最新预警列表

CRITICAL Cisco PSIRT 2026-08-07

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address m

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2026-31958:python-tornado security update

python-tornado security update

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2025-45582:tar security update

tar security update

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2025-50181:python-pip security update

python-pip security update

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2024-1681:python-Flask-Cors security update

python-Flask-Cors security update

CRITICAL NVD Recent 2026-08-06

CVE-2026-63077:In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CRITICAL NVD Recent 2026-08-05

CVE-2025-29296:H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilitie

CRITICAL Cisco PSIRT 2026-08-05

Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more in

CRITICAL NVD Recent 2026-08-04

CVE-2026-12940:IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DA

CRITICAL NVD Recent 2026-08-04

CVE-2026-59638:In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1

CRITICAL NVD Recent 2026-08-03

CVE-2026-41452:Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLH

CRITICAL NVD Recent 2026-08-03

CVE-2026-39932:OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads

CRITICAL openEuler 安全公告 OSV 2026-08-01

CVE-2025-71273:kernel security update

kernel security update

CRITICAL openEuler 安全公告 OSV 2026-08-01

CVE-2026-59884:python-pyasn1 security update

python-pyasn1 security update

CRITICAL openEuler 安全公告 OSV 2026-08-01

CVE-2025-15059:gimp security update

gimp security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。