CloudMap漏洞情报库
漏洞库厂商产品风险排行
开始检索 ↗
CloudMap漏洞情报库

面向安全研究者与技术团队的公开漏洞情报检索平台。

漏洞库厂商产品风险排行
© 2026 CloudMap数据仅供安全研究与风险评估参考
LIVE
CVEEPSSKEVCVSS
持续聚合全球公开漏洞情报

让每一个漏洞
清晰可见

聚合 CVE、CNVD、CVSS 与 EPSS 数据,以厂商和产品为脉络,帮助你更快完成漏洞检索与风险判断。

⌕/
快速入口严重漏洞PoC 已收录EXP 已收录CISA KEV
10,857收录漏洞全部记录→3,060严重漏洞CVSS 9.0+→8,272PoC 已收录仅状态可见→566EXP 已收录优先处置→67CISA KEV已知在野利用→
RISK LANDSCAPE

风险态势概览

数据更新于 2026/10/2 06:49:15

新增漏洞趋势按披露日期统计
进入漏洞库 →
近 30 天新增284峰值 284 / 日
09-0310-02
风险等级分布CVSS Severity
严重3,060
高危3,687
中危2,895
低危1,181
安全边界

本站仅公开 PoC 与 EXP 的收录状态,不提供内容、路径或下载能力。

高频厂商按关联漏洞数排序
全部厂商 →
  1. 01微软公司527
  2. 02wp-plugin375
  3. 03阿帕奇329
  4. 04oracle113
  5. 05Adobe102
  6. 06joomla97
  7. 07威睿87
  8. 08fedoraproject80
  9. 09wordpress79
  10. 10linux77
  11. 11思科系统公司75
  12. 12友讯电子设备(上海)有限公司版权所有67
LATEST INTELLIGENCE

最新漏洞情报

按披露时间持续更新,快速掌握值得关注的安全风险。

查看全部漏洞 →
严重2026/09/30

ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCE

ArangoDB <= 3.12.10.1 contains an authentication bypass in the default server.authentication-system-only=true mode (GHSA-rrgq-978q-36mq). The auth gate evaluates the raw URL while action dispatch uses URL-decoded suffixes. Encoding the leading underscore as %5f makes protected /_api/simple/* actions appear public to the auth gate but dispatches as privileged system actions, allowing unauthenticated read/write of the _users collection including password hashes.Chained with GHSA-rvhw-4hpw-9vrx (client-controlled isSystem:true in REST task creation), this yields root-context command execution in the official container image where arangod runs as UID 0.

PoC 已收录
CVSS—
高危2026/09/30

WordPress Click2Shell Theme Preview Selector Injection

WordPress contains a client-side selector injection in the theme installer preview route. A crafted URL opened by an authenticated administrator can cause WordPress to automatically install and preview an attacker-selected inactive theme from WordPress.org. The issue can be chained with a separate vulnerability in an installed theme to achieve code execution.

wordpressPoC 已收录
CVSS—
严重2026/09/30

WordPress Simple File List <=4.2.2 - Remote Code Execution

An unrestricted file upload vulnerability in the WordPress Simple File List plugin before version 4.2.3 allows unauthenticated remote attackers to achieve remote code execution. The plugin's upload endpoint (ee-upload-engine.php) restricts file uploads based on extension, but lacks proper validation after file renaming. An attacker can first upload a PHP payload disguised as a .png file, then use the plugin’s ee-file-engine.php rename functionality to change the extension to .php. This bypasses upload restrictions and results in the uploaded payload being executable on the server.

PoC 已收录
CVSS—
高危2026/09/30

IBM WebSphere HCL Digital Experience - Server-Side Request Forgery

IBM WebSphere HCL Digital Experience is vulnerable to server-side request forgery that impacts on-premise deployments and containers.

PoC 已收录
CVSS—
低危2026/09/30

AfterLogic Aurora and WebMail Pro < 7.7.9 - Full Path Disclosure

AfterLogic Aurora and WebMail Pro products with 7.7.9 and all lower versions are affected by this vulnerability, simply sending an HTTP DELETE request to WebDAV EndPoint with built-in “caldav_public_user@localhost” and it’s the predefined password “caldav_public_user” allows the attacker to obtain web root path.

PoC 已收录
CVSS—
中危2026/09/30

BentoML v1.3.9 - Open Redirect

An open redirect vulnerability exists in BentoML v1.3.9, where the file parameter in the /ui/gradio_api/file= endpoint can be manipulated to redirect users to malicious websites. This could facilitate phishing attacks by tricking users into visiting attacker-controlled URLs.

PoC 已收录
CVSS—
EXPLORE THE LANDSCAPE

从不同维度理解风险

VVENDORS

厂商视图

按厂商归集产品与漏洞,快速建立资产相关的风险脉络。

浏览厂商 →
PPRODUCTS

产品视图

聚焦具体产品,了解关联漏洞数量与受影响范围。

浏览产品 →
RRISK RANKINGS

风险排行

结合 CVSS 与 EPSS,从危害和利用概率两个角度识别优先级。

查看排行 →