CloudMap
漏洞情报库
漏洞库
厂商
产品
风险排行
开发者中心
开始检索
↗
VULNERABILITY INTELLIGENCE
漏洞情报库
组合风险、利用情报和受影响对象,快速定位需要优先处置的漏洞。
利用情报保护
仅展示 PoC / EXP 是否收录
不公开内容、路径和下载地址
⌕
/
搜索漏洞
8,272
条匹配记录
PoC
EXP
绿色表示已收录,灰色表示暂无
漏洞与影响对象
漏洞类型
风险等级
CVSS
EPSS
利用情报
披露时间
CVE-2026-33497
Langflow < 1.7.0 - Path Traversal
Langflow
路径穿越
高危
—
2.0%
PoC
EXP
2026/07/28
CVE-2026-8732
WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauthenticated Administrator Account Creation
WP Maps Pro
未授权访问
严重
—
1.9%
PoC
EXP
2026/07/28
CVE-2026-46442
Flowise < 3.1.2 - node-custom-function Unauthorized RCE
Flowise
远程代码执行
严重
—
3.4%
PoC
EXP
2026/07/28
CVE-2026-23696
Windmill < 1.603.3 - SQL Injection
Windmill
SQL注入
严重
—
13.6%
PoC
EXP
2026/07/28
CVE-2026-58455
Dockwatch <= 0.6.567 - OS Command Injection
Dockwatch
远程代码执行
严重
—
8.0%
PoC
EXP
2026/07/28
CVE-2026-42796
Arelle < 2.39.10 - Remote Code Execution
Arelle
未授权访问
严重
—
3.9%
PoC
EXP
2026/07/28
CVE-2026-3296
KEV
Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection
everest-forms
反序列化
严重
—
3.0%
PoC
EXP
2026/07/28
CVE-2026-15094
WP Hotel Booking <= 2.3.2 - Cross-Site Scripting
wp_hotel_booking
跨站脚本攻击
中危
—
0.69%
PoC
EXP
2026/07/28
CVE-2026-9198
RCE
IBM Langflow - Remote Code Execution
Langflow
身份验证绕过
严重
—
28.7%
PoC
EXP
2026/07/28
CVE-2026-6875
ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE
ServiceNow
远程代码执行
严重
—
1.4%
PoC
EXP
2026/07/28
CVE-2026-8385
WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure
wp-google-maps
未授权访问
中危
—
0.73%
PoC
EXP
2026/07/28
CVE-2021-47795
GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting
geowebserver
跨站脚本攻击
高危
—
2.9%
PoC
EXP
2026/07/28
vLLM OpenAI-Compatible API - Unauthenticated Exposure
vLLM
未授权访问
中危
—
—
PoC
EXP
2026/07/28
SMB - Default Logins
smb
弱口令
高危
—
—
PoC
EXP
2026/07/28
CVE-2026-48908
KEV
Joomla SP Page Builder <= 6.6.1 - Unauthenticated Arbitrary File Upload RCE
SP Page Builder
远程代码执行
严重
—
88.5%
PoC
EXP
2026/07/28
CVE-2026-15409
KEV
SonicWall SMA1000 - Server-Side Request Forgery
SonicWall SMA
服务端请求伪造
严重
—
6.8%
PoC
EXP
2026/07/28
CVE-2026-48909
Joomla SP LMS <= 4.1.3 - Remote Code Execution
Joomla
未授权访问
严重
—
4.9%
PoC
EXP
2026/07/28
Windows Command Injection - Generic Detection
远程代码执行
高危
—
—
PoC
EXP
2026/07/28
Unix Command Injection - Generic Detection
远程代码执行
高危
—
—
PoC
EXP
2026/07/28
CVE-2025-29927
Next.js Middleware Authorization Bypass
next.js
身份验证绕过
严重
—
99.2%
PoC
EXP
2026/07/28
← 上一页
16 / 414
下一页 →