最新预警列表

HIGH CISA KEV 2026-08-27

CVE-2026-66384:JFrog JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

HIGH NVD Recent 2026-08-26

CVE-2026-35445:Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to inv

HIGH NVD Recent 2026-08-26

CVE-2026-78122:docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs,

HIGH NVD Recent 2026-08-26

CVE-2026-32258:Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LES

HIGH NVD Recent 2026-08-26

CVE-2026-9771:The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USE

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output bu

HIGH NVD Recent 2026-08-26

CVE-2026-54481:Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

HIGH NVD Recent 2026-08-26

CVE-2026-24791:Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

HIGH NVD Recent 2026-08-26

CVE-2026-13048:Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by ap

HIGH CISA KEV 2026-08-26

CVE-2019-1068:Microsoft Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

HIGH CISA KEV 2026-08-26

CVE-2021-23758:Ajax.NET Professional Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are adv

HIGH NVD Recent 2026-08-25

CVE-2026-0551:The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible

HIGH NVD Recent 2026-08-24

CVE-2026-16149:The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints

HIGH NVD Recent 2026-08-24

CVE-2026-78050:A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-b

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_ena

HIGH NVD Recent 2026-08-24

CVE-2026-47895:In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

HIGH NVD Recent 2026-08-20

CVE-2026-20320:A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are impro

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。