最新预警列表

MEDIUM openEuler 安全公告 OSV 2026-08-01

CVE-2026-54058:python-pillow security update

python-pillow security update

MEDIUM openEuler 安全公告 OSV 2026-08-01

CVE-2026-54058:python-pillow security update

python-pillow security update

MEDIUM openEuler 安全公告 OSV 2026-08-01

CVE-2026-54058:python-pillow security update

python-pillow security update

MEDIUM NVD Recent 2026-08-01

CVE-2026-20316:A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted syst

MEDIUM NVD Recent 2026-08-01

CVE-2026-54707:OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionsh

CRITICAL NVD Recent 2026-07-31

CVE-2026-52855:Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, a

CRITICAL NVD Recent 2026-07-31

CVE-2026-67822:Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restr

HIGH NVD Recent 2026-07-31

CVE-2026-66731:facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single P

HIGH NVD Recent 2026-07-31

CVE-2026-66730:facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial

HIGH NVD Recent 2026-07-31

CVE-2026-66729:facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u

facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. A

CRITICAL NVD Recent 2026-07-31

CVE-2026-54725:vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and

MEDIUM NVD Recent 2026-07-31

CVE-2026-54706:OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py thr

HIGH NVD Recent 2026-07-31

CVE-2026-52856:Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

CRITICAL CERT/CC VU 2026-07-31

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

Overview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual

MEDIUM NVD Recent 2026-07-31

CVE-2026-51293:Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。