最新预警列表

MEDIUM NVD Recent 2026-09-11

CVE-2026-68528:Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for an

CRITICAL NVD Recent 2026-09-11

CVE-2026-54047:Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior t

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side sta

MEDIUM NVD Recent 2026-09-11

CVE-2026-18122:Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization;

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read s

MEDIUM CERT/CC VU 2026-09-11

VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

Overview An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful exploitation can lead to an immediate denial of servic

HIGH NVD Recent 2026-09-11

CVE-2026-73694:FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd(

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attacker

MEDIUM NVD Recent 2026-09-11

CVE-2026-82470:Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second a

MEDIUM NVD Recent 2026-09-11

CVE-2026-82469:Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a

MEDIUM NVD Recent 2026-09-11

CVE-2026-82468:Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF t

MEDIUM NVD Recent 2026-09-11

CVE-2026-82467:Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browse

CRITICAL NVD Recent 2026-09-11

CVE-2026-82466:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account

HIGH NVD Recent 2026-09-11

CVE-2026-17615:A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unaut

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an end

HIGH NVD Recent 2026-09-11

CVE-2026-20293:A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-ba

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or a

HIGH NVD Recent 2026-09-11

CVE-2026-67277:RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized ta

HIGH NVD Recent 2026-09-11

CVE-2026-23855:Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions pri

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.

MEDIUM CISA KEV 2026-09-11

CVE-2026-85706:GitLab GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。