全部/科技/实时热榜

NVD · 实时热榜

HISTORY2026年8月9日102 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS102 个热搜
  1. 01
    CVE-2026-17510 · UNKNOWN

    Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, char)`. A zero length attribute makes that a zero size reallocation, which Perl implements as a free returning NULL, so the buffer pointer becomes NULL, the following `strncpy` copies nothing, and the caller dereferences NULL in the `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is even length, so the ASN.1 decoder accepts it and the value reaches this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on `length + 1` or `length * 4 + 1` and are unaffected. Any caller that passes an untrusted PKCS#12 file to info_as_hash() can crash the process. info() prints attribute values directly without sizing a buffer and is unaffected.

    最高第 110:28 达到10:28 首次观测上榜14:28 观测离榜累计约4小时
  2. 02
    CVE-2026-19288 · LOW 1.9

    A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The attack needs to be performed locally. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 100:00 达到当日首次采集时已在榜08:20 观测离榜累计约8小时20分
  3. 03
    CVE-2026-19328 · LOW 1.9

    A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to version 0.1.1 is recommended to address this issue. The identifier of the patch is 855b46739e0f6e8388f17f9d0066ac4298a3965d. Upgrading the affected component is recommended.

    最高第 111:32 达到11:32 首次观测上榜14:28 观测离榜累计约2小时56分
  4. 04
    CVE-2026-19330 · LOW 1.9

    A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 112:20 达到12:20 首次观测上榜14:28 观测离榜累计约2小时8分
  5. 05
    CVE-2026-19334 · LOW 1.9

    A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 113:24 达到13:24 首次观测上榜14:28 观测离榜累计约1小时4分
  6. 06
    CVE-2026-19337 · LOW 1.9

    A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called f071d491b685011ca04e8ab8d586fc65f86bcee1. It is advisable to implement a patch to correct this issue.

    最高第 114:28 达到14:28 首次观测上榜当日结束时仍在榜累计约9小时20分
  7. 07
    CVE-2026-19341 · HIGH 7.4

    A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 115:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分
  8. 08
    CVE-2026-19343 · MEDIUM 5.5

    A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

    最高第 116:20 达到16:20 首次观测上榜当日结束时仍在榜累计约7小时28分
  9. 09
    CVE-2026-19346 · HIGH 7.4

    A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

    最高第 118:28 达到18:28 首次观测上榜当日结束时仍在榜累计约5小时20分
  10. 10
    CVE-2026-19350 · MEDIUM 5.3

    A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.

    最高第 119:32 达到19:32 首次观测上榜当日结束时仍在榜累计约4小时16分
  11. 11
    CVE-2026-19351 · MEDIUM 5.5

    A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.

    最高第 120:20 达到20:20 首次观测上榜当日结束时仍在榜累计约3小时28分
  12. 12
    CVE-2026-19353 · LOW 1.3

    A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.

    最高第 121:24 达到21:24 首次观测上榜当日结束时仍在榜累计约2小时24分
  13. 13
    CVE-2026-19356 · MEDIUM 5.5

    A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 122:28 达到22:28 首次观测上榜当日结束时仍在榜累计约1小时20分
  14. 14
    CVE-2026-19357 · MEDIUM 5.5

    A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 123:32 达到23:32 首次观测上榜当日结束时仍在榜累计约16分钟
  15. 15
    CVE-2026-67620 · MEDIUM 6.3

    Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows.

    最高第 100:20 达到00:20 首次观测上榜08:20 观测离榜累计约8小时
  16. 16
    CVE-2026-71502 · MEDIUM 5.1

    CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conversion whose name or description contains a malicious Vue expression using the application's configured [[ ... ]] delimiters. User profile names may provide an additional injection vector. Although Jinja HTML escaping is applied, the resulting value is subsequently included in a DOM region compiled by Vue. Vue interprets the attacker-controlled value as a template expression rather than ordinary text. By accessing the JavaScript Function constructor from within the expression, an attacker can execute arbitrary JavaScript in the security context of the CTI-Transmute origin. The application's nonce-based Content Security Policy does not prevent exploitation because the Vue runtime compiler requires the unsafe-eval policy exception. The malicious payload is stored by the application and executed whenever another user opens an affected page, such as the public conversion detail page. The victim may be a normal user or an administrator. Successful exploitation could allow the attacker to: * Access data available to the victim through the application. * Extract API keys, tokens, or other sensitive information exposed to the page. * Perform authenticated actions using the victim's session. * Modify conversions or other application data. * Escalate the impact by targeting an administrator. A demonstrated payload can use [].constructor.constructor(...) to obtain the JavaScript Function constructor and execute arbitrary code. The regression tests also show that a short first-stage payload could retrieve an uncapped conversion description and evaluate a larger second-stage payload. The patch addresses the vulnerability by registering a global Jinja finalize hook that inserts a zero-width Unicode word joiner inside every Vue delimiter found in server-rendered values. This prevents Vue from recognizing the values as template expressions while preserving their visible representation.

    最高第 106:28 达到06:28 首次观测上榜12:20 观测离榜累计约5小时52分
  17. 17
    CVE-2026-71955 · CRITICAL 9.3

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.

    最高第 101:24 达到01:24 首次观测上榜11:32 观测离榜累计约10小时8分
  18. 18
    CVE-2026-71958 · CRITICAL 9.3

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

    最高第 102:28 达到02:28 首次观测上榜12:20 观测离榜累计约9小时52分
  19. 19
    CVE-2026-71983 · CRITICAL 9.3

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.

    最高第 107:32 达到07:32 首次观测上榜12:20 观测离榜累计约4小时48分
  20. 20
    CVE-2026-71993 · CRITICAL 9.3

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

    最高第 108:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分
  21. 21
    CVE-2026-19287 · LOW 1.9

    A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 200:00 达到当日首次采集时已在榜07:32 观测离榜累计约7小时32分
  22. 22
    CVE-2026-19327 · LOW 1.9

    A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. This patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. Applying a patch is advised to resolve this issue.

    最高第 211:32 达到11:32 首次观测上榜14:28 观测离榜累计约2小时56分
  23. 23
    CVE-2026-19329 · LOW 1.9

    A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command injection. The attack requires a local approach. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 212:20 达到12:20 首次观测上榜14:28 观测离榜累计约2小时8分
  24. 24
    CVE-2026-19333 · LOW 1.9

    A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 213:24 达到13:24 首次观测上榜14:28 观测离榜累计约1小时4分
  25. 25
    CVE-2026-19336 · MEDIUM 4.8

    A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.

    最高第 214:28 达到14:28 首次观测上榜23:32 观测离榜累计约9小时4分
  26. 26
    CVE-2026-19340 · LOW 2.1

    A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 215:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分
  27. 27
    CVE-2026-19342 · MEDIUM 5.5

    A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.

    最高第 216:20 达到16:20 首次观测上榜当日结束时仍在榜累计约7小时28分
  28. 28
    CVE-2026-19345 · MEDIUM 5.5

    A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used.

    最高第 218:28 达到18:28 首次观测上榜当日结束时仍在榜累计约5小时20分
  29. 29
    CVE-2026-19348 · HIGH 8.9

    A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

    最高第 219:32 达到19:32 首次观测上榜当日结束时仍在榜累计约4小时16分
  30. 30
    CVE-2026-19352 · LOW 1.3

    A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.

    最高第 221:24 达到21:24 首次观测上榜当日结束时仍在榜累计约2小时24分
  31. 31
    CVE-2026-19355 · MEDIUM 5.5

    A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 222:28 达到22:28 首次观测上榜当日结束时仍在榜累计约1小时20分
  32. 32
    CVE-2026-42170 · HIGH 7.8

    A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.

    最高第 200:20 达到00:20 首次观测上榜08:20 观测离榜累计约8小时
  33. 33
    CVE-2026-71954 · CRITICAL 9.3

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

    最高第 201:24 达到01:24 首次观测上榜11:32 观测离榜累计约10小时8分
  34. 34
    CVE-2026-71957 · CRITICAL 9.3

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

    最高第 202:28 达到02:28 首次观测上榜11:32 观测离榜累计约9小时4分
  35. 35
    CVE-2026-71992 · CRITICAL 9.3

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.

    最高第 208:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分
  36. 36
    CVE-2026-10595 · HIGH 7.5

    A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.

    最高第 312:20 达到12:20 首次观测上榜14:28 观测离榜累计约2小时8分
  37. 37
    CVE-2026-19285 · LOW 1.9

    A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results in path traversal. The attack must be initiated from a local position. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 300:00 达到当日首次采集时已在榜06:28 观测离榜累计约6小时28分
  38. 38
    CVE-2026-19326 · LOW 1.9

    A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 311:32 达到11:32 首次观测上榜14:28 观测离榜累计约2小时56分
  39. 39
    CVE-2026-19332 · LOW 1.9

    A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 313:24 达到13:24 首次观测上榜14:28 观测离榜累计约1小时4分
  40. 40
    CVE-2026-19335 · LOW 1.9

    A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 314:28 达到14:28 首次观测上榜22:28 观测离榜累计约8小时
  41. 41
    CVE-2026-19339 · LOW 2.1

    A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 315:32 达到15:32 首次观测上榜当日结束时仍在榜累计约8小时16分
  42. 42
    CVE-2026-19344 · MEDIUM 5.5

    A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    最高第 318:28 达到18:28 首次观测上榜当日结束时仍在榜累计约5小时20分
  43. 43
    CVE-2026-19347 · LOW 2.1

    A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

    最高第 319:32 达到19:32 首次观测上榜当日结束时仍在榜累计约4小时16分
  44. 44
    CVE-2026-19354 · MEDIUM 5.3

    A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

    最高第 322:28 达到22:28 首次观测上榜当日结束时仍在榜累计约1小时20分
  45. 45
    CVE-2026-71953 · CRITICAL 9.3

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.

    最高第 301:24 达到01:24 首次观测上榜11:32 观测离榜累计约10小时8分
  46. 46
    CVE-2026-71956 · CRITICAL 9.3

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

    最高第 302:28 达到02:28 首次观测上榜11:32 观测离榜累计约9小时4分
  47. 47
    CVE-2026-71991 · CRITICAL 9.3

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

    最高第 308:20 达到08:20 首次观测上榜14:28 观测离榜累计约6小时8分
  48. 48
    CVE-2026-18603 · UNKNOWN

    The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.

    最高第 414:28 达到14:28 首次观测上榜22:28 观测离榜累计约8小时
  49. 49
    CVE-2026-19284 · LOW 1.9

    A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 400:00 达到当日首次采集时已在榜02:28 观测离榜累计约2小时28分
  50. 50
    CVE-2026-19325 · LOW 1.9

    A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation of the argument file_name leads to path traversal. The attack must be carried out locally. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

    最高第 411:32 达到11:32 首次观测上榜14:28 观测离榜累计约2小时56分