最新预警列表

HIGH NVD Recent 2026-08-31

CVE-2026-18268:Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows loc

Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability t

HIGH NVD Recent 2026-08-31

CVE-2026-15679:Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This

Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User i

HIGH NVD Recent 2026-08-31

CVE-2026-18349:Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injectio

Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4.

HIGH NVD Recent 2026-08-31

CVE-2024-13942:Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me

Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD). The code reads the header of the next-stage loader twice. The header contains hashes of the exec

HIGH NVD Recent 2026-08-31

CVE-2026-82472:Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication,

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources

HIGH NVD Recent 2026-08-31

CVE-2025-36940:Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

HIGH CISA KEV 2026-08-31

CVE-2026-81578:PaperCut PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

HIGH openEuler 安全公告 OSV 2026-08-30

CVE-2026-18724:open-iscsi security update

open-iscsi security update

HIGH openEuler 安全公告 OSV 2026-08-30

CVE-2026-31962:htslib security update

htslib security update

HIGH NVD Recent 2026-08-28

CVE-2026-19685:NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) c

HIGH NVD Recent 2026-08-28

CVE-2026-15469:The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5

The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.  A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protoco

HIGH NVD Recent 2026-08-28

CVE-2026-66908:Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through

HIGH NVD Recent 2026-08-28

CVE-2026-50768:File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to ex

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

HIGH NVD Recent 2026-08-27

CVE-2026-66907:Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud

HIGH NVD Recent 2026-08-27

CVE-2026-32257:Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。