最新预警列表

HIGH NVD Recent 2026-07-15

CVE-2026-15428:An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters,

HIGH NVD Recent 2026-07-15

CVE-2026-15427:An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation r

HIGH NVD Recent 2026-07-15

CVE-2026-20187:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20158:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20157:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20156:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20153:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20150:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-15701:A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow.

HIGH NVD Recent 2026-07-14

CVE-2026-39903:Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulne

Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass re

HIGH NVD Recent 2026-07-14

CVE-2026-29009:U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONF

U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multi

HIGH NVD Recent 2026-07-14

CVE-2026-29008:U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c

U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data off

HIGH NVD Recent 2026-07-14

CVE-2026-57432:Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack

Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repea

HIGH NVD Recent 2026-07-14

CVE-2026-15506:A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be ap

HIGH NVD Recent 2026-07-14

CVE-2026-58281:Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ove

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。