SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

社区情报

来自安全社区、研究机构和开源生态的情报。

  • CVE-2026-11413 | JingDong JD Cloud Box AX6600 4.5.3.r4546 /sbin/jdcweb_rpc set_macfilter stack-based overflow

    发布时间 2026-06-06 02:45 (UTC+08:00) 抓取时间 2026-06-06 04:00 (UTC+08:00)

    A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/jingdong:jd_cloud_box_ax6600">JingDong JD Cloud Box AX6600 4.5.3.r4546</a>. The impacted element is the function <code>set_macfilter</code> of the file <em>/sbin/jdcweb_rpc</em>. The manipulation leads to stack-based buffer over

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:45:50 +0200"
    }
    VulDB CVE-2026-11413 cve official_bulletin
  • CVE-2026-11412 | Jinher OA C6 GetFormSn.aspx queryID sql injection

    发布时间 2026-06-06 02:43 (UTC+08:00) 抓取时间 2026-06-06 04:00 (UTC+08:00)

    A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/jinher:oa">Jinher OA C6</a>. The affected element is an unknown function of the file <em>/C6/JHSoft.Web.ModuleCount/GetFormSn.aspx</em>. Executing a manipulation of the argument <em>queryID</em> can lead to sql injection. T

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:43:46 +0200"
    }
    VulDB CVE-2026-11412 cve official_bulletin
  • CVE-2026-11411 | iAI Lab PDF AI App 4.21.0 on Android chatpdf.pro getExternalCacheDir _display_name path traversal

    发布时间 2026-06-06 02:42 (UTC+08:00) 抓取时间 2026-06-06 03:01 (UTC+08:00)

    A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/iai_lab:pdf_ai_app">iAI Lab PDF AI App 4.21.0</a> on Android. Impacted is the function <code>getExternalCacheDir</code> of the component <em>chatpdf.pro</em>. Performing a manipulation of the argument <em>_display_name</em> resul

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:42:27 +0200"
    }
    VulDB CVE-2026-11411 cve official_bulletin
  • CVE-2026-11408 | vertex-app vertex up to 2026.02.12 Log Viewer Endpoint app/model/LogMod.js req.query os command injection

    发布时间 2026-06-06 02:39 (UTC+08:00) 抓取时间 2026-06-06 03:01 (UTC+08:00)

    A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/vertex-app:vertex">vertex-app vertex up to 2026.02.12</a>. This issue affects some unknown processing of the file <em>app/model/LogMod.js</em> of the component <em>Log Viewer Endpoint</em>. Such manipulation of the argument <em>req

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:39:00 +0200"
    }
    VulDB CVE-2026-11408 cve official_bulletin
  • CVE-2026-11406 | GL.iNet MT3000 up to 4.4.5 OpenVPN Client Import Workflow ovpnclient.sh command injection

    发布时间 2026-06-06 02:31 (UTC+08:00) 抓取时间 2026-06-06 03:01 (UTC+08:00)

    A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/gl">GL.iNet MT3000 up to 4.4.5</a>. This vulnerability affects unknown code of the file <em>ovpnclient.sh</em> of the component <em>OpenVPN Client Import Workflow</em>. This manipulation causes command injection. This vulner

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:31:31 +0200"
    }
    VulDB CVE-2026-11406 cve official_bulletin
  • CVE-2026-2379 | Arista EOS up to 4.34.3M IPsec Feature operation after expiration

    发布时间 2026-06-06 02:23 (UTC+08:00) 抓取时间 2026-06-06 03:01 (UTC+08:00)

    A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/arista:eos">Arista EOS up to 4.34.3M</a>. This affects an unknown part of the component <em>IPsec Feature</em>. The manipulation results in operation on a resource after expiration. This vulnerability is cataloged as <

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:23:42 +0200"
    }
    VulDB CVE-2026-2379 cve official_bulletin
  • CVE-2025-71317 | Riello UPS NetMan up to 204 SSH Service cgi-bin/login.cgi hard-coded credentials (Exploit 52183 / EDB-52183)

    发布时间 2026-06-06 02:23 (UTC+08:00) 抓取时间 2026-06-06 03:01 (UTC+08:00)

    A vulnerability was found in <a href="https://vuldb.com/product/riello_ups:netman">Riello UPS NetMan up to 204</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the file <em>cgi-bin/login.cgi</em> of the component <em>SSH Service</em>. The manipulation leads to hard-coded crede

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:23:28 +0200"
    }
    VulDB CVE-2025-71317 cve official_bulletin
  • CVE-2026-50733 | shd101wyy Markdown Preview Enhanced up to 0.8.27 window.eval eval injection

    发布时间 2026-06-06 02:23 (UTC+08:00) 抓取时间 2026-06-06 03:01 (UTC+08:00)

    A vulnerability was found in <a href="https://vuldb.com/product/shd101wyy:markdown_preview_enhanced">shd101wyy Markdown Preview Enhanced up to 0.8.27</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this vulnerability is the function <code>window.eval</code>. Executing a manipulation can lead to improper neutralizati

    扩展字段
    {
      "raw_pub_date": "Fri, 05 Jun 2026 20:23:16 +0200"
    }
    VulDB CVE-2026-50733 cve official_bulletin