最新预警列表

LOW NVD Recent 2026-07-21

CVE-2026-10755:The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

MEDIUM NVD Recent 2026-07-21

CVE-2026-10724:The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages tha

HIGH NVD Recent 2026-07-21

CVE-2026-10081:The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malici

MEDIUM NVD Recent 2026-07-21

CVE-2026-24232:NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

MEDIUM NVD Recent 2026-07-21

CVE-2026-16108:A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm

MEDIUM NVD Recent 2026-07-21

CVE-2026-1562:Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

MEDIUM NVD Recent 2026-07-21

CVE-2026-1563:Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

MEDIUM NVD Recent 2026-07-21

CVE-2026-16103:A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitte

LOW NVD Recent 2026-07-21

CVE-2026-16131:A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remote

MEDIUM NVD Recent 2026-07-21

CVE-2026-16093:Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client cre

MEDIUM NVD Recent 2026-07-20

CVE-2026-12724:The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into

MEDIUM NVD Recent 2026-07-20

CVE-2026-12723:The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identi

HIGH NVD Recent 2026-07-20

CVE-2026-12592:The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the

MEDIUM NVD Recent 2026-07-20

CVE-2026-11868:The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

HIGH NVD Recent 2026-07-20

CVE-2026-11349:The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。