约 10 条结果 · 全文检索
文章安全速报

【低危】Gogs has DoS in rendering issue index pattern

Gogs has DoS in rendering issue index pattern

system · ◷ 0 · 2026-06-23
文章安全速报

【高危】LangSmith SDK TracingMiddleware: Arbitrary server-side file read

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

system · ◷ 1 · 2026-06-20
文章安全速报

【严重】scimPatch vulnerable to prototype pollution via unfiltered keys in patch

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

system · ◷ 0 · 2026-06-23
文章安全速报

【中危】SurrealDB: Denial of Service via deep operator chains

SurrealDB: Denial of Service via deep operator chains

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file rea

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

system · ◷ 1 · 2026-06-20
文章安全速报

【严重】OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

system · ◷ 0 · 2026-06-23
文章企业安全

Ghost_Bits_Cast_Attack_深度解读

原文PDF文件: Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf Cast Attack 技术全解:Ghost Bits 如何撕裂 Java 安全边界 从底层位运算到企业级防御体系——基于 Asia-26-Bai-Cast-Attack-G…

system · ◷ 2 · 2026-04-29
文章安全速报

【高危】@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing

@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing

system · ◷ 1 · 2026-06-20
文章安全速报

【高危】Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

system · ◷ 0 · 2026-06-23