vulnti.work

Public vulnerability intelligence, Chinese-localised

vulnti.work is an AI-accelerated public-service aggregator covering NVD / GHSA / CISA KEV / vendor PSIRT / security mailing lists / CH-4 social channels. All data is sourced from lawful public channels.

Latest vulnerabilities

Drupal Core SQL Injection Vulnerability
Critical KEV

CVE-2026-9082 · 2026-07-14 · pending_review

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Google Dawn Use-After-Free Vulnerability
High KEV

CVE-2026-5281 · 2026-07-14 · pending_review

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple…

Check Point Security Gateway Improper Authentication Vulnerability
Critical KEV

CVE-2026-50751 · 2026-07-14 · pending_review

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN con…

SimpleHelp Authentication Bypass Vulnerability
High KEV

CVE-2026-48558 · 2026-07-14 · pending_review

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographi…

Adobe ColdFusion Path Traversal Vulnerability
High KEV

CVE-2026-48282 · 2026-07-14 · pending_review

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
High KEV

CVE-2026-48172 · 2026-07-14 · pending_review

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

Nx Console Embedded Malicious Code Vulnerability
High KEV

CVE-2026-48027 · 2026-07-14 · pending_review

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from m…

TanStack Unspecified Vulnerability
High KEV

CVE-2026-45321 · 2026-07-14 · pending_review

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

Microsoft Exchange Server Cross-Site Scripting Vulnerability
High KEV

CVE-2026-42897 · 2026-07-14 · pending_review

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browse…

BerriAI LiteLLM Command Injection Vulnerability
High KEV

CVE-2026-42271 · 2026-07-14 · pending_review

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

BerriAI LiteLLM SQL Injection Vulnerability
High KEV

CVE-2026-42208 · 2026-07-14 · pending_review

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Marimo Remote Code Execution Vulnerability
Critical KEV

CVE-2026-39987 · 2026-07-14 · pending_review

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Google Skia Out-of-Bounds Write Vulnerability
High KEV

CVE-2026-3909 · 2026-07-14 · pending_review

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android,…

Four subscription channels

Subscribe to the intelligence you care about (product / CVE / severity filters).