约 15 条结果 · 全文检索
文章安全速报

【中危】SurrealDB: Denial of Service via deep operator chains

SurrealDB: Denial of Service via deep operator chains

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field

SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch

SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file rea

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions

Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】Zeep: Server-Side Request Forgery (SSRF)

Zeep: Server-Side Request Forgery (SSRF)

system · ◷ 3 · 2026-06-20
文章安全速报

【中危】Anki: User scripts in iframes have access to the internal Anki API

Anki: User scripts in iframes have access to the internal Anki API

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

system · ◷ 1 · 2026-06-20
文章安全速报

【中危】zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

system · ◷ 0 · 2026-06-23
文章安全速报

【中危】devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML i

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

system · ◷ 0 · 2026-06-23
文章安全速报

【中危】nebula-mesh's stores enrollment tokens unhashed in SQLite

nebula-mesh's stores enrollment tokens unhashed in SQLite

system · ◷ 0 · 2026-06-23
文章安全速报

【中危】Gogs has SSRF in webhook deliveries

Gogs has SSRF in webhook deliveries

system · ◷ 0 · 2026-06-23
文章安全速报

【中危】@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

system · ◷ 0 · 2026-06-23
文章安全速报

【高危】Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

system · ◷ 0 · 2026-06-23