← All credits
Yu Sun
35 vulnerability records and advisories credit this contributor.
CVE-2026-82454
Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in
CVE-2026-79785
X-AnyLabeling before 4.0.0-beta.9 Improper Certificate Validation in Model Downloads
CVE-2026-73032
PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval()
CVE-2026-73030
unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
CVE-2026-69117
NetBox 4.5.8 ORM Injection via WritableNestedSerializer
CVE-2026-73031
telegram-search Stored XSS via v-html in MessageList.vue
CVE-2026-72743
SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html
CVE-2026-93992
Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal
CVE-2026-93013
RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal
CVE-2026-69116
FlyEnv < 4.18.0 Cross-Site Scripting via v-html