    CVE-2026-19814 · HIGH 7.4

    A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    最高第 217:18 达到17:18 首次观测上榜20:30 观测离榜累计约3小时12分
  29. 29
    CVE-2026-19826 · MEDIUM 5.5

    A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.

    最高第 221:18 达到21:18 首次观测上榜当日结束时仍在榜累计约2小时40分
  30. 30
    CVE-2026-53472 · MEDIUM 6.3

    A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information.

    最高第 222:22 达到22:22 首次观测上榜当日结束时仍在榜累计约1小时36分
  31. 31
    CVE-2026-58224 · MEDIUM 6.5

    A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents.

    最高第 223:26 达到23:26 首次观测上榜当日结束时仍在榜累计约32分钟
  32. 32
    CVE-2026-59765 · UNKNOWN

    SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

    最高第 201:19 达到01:19 首次观测上榜06:04 观测离榜累计约4小时46分
  33. 33
    CVE-2026-73051 · MEDIUM 6.3

    actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.

    最高第 220:30 达到20:30 首次观测上榜23:26 观测离榜累计约2小时56分
  34. 34
    CVE-2026-73480 · MEDIUM 4.8

    gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling title spoofing, clipboard manipulation, or other terminal-dependent effects.

    最高第 206:04 达到06:04 首次观测上榜06:20 观测离榜累计约16分钟
  35. 35
    CVE-2026-73557 · MEDIUM 6.3

    vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore state can be raced by concurrent prompt_embeds parts submitted to POST /v1/chat/completions through AsyncMultiModalItemTracker.resolve_items, asyncio.gather, and the default executor, allowing an invalid sparse tensor to reach tensor.to_dense despite the CVE-2025-62164 guard when enable_prompt_embeds is enabled. This issue is fixed in version 0.26.0.

    最高第 200:00 达到当日首次采集时已在榜00:31 观测离榜累计约31分钟
  36. 36
    CVE-2026-73670 · HIGH 8.6

    A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform table traversal, time-based blind, boolean-based blind, and error-based injection techniques to enumerate full database schema, access system tables such as information_schema, and chain the disclosure with secondary injection points to extract credential data.

    最高第 200:31 达到00:31 首次观测上榜01:19 观测离榜累计约48分钟
  37. 37
    CVE-2026-73842 · CRITICAL 9

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.

    最高第 206:20 达到06:20 首次观测上榜13:34 观测离榜累计约7小时14分
  38. 38
    CVE-2025-10308 · MEDIUM 4.3

    The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    最高第 313:34 达到13:34 首次观测上榜20:30 观测离榜累计约6小时56分
  39. 39
    CVE-2026-1621 · MEDIUM 5.3

    Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204.

    最高第 322:22 达到22:22 首次观测上榜当日结束时仍在榜累计约1小时36分
  40. 40
    CVE-2026-16810 · MEDIUM 6.5

    The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    最高第 314:22 达到14:22 首次观测上榜20:30 观测离榜累计约6小时8分
  41. 41
    CVE-2026-19749 · LOW 2.9

    A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.

    最高第 306:04 达到06:04 首次观测上榜06:20 观测离榜累计约16分钟
  42. 42
    CVE-2026-19763 · MEDIUM 5.1

    A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded.

    最高第 309:32 达到09:32 首次观测上榜14:22 观测离榜累计约4小时50分
  43. 43
    CVE-2026-19767 · LOW 2.1

    A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

    最高第 310:20 达到10:20 首次观测上榜14:22 观测离榜累计约4小时2分
  44. 44
    CVE-2026-19785 · MEDIUM 5.3

    A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical Module. Such manipulation of the argument table leads to sql injection. The attack may be launched remotely. Upgrading to version 12.8 is able to resolve this issue. The name of the patch is 6234a0ee0124c0667c824693ac77164f18946ddf. Upgrading the affected component is recommended.

    最高第 311:24 达到11:24 首次观测上榜16:30 观测离榜累计约5小时6分
  45. 45
    CVE-2026-19794 · HIGH 7.2

    The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    最高第 316:30 达到16:30 首次观测上榜20:30 观测离榜累计约4小时
  46. 46
    CVE-2026-19825 · MEDIUM 5.5

    A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

    最高第 321:18 达到21:18 首次观测上榜当日结束时仍在榜累计约2小时40分
  47. 47
    CVE-2026-19880 · MEDIUM 6.3

    Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.

    最高第 323:26 达到23:26 首次观测上榜当日结束时仍在榜累计约32分钟
  48. 48
    CVE-2026-59763 · UNKNOWN

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

    最高第 301:19 达到01:19 首次观测上榜06:04 观测离榜累计约4小时46分
  49. 49
    CVE-2026-73049 · MEDIUM 6.9

    SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when filtering backlinks. Anonymous readers can supply a publicly visible database row identifier to discover hidden-tier documents that reference it, receiving the database name, row title, and document path of hidden documents.

    最高第 320:30 达到20:30 首次观测上榜23:26 观测离榜累计约2小时56分
  50. 50
    CVE-2026-73556 · MEDIUM 5.3

    vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_output_request_lm_format_enforcer, allowing an unauthenticated /v1/completions request against the lm-format-enforcer backend to consume a CPU core and stall the structured-output engine path with a catastrophic regular expression. This issue is fixed in version 0.26.0.

    最高第 300:00 达到当日首次采集时已在榜00:31 观测离榜累计约31分钟