A vulnerability was found in codexu NoteGen up to 0.31.x. It has been declared as problematic. This impacts the function dangerouslySetInnerHTML of the component chat-preview. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-17496. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
Claude 共享对话功能曝出高危隐私安全漏洞。用户通过该功能生成的公开分享链接未配置搜索引擎禁止抓取标识,致使大量对话内容被谷歌等搜索引擎收录索引,任意网民只需检索关键词,就能完整浏览对话全文。
此次泄露内容覆盖多类高敏感数据,包括接口密钥、加密货币钱包地址、个人求职简历、法律咨询记录、企业内部项目文档、社保身份编号等。约一年前 ChatGPT 曾出现完全一致的共享链接爬虫泄露问题,当时 OpenAI 迅速完成漏洞修复。反观开发 Claude 的 Anthropic,截至目前仍未推出修复方案。安全人员提醒所有用户,尽快进入账号设置内的「共享对话」管理页面,手动删除包含个人隐私、财务信息的聊天会话,规避信息持续外泄风险。
A vulnerability was found in codexu NoteGen up to 0.31.x. It has been declared as problematic. This impacts the function dangerouslySetInnerHTML of the component chat-preview. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-17496. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in codexu NoteGen up to 0.31.x. It has been classified as problematic. This affects an unknown function of the component Tauri shell plugin. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-17497. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Microsoft Surface Management Services. It has been rated as very critical. This issue affects some unknown processing. This manipulation causes improper input validation.
This vulnerability is tracked as CVE-2026-54120. The attack is possible to be carried out remotely. No exploit exists.
This product is a managed service, so users do not have direct control over vulnerability countermeasures.
A vulnerability categorized as critical has been discovered in Microsoft Account. Impacted is an unknown function. Such manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2026-56165. The attack may be performed from remote. There is no available exploit.
This product is a managed service, which means users themselves cannot handle vulnerability countermeasures.
A vulnerability was found in Microsoft Graph. It has been declared as problematic. This vulnerability affects unknown code. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-49159. The attack can be executed remotely. There is not any exploit available.
This product is a managed service, indicating that users are not permitted to maintain vulnerability countermeasures themselves.
A vulnerability labeled as critical has been found in Microsoft Azure API Management. The impacted element is an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-35425. It is possible to launch the attack remotely. No exploit is available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
A vulnerability identified as very critical has been detected in Microsoft Azure Red Hat OpenShift. The affected element is an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-56160. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service, therefore users are not responsible for maintaining vulnerability countermeasures.
A vulnerability classified as critical was found in Microsoft Azure AI Search. Affected by this vulnerability is an unknown functionality. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-56167. The attack may be launched remotely. There is no exploit available.
This product is a managed service, so users are unable to manage vulnerability countermeasures on their own.
A vulnerability was found in meum Kirki Plugin up to 6.0.14 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument context results in improper control of resource identifiers.
This vulnerability was named CVE-2026-13464. The attack may be performed from remote. There is no available exploit.
A vulnerability described as critical has been identified in Microsoft Azure DNS. This impacts an unknown function. The manipulation results in improper authorization.
This vulnerability is reported as CVE-2026-58275. The attack can be launched remotely. No exploit exists.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
A vulnerability was found in Microsoft Exchange Server. It has been classified as very critical. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-56191. Remote exploitation of the attack is possible. No exploit is available.
This product is provided as a managed service, meaning users do not have the ability to maintain vulnerability countermeasures themselves.
A vulnerability classified as critical has been found in Microsoft Azure Key Vault. Affected is an unknown function. This manipulation causes improper authentication.
This vulnerability appears as CVE-2026-62825. The attack may be initiated remotely. There is no available exploit.
This product is a managed service. This means that users cannot maintain vulnerability countermeasures themselves.