最新预警列表

HIGH NVD Recent 2026-09-03

CVE-2026-81300:Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-81292:Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

HIGH NVD Recent 2026-09-03

CVE-2020-15878:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.

HIGH NVD Recent 2026-09-03

CVE-2020-15876:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address

HIGH NVD Recent 2026-09-03

CVE-2020-15874:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary s

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

HIGH NVD Recent 2026-09-03

CVE-2026-19913:The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP sch

CRITICAL NVD Recent 2026-09-03

CVE-2026-19912:The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose

HIGH NVD Recent 2026-09-03

CVE-2026-51788:An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification

An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component

MEDIUM NVD Recent 2026-09-03

CVE-2026-19953:URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in

URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to be normalized to Form C

HIGH NVD Recent 2026-09-03

CVE-2026-19590:OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations

OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config poin

CRITICAL NVD Recent 2026-09-03

CVE-2026-20212:A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remo

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in

HIGH NVD Recent 2026-09-03

CVE-2026-80223:Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to rec

Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant's records over GraphQL subscriptions. The subscription resolver in AshGraphql.Graphql.Resolver authorizes each not

MEDIUM NVD Recent 2026-09-02

CVE-2026-20355:Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilit

MEDIUM NVD Recent 2026-09-02

CVE-2026-20354:Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilit

HIGH NVD Recent 2026-09-02

CVE-2026-20281:A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that ar

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。