CloudMap
漏洞情报库
漏洞库
厂商
产品
风险排行
开发者中心
开始检索
↗
VULNERABILITY INTELLIGENCE
漏洞情报库
组合风险、利用情报和受影响对象,快速定位需要优先处置的漏洞。
利用情报保护
仅展示 PoC / EXP 是否收录
不公开内容、路径和下载地址
⌕
/
搜索漏洞
10,857
条匹配记录
PoC
EXP
绿色表示已收录,灰色表示暂无
漏洞与影响对象
漏洞类型
风险等级
CVSS
EPSS
利用情报
披露时间
CVE-2026-41456
Bludit CMS <= 3.20.0 - Cross-Site Scripting
Bludit
跨站脚本攻击
中危
—
—
PoC
EXP
2026/09/30
CVE-2026-30965
Parse Server < 8.6.21 / 9.x < 9.5.2 - Session Token Exfiltration
未分类
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-82329
JFrog Artifactory Access Blank Join Key Authentication Bypass
身份验证绕过
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-53595
FreeScout < 1.8.224 - Invite Hash Authorization Bypass
未授权访问
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-59726
ruflo MCP Bridge - Unauthenticated RCE via terminal_execute
未授权访问
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-49060
Hippoo Mobile App for WooCommerce - Broken Access Control
未授权访问
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-0650
OpenFlagr <= 1.1.18 - Authentication Bypass
未授权访问
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-76904
GeoServer jsonArrayContains CQL Filter - SQL Injection
GeoServer
SQL注入
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-60105
Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass
未授权访问
高危
—
—
PoC
EXP
2026/09/30
CVE-2026-71209
Audiobookshelf - Authentication Bypass
信息泄露
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-30623
LiteLLM 1.18.10 - Command Injection
远程代码执行
高危
—
—
PoC
EXP
2026/09/30
CVE-2026-14894
WordPress Super Forms <= 6.3.313 - Arbitrary File Upload
远程代码执行
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-41042
Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution
未授权访问
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-57219
RabbitMQ Management - OAuth 2 Client Secret Disclosure
未授权访问
高危
—
—
PoC
EXP
2026/09/30
CVE-2026-52806
Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument Injection
Gogs
远程代码执行
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-64849
MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass
服务端请求伪造
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-29962
HSC MailInspector - Local File Inclusion
文件包含
高危
—
—
PoC
EXP
2026/09/30
CVE-2026-34976
Dgraph <=v25.3.0 - Admin Mutation Missing Authorization
服务端请求伪造
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-27542
WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege Escalation
未授权访问
严重
—
—
PoC
EXP
2026/09/30
CVE-2026-0717
LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings Disclosure
未授权访问
中危
—
—
PoC
EXP
2026/09/30
← 上一页
12 / 543
下一页 →