最新预警列表

CRITICAL CERT-EU 2026-08-19

2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

CRITICAL NVD Recent 2026-08-19

CVE-2026-19626:A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during serv

CRITICAL Cisco PSIRT 2026-08-19

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access contro

CRITICAL Cisco PSIRT 2026-08-19

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 C

CRITICAL CERT/CC VU 2026-08-18

VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively

CRITICAL NVD Recent 2026-08-18

CVE-2026-71947:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands in

CRITICAL NVD Recent 2026-08-17

CVE-2026-71952:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the ol

CRITICAL NVD Recent 2026-08-14

CVE-2026-20267:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple i

CRITICAL NVD Recent 2026-08-12

CVE-2026-8457:The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without

CRITICAL NVD Recent 2026-08-12

CVE-2026-12571:An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

CRITICAL Cisco PSIRT 2026-08-12

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple i

CRITICAL NVD Recent 2026-08-11

CVE-2026-71951:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_va

CRITICAL NVD Recent 2026-08-11

CVE-2026-71946:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the

CRITICAL CERT/CC VU 2026-08-11

VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure

Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. U

CRITICAL NVD Recent 2026-08-11

CVE-2026-71954:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。