全部/科技/实时热榜

NVD · 实时热榜

HISTORY2026年8月25日310 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS310 个热搜
  1. 01
    CVE-2026-77384 · HIGH 7.5

    libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9.

    最高第 1306:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  2. 02
    CVE-2026-78259 · HIGH 7.3

    Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

    最高第 1206:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  3. 03
    CVE-2026-78262 · CRITICAL 9.8

    Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

    最高第 1106:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  4. 04
    CVE-2026-78263 · HIGH 7.1

    Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

    最高第 1006:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  5. 05
    CVE-2026-78264 · HIGH 7.1

    Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

    最高第 906:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  6. 06
    CVE-2026-78265 · CRITICAL 9.8

    Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

    最高第 806:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  7. 07
    CVE-2026-78266 · MEDIUM 6.5

    Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

    最高第 706:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  8. 08
    CVE-2026-78267 · CRITICAL 9.8

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

    最高第 606:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  9. 09
    CVE-2026-78268 · HIGH 7.5

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

    最高第 506:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  10. 10
    CVE-2026-78282 · HIGH 7.1

    Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

    最高第 406:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  11. 11
    CVE-2026-78284 · HIGH 8.6

    Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

    最高第 306:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  12. 12
    CVE-2026-78434 · MEDIUM 5.5

    A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 206:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  13. 13
    CVE-2026-78435 · LOW 2

    A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 106:27 达到06:27 首次观测上榜10:30 观测离榜累计约4小时3分
  14. 14
    CVE-2026-19943 · MEDIUM 6.4

    The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious titleTag value survives wp_kses_post on save because it is stored inside a block-comment delimiter and the live HTML is only synthesized at render time by do_blocks(), meaning the payload also fires in administrator and editor sessions during post preview.

    最高第 312:22 达到12:22 首次观测上榜16:22 观测离榜累计约4小时
  15. 15
    CVE-2026-75930 · MEDIUM 4.3

    The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary posts and pages — overwriting title and content, and seizing ownership by supplying an attacker-controlled post_author integer that bypasses wp_kses_post sanitization. The wp_rest nonce required by the handler is trivially obtainable by any logged-in user via /wp-admin/admin-ajax.php?action=rest-nonce and therefore does not constitute an authorization barrier.

    最高第 212:22 达到12:22 首次观测上榜16:22 观测离榜累计约4小时
  16. 16
    CVE-2026-76063 · MEDIUM 6.4

    The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The REST endpoint used to submit the video URL has its permission_callback set to __return_true, meaning any authenticated user — including those with Subscriber-level access — can reach the vulnerable code path.

    最高第 112:22 达到12:22 首次观测上榜16:22 观测离榜累计约4小时
  17. 17
    CVE-2026-75019 · MEDIUM 6.4

    The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives wp_kses_post on save because it contains no angle brackets — only a double-quote breakout of the cozyHoverEffect.boxShadow.color attribute value — allowing event-handler injection at the render stage.

    最高第 311:18 达到11:18 首次观测上榜15:18 观测离榜累计约4小时
  18. 18
    CVE-2026-75982 · MEDIUM 4.4

    The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX action. The LP_Admin_Ajax::create_page() handler only checks the edit_pages capability and a wp_rest nonce (both available to Editors), then reads the field_name parameter from the request without restricting it to a learn_press_* allow-list before passing it as the option key to LP_Helper::create_page(), which calls update_option($key_option, $page_id). This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrary WordPress options to a positive integer (a newly created page ID), enabling actions such as flipping users_can_register to a truthy value to open public registration, corrupting active_plugins to break the site, or otherwise tampering with site-wide settings normally reserved for administrators.

    最高第 211:18 达到11:18 首次观测上榜15:18 观测离榜累计约4小时
  19. 19
    CVE-2026-78685 · HIGH 8.6

    Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.

    最高第 111:18 达到11:18 首次观测上榜15:18 观测离榜累计约4小时
  20. 20
    CVE-2026-78679 · HIGH 7.1

    GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.

    最高第 510:30 达到10:30 首次观测上榜14:30 观测离榜累计约4小时
  21. 21
    CVE-2026-78680 · HIGH 8.5

    NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working directory. Attackers can exploit bare-name binary resolution on Windows via the current working directory or on Unix-like systems via relative PATH entries to execute their binary instead of the legitimate Graphviz tool.

    最高第 410:30 达到10:30 首次观测上榜14:30 观测离榜累计约4小时
  22. 22
    CVE-2026-78681 · HIGH 8.7

    NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.

    最高第 310:30 达到10:30 首次观测上榜14:30 观测离榜累计约4小时
  23. 23
    CVE-2026-78682 · HIGH 8.7

    NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content.

    最高第 210:30 达到10:30 首次观测上榜14:30 观测离榜累计约4小时
  24. 24
    CVE-2026-78683 · CRITICAL 9.4

    NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application. NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. Fixed in 3.10.0.

    最高第 110:30 达到10:30 首次观测上榜14:30 观测离榜累计约4小时
  25. 25
    CVE-2025-9878 · MEDIUM 6.4

    The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    最高第 511:18 达到11:18 首次观测上榜14:30 观测离榜累计约3小时12分
  26. 26
    CVE-2026-10627 · MEDIUM 5.3

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view the titles, dates, descriptions, and location details of events and locations that administrators have marked as draft, pending, trashed, or private.

    最高第 411:18 达到11:18 首次观测上榜14:30 观测离榜累计约3小时12分
  27. 27
    CVE-2026-53532 · HIGH 7.1

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.

    最高第 107:31 达到07:31 首次观测上榜10:30 观测离榜累计约2小时59分
  28. 28
    CVE-2026-78568 · CRITICAL 9.8

    The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    最高第 117:26 达到17:26 首次观测上榜20:22 观测离榜累计约2小时56分
  29. 29
    CVE-2026-12561 · MEDIUM 6.4

    The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This is due to insufficient input sanitization and output escaping in the vc_raw_html::render() method, which base64-decodes shortcode content (after a strip_tags() that is bypassed because the encoded payload contains no tags on save) and concatenates the result directly into the page HTML. Because WordPress's save-time wp_kses_post() filter only sees the inert base64 text inside a normal shortcode bracket and does not decode it, the dangerous tags survive into post_content and are emitted unescaped at render time. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page (for example, when an Editor or Administrator previews the pending post).

    最高第 413:26 达到13:26 首次观测上榜16:22 观测离榜累计约2小时56分
  30. 30
    CVE-2026-13214 · CRITICAL 9.8

    The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in subsys/net/lib/ocpp/ocpp.c) using an unbounded strcpy(). The parsed key value points directly into the receive buffer, so its length is bounded only by the message size (CONFIG_OCPP_RECV_BUFFER_SIZE, default 2048). The GetConfiguration message is delivered over the WebSocket connection that the charge point opens to its configured central system. The reader thread ocpp_wsreader() reads the message into ui->recv_buf and dispatches it to parse_getconfig_msg() via the PDU function table. An attacker who controls the central system endpoint, or a man-in-the-middle on an unencrypted connection, can send a GetConfiguration request whose "key" field exceeds 50 bytes and overflow the reader thread's stack with attacker-chosen bytes. The consequence is a remotely triggerable stack smash on the OCPP reader thread: at minimum a denial of service, and plausibly remote code execution depending on build-time hardening such as stack canaries and MPU configuration. The fix replaces the strcpy() with a bounded strncpy(key, payload.key[0], CISTR50 - 1) followed by explicit NUL termination, matching the bounded copies already used by the sibling handlers.

    最高第 313:26 达到13:26 首次观测上榜16:22 观测离榜累计约2小时56分
  31. 31
    CVE-2026-13215 · MEDIUM 6.8

    The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic number, revision, inode size and group counts, but never bounds s_log_block_size. On a successful verify, subsys/fs/ext2/ext2_ops.c computes fs->block_size = 1024 << superblock.s_log_block_size from this attacker-controlled uint32_t, so a crafted value either overflows the shift (undefined behaviour) or yields a block size far larger than CONFIG_EXT2_MAX_BLOCK_SIZE. That block size is then passed to k_mem_slab_init() by ext2_init_blocks_slab() to carve CONFIG_EXT2_MAX_BLOCK_COUNT blocks out of the fixed static buffer __ext2_block_memory_buffer, whose size is CONFIG_EXT2_MAX_BLOCK_COUNT * CONFIG_EXT2_MAX_BLOCK_SIZE. k_mem_slab_init() does not verify that the requested blocks fit the buffer, and the ext2 wrapper discards its return value, so the slab is laid out past the end of the static buffer. The mount immediately reads block-group, bitmap and inode blocks of fs->block_size bytes each into these slab blocks, producing an out-of-bounds write into adjacent static memory on the first block read. The entire path is gated only by data read from the mounted image, making this reachable by any attacker who can present a crafted ext2 image to a device that mounts it (for example a removable SD card or storage medium). Because the ext2 driver runs in kernel mode, supplying image bytes yields a supervisor-mode memory-corruption primitive, with impact ranging from denial of service to potential code execution. The fix rejects s_log_block_size values that overflow the shift (greater than 11) or that produce a block size exceeding CONFIG_EXT2_MAX_BLOCK_SIZE, so the block slab can no longer be initialized larger than its backing buffer.

    最高第 213:26 达到13:26 首次观测上榜16:22 观测离榜累计约2小时56分
  32. 32
    CVE-2026-78637 · MEDIUM 6.9

    A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a manipulation of the argument file_path results in argument injection. The attack may be initiated remotely. The patch is named db6e3f79d3beb20601be7e59669c39811ae3c330. It is recommended to apply a patch to fix this issue.

    最高第 113:26 达到13:26 首次观测上榜16:22 观测离榜累计约2小时56分
  33. 33
    CVE-2026-78638 · LOW 1.9

    A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 214:30 达到14:30 首次观测上榜17:26 观测离榜累计约2小时56分
  34. 34
    CVE-2026-78654 · MEDIUM 5.5

    A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component.

    最高第 114:30 达到14:30 首次观测上榜17:26 观测离榜累计约2小时56分
  35. 35
    CVE-2026-32560 · HIGH 8.8

    Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.

    最高第 1906:27 达到06:27 首次观测上榜09:23 观测离榜累计约2小时56分
  36. 36
    CVE-2026-32561 · HIGH 8.8

    Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

    最高第 1806:27 达到06:27 首次观测上榜09:23 观测离榜累计约2小时56分
  37. 37
    CVE-2026-32563 · CRITICAL 9.8

    Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

    最高第 1706:27 达到06:27 首次观测上榜09:23 观测离榜累计约2小时56分
  38. 38
    CVE-2026-45404 · MEDIUM 5.9

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0.

    最高第 1606:27 达到06:27 首次观测上榜09:23 观测离榜累计约2小时56分
  39. 39
    CVE-2026-68516 · MEDIUM 6.5

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.

    最高第 1506:27 达到06:27 首次观测上榜09:23 观测离榜累计约2小时56分
  40. 40
    CVE-2026-77337 · CRITICAL 9.1

    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

    最高第 1406:27 达到06:27 首次观测上榜09:23 观测离榜累计约2小时56分
  41. 41
    CVE-2026-14280 · MEDIUM 6.6

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal key is subsequently executed via an include_once() call that fires on every admin_init invocation — including unauthenticated admin-ajax.php requests — meaning once the malicious key is stored by an administrator, the inclusion is triggered without any further authentication or capability check.

    最高第 612:22 达到12:22 首次观测上榜15:18 观测离榜累计约2小时56分
  42. 42
    CVE-2026-17089 · MEDIUM 6.1

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The shortcode entry point sanitizes 'header_format' via wp_kses(), but the unauthenticated 'search_events_grouped' AJAX action bypasses this sanitization entirely, leaving the parameter unsanitized before it is echoed into the HTML body in output_grouped().

    最高第 512:22 达到12:22 首次观测上榜15:18 观测离榜累计约2小时56分
  43. 43
    CVE-2026-19892 · HIGH 8.8

    The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover.

    最高第 412:22 达到12:22 首次观测上榜15:18 观测离榜累计约2小时56分
  44. 44
    CVE-2026-78675 · HIGH 8.6

    GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.

    最高第 910:30 达到10:30 首次观测上榜13:26 观测离榜累计约2小时56分
  45. 45
    CVE-2026-78676 · CRITICAL 9.3

    GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

    最高第 810:30 达到10:30 首次观测上榜13:26 观测离榜累计约2小时56分
  46. 46
    CVE-2026-78677 · HIGH 8.7

    GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.

    最高第 710:30 达到10:30 首次观测上榜13:26 观测离榜累计约2小时56分
  47. 47
    CVE-2026-78678 · HIGH 7.1

    GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

    最高第 610:30 达到10:30 首次观测上榜13:26 观测离榜累计约2小时56分
  48. 48
    CVE-2026-79670 · MEDIUM 4.8

    Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Type using only client-supplied headers without server-side inspection. Attackers with admin privileges can upload SVG or HTML files containing JavaScript that executes in the application origin when accessed by any user, enabling session hijacking and data exfiltration.

    最高第 420:22 达到20:22 首次观测上榜22:31 观测离榜累计约2小时9分
  49. 49
    CVE-2026-79671 · MEDIUM 5.1

    Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169.254.169.254.nip.io). An attacker with admin privileges can create a webhook with such a hostname to bypass validation and cause the server to make requests to internal services, cloud metadata endpoints, and private network resources. The issue is fixed in 4.4.3.

    最高第 320:22 达到20:22 首次观测上榜22:31 观测离榜累计约2小时9分
  50. 50
    CVE-2026-79672 · HIGH 7

    Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.

    最高第 220:22 达到20:22 首次观测上榜22:31 观测离榜累计约2小时9分