最新预警列表

HIGH NVD Recent 2026-07-27

CVE-2026-15962:The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level acces

HIGH NVD Recent 2026-07-27

CVE-2026-17497:NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|

HIGH NVD Recent 2026-07-27

CVE-2026-17496:NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content tha

HIGH NVD Recent 2026-07-27

CVE-2026-65711:sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupS

HIGH NVD Recent 2026-07-27

CVE-2026-65710:sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting t

HIGH NVD Recent 2026-07-27

CVE-2026-65709:sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-accoun

HIGH NVD Recent 2026-07-27

CVE-2026-65708:sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorizat

MEDIUM NVD Recent 2026-07-27

CVE-2026-12982:The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploit

HIGH NVD Recent 2026-07-27

CVE-2026-12493:The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allow

CRITICAL NVD Recent 2026-07-27

CVE-2026-12394:The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

HIGH NVD Recent 2026-07-27

CVE-2026-12255:The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a val

MEDIUM NVD Recent 2026-07-27

CVE-2026-10082:The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content

HIGH NVD Recent 2026-07-27

CVE-2025-15662:The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arb

HIGH NVD Recent 2026-07-27

CVE-2026-15928:XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

MEDIUM NVD Recent 2026-07-27

CVE-2026-17500:A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。