CloudMap
漏洞情报库
漏洞库
厂商
产品
风险排行
开发者中心
开始检索
↗
VULNERABILITY INTELLIGENCE
漏洞情报库
组合风险、利用情报和受影响对象,快速定位需要优先处置的漏洞。
验证信息保护
仅展示 PoC 是否收录
不公开内容、路径和下载地址
⌕
/
搜索漏洞
10,858
条匹配记录
PoC
绿色表示已收录,灰色表示暂无
漏洞与影响对象
漏洞类型
风险等级
CVSS
EPSS
PoC 状态
披露时间
CVE-2026-41456
Bludit CMS <= 3.20.0 - Cross-Site Scripting
Bludit
跨站脚本攻击
中危
—
2.7%
PoC
2026/09/30
CVE-2026-30965
Parse Server < 8.6.21 / 9.x < 9.5.2 - Session Token Exfiltration
信息泄露
严重
—
1.6%
PoC
2026/09/30
CVE-2026-82329
JFrog Artifactory Access Blank Join Key Authentication Bypass
身份验证绕过
严重
—
14.1%
PoC
2026/09/30
CVE-2026-53595
FreeScout < 1.8.224 - Invite Hash Authorization Bypass
未授权访问
严重
—
1.9%
PoC
2026/09/30
CVE-2026-59726
RCE
ruflo MCP Bridge - Unauthenticated RCE via terminal_execute
未授权访问
严重
—
3.0%
PoC
2026/09/30
CVE-2026-49060
Hippoo Mobile App for WooCommerce - Broken Access Control
未授权访问
严重
—
1.6%
PoC
2026/09/30
CVE-2026-0650
OpenFlagr <= 1.1.18 - Authentication Bypass
未授权访问
严重
—
1.5%
PoC
2026/09/30
CVE-2026-76904
RCE
GeoServer jsonArrayContains CQL Filter - SQL Injection
GeoServer
SQL注入
严重
—
2.4%
PoC
2026/09/30
CVE-2026-60105
Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass
未授权访问
高危
—
1.5%
PoC
2026/09/30
CVE-2026-71209
Audiobookshelf - Authentication Bypass
信息泄露
严重
—
1.9%
PoC
2026/09/30
CVE-2026-30623
RCE
LiteLLM 1.18.10 - Command Injection
远程代码执行
高危
—
5.0%
PoC
2026/09/30
CVE-2026-14894
RCE
WordPress Super Forms <= 6.3.313 - Arbitrary File Upload
远程代码执行
严重
—
5.1%
PoC
2026/09/30
CVE-2026-41042
RCE
Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution
未授权访问
严重
—
1.5%
PoC
2026/09/30
CVE-2026-57219
RabbitMQ Management - OAuth 2 Client Secret Disclosure
未授权访问
高危
—
2.8%
PoC
2026/09/30
CVE-2026-52806
RCE
Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection
Gogs
远程代码执行
严重
—
7.9%
PoC
2026/09/30
CVE-2026-64849
MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass
服务端请求伪造
严重
—
9.8%
PoC
2026/09/30
CVE-2026-29962
HSC MailInspector - Local File Inclusion
文件包含
高危
—
1.8%
PoC
2026/09/30
CVE-2026-34976
Dgraph <=v25.3.0 - Admin Mutation Missing Authorization
服务端请求伪造
严重
—
1.7%
PoC
2026/09/30
CVE-2026-27542
WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege Escalation
未授权访问
严重
—
1.8%
PoC
2026/09/30
CVE-2026-0717
LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings Disclosure
未授权访问
中危
—
0.94%
PoC
2026/09/30
← 上一页
12 / 543
下一页 →