搜尋
30,476 筆結果- MEDIUM5.9CVE-2026-49267Apache Airflow: No certificate validation on SMTP STARTTLS connections
- MEDIUM6.5CVE-2026-48726Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
- MEDIUM4.3CVE-2026-46764Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter
- MEDIUM6.5CVE-2026-42358Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets
- MEDIUM4.3CVE-2026-41014Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
- LOW3.1CVE-2026-40963Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
- MEDIUM6.5CVE-2026-40861Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler
- MEDIUM4.1CVE-2026-48013Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
- MEDIUM4.9CVE-2026-48015Shopware: Stored XSS via SVG file upload — no SVG sanitization
- MEDIUM4.3CVE-2026-48016Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment
- MEDIUM6.5CVE-2026-48014Shopware: Admin API ACL Bypass in Order State Transition Endpoints
- MEDIUM4.3CVE-2026-48012Shopware SSO referer trust leading to an arbitrary redirect target
- LOW3.7CVE-2026-48011Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
- MEDIUM6.5CVE-2026-48010Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts
- MEDIUM6.8CVE-2026-48009Shopware: Admin Account Takeover via User Recovery Hash Exposure
- MEDIUM6.5CVE-2026-48008Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
- MEDIUM4.7CVE-2026-50183WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
- MEDIUM6.1CVE-2026-50182WWBN AVideo: Unauthenticated Reflected XSS via $_GET['search'] in AVideo YouTubeAPI Gallery Pagination
- MEDIUM4.3CVE-2026-47696EPSS 0.02%WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint
- MEDIUM5.4CVE-2026-47694EPSS 0.03%WWBN AVideo: Stored XSS via unescaped Gallery category description
- MEDIUM5.3CVE-2026-47676Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
- MEDIUM5.3CVE-2026-47674Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
- MEDIUM4.3CVE-2026-47675Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
- MEDIUM4.8CVE-2026-47673Hono: JWT middleware accepts any Authorization scheme, not only Bearer
- MEDIUM5.4CVE-2026-47671Nhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
第 1 / 1220 頁下一頁 →